{"product_id":11116,"v_id":11116,"product_name":"SailPoint IdentityIQ File Access Manager Version 8.1","certification_status":"Certified","certification_date":"2020-12-08T00:00:00Z","tech_type":"Application Software","vendor_id":{"name":"SailPoint Technologies, Inc.","website":"www.sailpoint.com/"},"vendor_poc":"Dan Martillotti","vendor_phone":"5123462000","vendor_email":"dan.martillotti@sailpoint.com","assigned_lab":{"cctl_name":"Booz Allen Hamilton Common Criteria Testing Laboratory"},"product_description":"<p class=\"MsoNormal\"><span style=\"font-size: 10.0pt; font-family: 'Arial',sans-serif;\">The SailPoint IdentityIQ File Access Manager (FAM) version 8.1 (&ldquo;IdentityIQ FAM&rdquo;) application&rsquo;s primary functionality is to allow its users to review and manage the governed data created by IdentityIQ FAM for the monitoring of enterprise data stored on one or more managed resources. The governed data allows IdentityIQ FAM users to identify and classify data, understand on which managed resources within the network the data is stored, and understand which enterprise users have access to the data.</span></p>","evaluation_configuration":"<p class=\"MsoNormal\"><span style=\"font-size: 10.0pt; font-family: 'Arial',sans-serif;\">In the evaluated configuration, the Target of Evaluation (TOE) is the SailPoint IdentityIQ File Access Manager (FAM) 8.1 (&ldquo;IdentityIQ FAM&rdquo;) application is installed on a Windows Server 2019 and through APIs the TOE utilizes several functions of the operating system to perform its operations. The TOE relies on .NET Framework to function and Internet Information Services (IIS) to host its GUI web pages. <span style=\"mso-spacerun: yes;\">&nbsp;</span>The administrative interfaces include a local Fat Client for local access and a web GUI for remote access. The TOE is configured to securely communicate with the following external IT entities: LDAP Server, SQL Database, and Windows File Server(s). <span style=\"mso-spacerun: yes;\">&nbsp;</span><span style=\"mso-spacerun: yes;\"> &nbsp;</span></span></p>\r\n<p class=\"MsoNormal\"><span style=\"font-size: 10.0pt; font-family: 'Arial',sans-serif;\">SailPoint IdentityIQ FAM 8.1 is a software-only TOE and therefore its physical boundary is its software. The TOE does not include the hardware or operating system of the system on which it is installed. It also does not include the third party software which is required for the TOE to run. The following table lists the components that are required for the TOE&rsquo;s use in the evaluated configuration. These Operational Environment components are expected to be patched to include the latest security fixes for each component.</span></p>\r\n<table class=\"ST-TABLE1\" style=\"margin-left: .25pt; border-collapse: collapse; border: none; mso-border-alt: solid #7BA0CD 1.0pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.75pt 0in 5.75pt;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<tbody>\r\n<tr style=\"mso-yfti-irow: -1; mso-yfti-firstrow: yes; mso-yfti-lastfirstrow: yes;\">\r\n<td style=\"width: 146.5pt; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; background: black; padding: 0in 5.75pt 0in 5.75pt;\" width=\"195\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"line-height: 115%; page-break-after: avoid; mso-yfti-cnfc: 5;\"><strong><span style=\"font-size: 9.0pt; mso-bidi-font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri; color: white;\">OE Component</span></strong></p>\r\n</td>\r\n<td style=\"width: 284.5pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: black; padding: 0in 5.75pt 0in 5.75pt;\" width=\"379\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"text-align: center; line-height: 115%; page-break-after: avoid; mso-yfti-cnfc: 1;\" align=\"center\"><strong><span style=\"font-size: 9.0pt; mso-bidi-font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri; color: white;\">Requirement</span></strong></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 0;\">\r\n<td style=\"width: 146.5pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" width=\"195\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"line-height: 115%; page-break-after: avoid; mso-yfti-cnfc: 68;\"><strong><span style=\"font-size: 9.0pt; mso-bidi-font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">Host Platform</span></strong></p>\r\n</td>\r\n<td style=\"width: 284.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" valign=\"top\" width=\"379\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"text-align: center; line-height: 115%; page-break-after: avoid; mso-yfti-cnfc: 64;\" align=\"center\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">Microsoft Windows Server 2019 Datacenter (1809)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 1;\">\r\n<td style=\"width: 146.5pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.75pt 0in 5.75pt;\" width=\"195\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"line-height: 115%; page-break-after: avoid; mso-yfti-cnfc: 132;\"><strong><span style=\"font-size: 9.0pt; mso-bidi-font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">Host Platform OS Type</span></strong></p>\r\n</td>\r\n<td style=\"width: 284.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.75pt 0in 5.75pt;\" valign=\"top\" width=\"379\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"text-align: center; line-height: 115%; page-break-after: avoid; mso-yfti-cnfc: 128;\" align=\"center\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">(includes: IIS, .NET, and SMB services)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 2;\">\r\n<td style=\"width: 146.5pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" width=\"195\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"line-height: 115%; page-break-after: avoid; tab-stops: 0in; mso-yfti-cnfc: 68;\"><strong><span style=\"font-size: 9.0pt; mso-bidi-font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">Host Server&rsquo;s Processor</span></strong></p>\r\n</td>\r\n<td style=\"width: 284.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" valign=\"top\" width=\"379\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"text-align: center; line-height: 115%; page-break-after: avoid; mso-yfti-cnfc: 64;\" align=\"center\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">64-bit</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 3;\">\r\n<td style=\"width: 146.5pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.75pt 0in 5.75pt;\" width=\"195\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"line-height: 115%; page-break-after: avoid; tab-stops: 0in; mso-yfti-cnfc: 132;\"><strong><span style=\"font-size: 9.0pt; mso-bidi-font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">SQL Database</span></strong></p>\r\n</td>\r\n<td style=\"width: 284.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.75pt 0in 5.75pt;\" valign=\"top\" width=\"379\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"text-align: center; line-height: 115%; page-break-after: avoid; mso-yfti-cnfc: 128;\" align=\"center\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">Intel Xeon Gold 6230 (Cascade Lake)</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 4; mso-yfti-lastrow: yes;\">\r\n<td style=\"width: 146.5pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" width=\"195\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"line-height: 115%; page-break-after: avoid; mso-yfti-cnfc: 68;\"><strong><span style=\"font-size: 9.0pt; mso-bidi-font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">LDAP Server</span></strong></p>\r\n</td>\r\n<td style=\"width: 284.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\" valign=\"top\" width=\"379\">\r\n<p class=\"MsoNormalCxSpMiddle\" style=\"text-align: center; line-height: 115%; page-break-after: avoid; mso-yfti-cnfc: 64;\" align=\"center\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">SQL Server 2016</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n<p class=\"MsoNormal\"><span style=\"font-size: 10.0pt; font-family: 'Arial',sans-serif;\"><br />IdentityIQ FAM&rsquo;s primary functionality of monitoring enterprise data was not evaluated, except where the product&rsquo;s functionality relates to the Security Functional Requirements (SFRs) included within the scope of the evaluation.</span></p>","security_evaluation_summary":"<p class=\"MsoNormal\"><span style=\"font-size: 10.0pt; font-family: 'Arial',sans-serif;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. SailPoint IdentityIQ File Access Manager 8.1 was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 3.1 Revision 5. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 Revision 5. The product, when installed and configured per the instructions provided in the preparative guidance, satisfies all of the security functional requirements stated in the <em style=\"mso-bidi-font-style: normal;\">SailPoint IdentityIQ File Access Manager 8.1 Security Target Version 1.10, November 30, 2020</em>. The evaluation underwent CCEVS Validator review. The evaluation was completed in December 2020. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, CCEVS-VR-VID<span style=\"color: #000006;\">11116</span> -2020 prepared by CCEVS.</span></p>","environmental_strengths":"<h3 style=\"text-indent: -.5in; line-height: 115%; mso-pagination: widow-orphan lines-together; page-break-after: avoid; border: none; mso-padding-alt: 0in 0in 0in 0in; margin: 10.0pt 0in 6.0pt .5in;\"><a name=\"_Toc523167275\"></a><a name=\"_Toc461559894\"></a><span style=\"mso-bookmark: _Toc523167275;\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif;\">Cryptographic Support</span></span></h3>\r\n<p class=\"MsoNormal\"><a name=\"_Toc461559895\"></a><a name=\"_Toc473032270\"></a><a name=\"_Toc468112259\"></a><a name=\"_Toc468181769\"></a><a name=\"_Toc469052033\"></a><a name=\"_Toc469401982\"></a><a name=\"_Toc468112260\"></a><a name=\"_Toc468181770\"></a><a name=\"_Toc469052034\"></a><a name=\"_Toc469401983\"></a><span style=\"mso-bookmark: _Toc461559895;\"><span style=\"font-size: 10.0pt; font-family: 'Arial',sans-serif;\">The TOE invokes the Windows platform&rsquo;s cryptographic services to secure data in transit communication. Due to this, the TOE does not <span style=\"mso-bidi-font-style: italic;\">directly invoke any DRBG functionality</span> nor does the TOE perform generation of asymmetric cryptographic keys. The TOE also uses the Windows platform&rsquo;s Data Protection API to store the credentials for accessing the SQL database.</span></span></p>\r\n<h3 style=\"text-indent: -.5in; line-height: 115%; mso-pagination: widow-orphan lines-together; page-break-after: avoid; border: none; mso-padding-alt: 0in 0in 0in 0in; margin: 10.0pt 0in 6.0pt .5in;\"><span style=\"mso-bookmark: _Toc461559895;\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif;\">User Data Protection</span></span></h3>\r\n<p class=\"MsoNormal\" style=\"margin-top: 6.0pt; line-height: 115%; mso-pagination: none;\"><a name=\"_Toc523167277\"></a><a name=\"_Toc461559896\"></a><span style=\"mso-bookmark: _Toc523167277;\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri; color: black; mso-bidi-font-style: italic;\">The TOE relies on the Windows platform to handle the following network connections, to include all of their cryptographic operations:</span></span></p>\r\n<ul style=\"margin-top: 0in;\" type=\"disc\">\r\n<li class=\"MsoNormalCxSpMiddle\" style=\"margin-top: 6.0pt; margin-bottom: 6.0pt; mso-add-space: auto; line-height: 115%; mso-pagination: none; mso-list: l0 level1 lfo1;\"><span style=\"mso-bookmark: _Toc461559896;\"><span style=\"mso-bookmark: _Toc523167277;\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">respond to TLS connection requests from an Activity Monitor to receive managed resource data, </span></span></span></li>\r\n<li class=\"MsoNormalCxSpMiddle\" style=\"margin-top: 6.0pt; margin-bottom: 6.0pt; mso-add-space: auto; line-height: 115%; mso-pagination: none; mso-list: l0 level1 lfo1;\"><span style=\"mso-bookmark: _Toc461559896;\"><span style=\"mso-bookmark: _Toc523167277;\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">initiate a TLS connection to an LDAP server to perform authentication requests and query enterprise user account information, and</span></span></span></li>\r\n<li class=\"MsoNormalCxSpLast\" style=\"margin-top: 6.0pt; margin-bottom: 6.0pt; mso-add-space: auto; line-height: 115%; mso-pagination: none; mso-list: l0 level1 lfo1;\"><span style=\"mso-bookmark: _Toc461559896;\"><span style=\"mso-bookmark: _Toc523167277;\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Calibri;\">initiate a TLS connection to read and write TOE configuration data and governed data to the SQL database.</span></span></span></li>\r\n</ul>\r\n<h3 style=\"text-indent: -.5in; line-height: 115%; mso-pagination: widow-orphan lines-together; page-break-after: avoid; border: none; mso-padding-alt: 0in 0in 0in 0in; margin: 10.0pt 0in 6.0pt .5in;\"><span style=\"mso-bookmark: _Toc461559896;\"><span style=\"mso-bookmark: _Toc523167277;\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif;\">Security Management</span></span></span></h3>\r\n<p class=\"MsoNormal\"><a name=\"_Toc461559897\"></a><span style=\"font-size: 10.0pt; font-family: 'Arial',sans-serif;\">The administrator that installs the TOE will set the initial credentials for accessing the TOE and will also be assigned the owner permissions for the TOE&rsquo;s software by the Windows platform. Due to the Windows platform&rsquo;s access permissions and the TOE&rsquo;s install directory being C:\\Program Files, the TOE&rsquo;s binaries and data files are protected from unprivileged modification. The TOE&rsquo;s administrators are able to configure the TOE and perform tasks via the TOE&rsquo;s GUI and fat client. All TOE configuration options are stored in the remote SQL database.</span></p>\r\n<h3 style=\"text-indent: -.5in; line-height: 115%; mso-pagination: widow-orphan lines-together; page-break-after: avoid; border: none; mso-padding-alt: 0in 0in 0in 0in; margin: 10.0pt 0in 6.0pt .5in;\"><span style=\"mso-bookmark: _Toc461559897;\"><a name=\"_Toc523167278\"></a><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif;\">Privacy</span></span></h3>\r\n<p class=\"MsoNormal\"><span style=\"mso-bookmark: _Toc461559897;\"><span style=\"mso-bookmark: _Toc523167278;\"><span style=\"font-size: 10.0pt; font-family: 'Arial',sans-serif;\">The TOE ensures the privacy of its administrators and users by not providing any ability to collect or transmit personally identifiable information (PII) over the network.</span></span></span></p>\r\n<h3 style=\"text-indent: -.5in; line-height: 115%; mso-pagination: widow-orphan lines-together; page-break-after: avoid; border: none; mso-padding-alt: 0in 0in 0in 0in; margin: 10.0pt 0in 6.0pt .5in;\"><span style=\"mso-bookmark: _Toc461559897;\"><span style=\"mso-bookmark: _Toc523167278;\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif;\">Protection of the TSF</span></span></span></h3>\r\n<p class=\"MsoNormal\"><a name=\"_Toc461559898\"></a><span style=\"font-size: 10.0pt; font-family: 'Arial',sans-serif;\">The TOE relies on the Windows platform to request memory and will not request an explicit memory address. The TOE does not allocate any memory region with both write and execute permissions. As a .NET framework application, the TOE has stack-based buffer overflow protections. The TOE uses a number of Windows platform APIs and third party libraries as part of its operation.</span></p>\r\n<p class=\"MsoNormal\"><span style=\"mso-bookmark: _Toc461559898;\"><span style=\"font-size: 10.0pt; font-family: 'Arial',sans-serif;\">Administrators can verify the TOE&rsquo;s version by checking any of the TOE&rsquo;s binary files or by authenticating to the fat client. The TOE automatically checks its software version against the latest available software version provided by SailPoint. TOE software, including patch updates, is signed with a DigiCert certificate. Administrators can initiate the software update process through the fat client. The TOE&rsquo;s uninstallation process results in the deletion of all traces of the application, with the exception of configuration settings, output files, and audit/log events. </span></span></p>\r\n<h3 style=\"text-indent: -.5in; line-height: 115%; mso-pagination: widow-orphan lines-together; page-break-after: avoid; border: none; mso-padding-alt: 0in 0in 0in 0in; margin: 10.0pt 0in 6.0pt .5in;\"><a name=\"_Toc523167280\"></a><a name=\"_Toc461559899\"></a><span style=\"mso-bookmark: _Toc523167280;\"><span style=\"font-size: 10.0pt; line-height: 115%; font-family: 'Arial',sans-serif;\">Trusted Path/Channels</span></span></h3>\r\n<p class=\"MsoNormal\"><span style=\"font-size: 10.0pt; font-family: 'Arial',sans-serif;\">The TOE invokes the Windows platform to encrypt all data-in-transit communications between itself and another trusted IT product. The trusted IT products, encryption protocols used, and the purpose of the connection have been described under the &ldquo;User Data Protection&rdquo; section above.</span></p>","features":[]}