{"product_id":11196,"v_id":11196,"product_name":"MobileIron Platform 11","certification_status":"Certified","certification_date":"2021-09-01T00:00:00Z","tech_type":"Mobility","vendor_id":{"name":"MobileIron, an Ivanti Company","website":"www.mobileiron.com"},"vendor_poc":"Babu Srinivasan","vendor_phone":"408-459-9634","vendor_email":"babu.srinivasan@ivanti.com","assigned_lab":{"cctl_name":"Gossamer Security Solutions"},"product_description":"<p class=\"Body\"><span style=\"font-family: 'Arial',sans-serif;\">The TOE is the MobileIron Platform composed of the following components:</span></p>\r\n<p class=\"Body\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo3; margin: 0in 0in 3.0pt .5in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style=\"font-family: 'Arial',sans-serif;\">MobileIron Core, Version 11</span></p>\r\n<p class=\"Body\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo3;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style=\"font-family: 'Arial',sans-serif;\">MobileIron Client &ndash; Mobile@Work for Android, Version 11</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Arial',sans-serif;\">The TOE is an MDM solution where the claimed security functions are implemented in a central MDM server &ndash; MobileIron Core - and distributed MDM agents &ndash; MobileIron Client.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Arial',sans-serif;\">MobileIron Core (<a href=\"http://www.mobileiron.com/en/products/core\">http://www.mobileiron.com/en/products/core</a>) integrates with backend enterprise IT systems and enables IT to define security and management policies for mobile apps, content and devices independent of the operating system. <span style=\"mso-spacerun: yes;\">&nbsp;</span>MobileIron Core enables mobile devices (including both Android and iOS mobile devices), application, and content management.</span></p>\r\n<p class=\"Body\" style=\"text-indent: -.25in; mso-list: l2 level1 lfo1; margin: 0in 0in 3.0pt .5in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style=\"font-family: 'Arial',sans-serif;\">Mobile device management capabilities are the primary focus of this evaluation and enable IT to securely manage mobile devices across mobile operating systems and provide secure corporate email, automatic device configuration, certificate-based security, and selective wiping of enterprise data from both corporate-owned as well as user-owned devices.</span></p>\r\n<p class=\"Body\" style=\"text-indent: -.25in; mso-list: l2 level1 lfo1; margin: 0in 0in 3.0pt .5in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style=\"font-family: 'Arial',sans-serif;\">Mobile application management capabilities are a secondary focus of this evaluation and help IT manage the entire application lifecycle, from making the applications available in the enterprise app storefront, facilitating deployment of applications to mobile devices, and retiring applications as necessary.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Arial',sans-serif;\">MobileIron Client&ndash; also known as Mobile@Work for Android &ndash; is an app downloaded by end users onto their mobile devices. It configures the device to function in an enterprise environment by enforcing the configuration and security policies set by the IT department. Once installed, it creates a secure MobileIron container to protect enterprise data and applications.</span></p>\r\n<p class=\"Body\" style=\"text-indent: -.25in; mso-list: l1 level1 lfo2; margin: 0in 0in 3.0pt .5in;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style=\"font-family: 'Arial',sans-serif;\">The MobileIron Client works with MobileIron Core to configure corporate email, Wi-Fi, VPN, and security certificates and to create a clear separation between personal and business information. This allows IT to selectively wipe only the enterprise data on the device if the user leaves or if the device falls out of compliance or is lost.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify;\"><span style=\"font-family: 'Arial',sans-serif;\">Note that MobileIron distributes a Mobile@Work for iOS application, however, given restrictions on the associated Apple iOS mobile devices it is incapable of implementing the required MDM agent security functions.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Rather, Mobile@Work for iOS is an optional component and serves only to direct the built-in iOS MDM agent to the MobileIron Core MDM server for enrollment.<span style=\"mso-spacerun: yes;\">&nbsp; </span>As such, this component does not implement any security functions.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Mobile@Work for iOS is not required to enroll an iOS device with the MobileIron Core MDM server &ndash; the Safari browser built into iOS devices can be used to enroll with the MobileIron Core MDM server with no other application support.</span></p>","evaluation_configuration":"<p class=\"Body\" style=\"page-break-after: avoid;\"><span style=\"font-family: arial, helvetica, sans-serif;\">The TOE is the MobileIron Platform composed of the following components:</span></p>\r\n<p class=\"Body\" style=\"text-indent: -.25in; mso-list: l1 level1 lfo1; margin: 0in 0in 3.0pt .5in;\"><span style=\"font-family: arial, helvetica, sans-serif;\"><!-- [if !supportLists]--><span style=\"mso-list: Ignore;\">&middot;<span style=\"font-style: normal; font-variant: normal; font-weight: normal; font-stretch: normal; font-size: 7pt; line-height: normal;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]-->MobileIron Core, Version 11</span></p>\r\n<p class=\"Body\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo1;\"><span style=\"font-family: arial, helvetica, sans-serif;\"><!-- [if !supportLists]--><span style=\"mso-list: Ignore;\">&middot;<span style=\"font-style: normal; font-variant: normal; font-weight: normal; font-stretch: normal; font-size: 7pt; line-height: normal;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><!--[endif]-->MobileIron Client &ndash; Mobile@Work for Android, Version 11</span></p>\r\n<p class=\"Body\" style=\"page-break-after: avoid;\"><span style=\"font-family: arial, helvetica, sans-serif;\"><u>MobileIron Core:</u></span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">MobileIron Core is a server based on a CentOS 7.6 Linux operating system (OS) with Apache 2.4 (or later) that runs on an Intel x64 architecture server platform.<span style=\"mso-spacerun: yes;\">&nbsp; </span>MobileIron supports the MobileIron Core operating as virtual deployments in VMWare ESXi (6.5, 6.7 or 7.0).</span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">MobileIron Core can optionally be configured to utilize an external LDAP server via a secure TLS channel to authenticate users.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\"><u>MobileIron Client:</u></span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">MobileIron Client consists of apps deployed on Android mobile devices. NIAP requires that MDM agents must be installed on NIAP-evaluated mobile devices in order to be evaluated using the MOD-MDMA10. At present there are a number of evaluated Samsung Galaxy mobile Android devices ranging from Android version 10 and 11 that can be used with the Android version of the MDM Agent.</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 3pt 0.75in; text-indent: -0.25in;\" align=\"left\"><span style=\"font-family: arial, helvetica, sans-serif;\"><!-- [if !supportLists]-->&middot;<span style=\"font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><!--[endif]-->(NIAP VID 11042, https://www.niap-ccevs.org/Product/Compliant.cfm?PID=11042) Samsung Galaxy Devices on Android 10: Samsung Galaxy S20</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 3pt 0.75in; text-indent: -0.25in;\" align=\"left\"><span style=\"font-family: arial, helvetica, sans-serif;\"><!-- [if !supportLists]-->&middot;<span style=\"font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><!--[endif]-->(NIAP VID 11109, https://www.niap-ccevs.org/Product/Compliant.cfm?PID=11109) Samsung Galaxy Devices on Android 10: Samsung Galaxy A71</span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 3pt 0.75in; text-indent: -0.25in;\" align=\"left\"><span style=\"font-family: arial, helvetica, sans-serif;\">&middot;<span style=\"font-variant-numeric: normal; font-variant-east-asian: normal; font-stretch: normal; font-size: 7pt; line-height: normal;\">&nbsp; &nbsp; &nbsp; &nbsp;</span>(NIAP VID 11160, <a href=\"../../Product/Compliant.cfm?PID=11160\"><span style=\"color: windowtext; text-decoration-line: none;\">https://www.niap-ccevs.org/Product/Compliant.cfm?PID=11160</span></a>) Samsung Galaxy Devices on Android 11</span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">MobileIron Core can manage devices with the iOS MDM agent developed and evaluated by Apple Inc. &ndash; that agent has been evaluated on Apple iPad and iPhone Mobile Devices with iOS 13 (NIAP VID 11036).</span></p>","security_evaluation_summary":"<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><span style=\"font-family: arial, helvetica, sans-serif;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation demonstrated that <span style=\"mso-bidi-font-style: italic;\">the TOE </span>meets the security requirements contained in the Security Target.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when delivered and configured as identified in the <span style=\"mso-no-proof: yes;\">MobileIron</span> <span style=\"mso-no-proof: yes;\">Core and Android and iOS Client Mobile Device Management Protection Profile Guide 11</span>, <span style=\"mso-no-proof: yes;\">August 2021</span> document, satisfies all of the security functional requirements stated in the <span style=\"mso-no-proof: yes;\">MobileIron Platform 11 Security Target</span>, Version <span style=\"mso-no-proof: yes;\">0.6</span>, <span style=\"mso-no-proof: yes;\">August 31, 2021</span>.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The project underwent CCEVS Validator review.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in <span style=\"mso-no-proof: yes;\">September 2021</span>.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID<span style=\"mso-no-proof: yes;\">11196-2021</span>) prepared by CCEVS.</span></p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><span style=\"font-family: arial, helvetica, sans-serif;\">The logical boundaries of the <span style=\"mso-no-proof: yes;\">MobileIron Platform</span> are realized in the security functions that it implements. Each of these security functions is summarized below.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><span style=\"font-family: arial, helvetica, sans-serif;\"><strong>Security audit:</strong></span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">The MDM Server can generate and store audit records for security-relevant events as they occur. These events are stored and protected by the MDM Server and can be reviewed by an authorized administrator. The MDM Server can be configured to export the audit records in either in CSV (comma separated values) format, text format, or a compressed archive format utilizing TLS for protection of the records on the network. The MDM Server also supports the ability to query information about MDM agents and export MDM configuration information.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; text-align: justify;\"><span style=\"font-family: arial, helvetica, sans-serif;\">The MDM Agent can generate audit records for security-relevant events and includes the ability to indicate (i.e., respond) when it has been enrolled and when policies are successfully applied to the MDM Agent. The MDM Server can be configured to alert an administrator based on its configuration. For example, it can be configured to alert the administrator when a policy update fails or an MDM Agent has been enrolled.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; page-break-after: avoid; mso-outline-level: 1;\"><span style=\"font-family: arial, helvetica, sans-serif;\"><strong>Cryptographic support:</strong></span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">The MDM Server and MDM Agent both include and/or utilize cryptographic modules with certified algorithms for a wide range of cryptographic functions including: asymmetric key generation and establishment, encryption/decryption, cryptographic hashing and keyed-hash message authentication. These functions are supported with suitable random bit generation, initialization vector generation, secure key storage, and key and protected data destruction.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">The primitive cryptographic functions are used to implement security communication protocols: TLS and HTTPS used for communication between the MDM Server and MDM Agent and between the MDM Server and remote administrators.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; page-break-after: avoid; mso-outline-level: 1;\"><span style=\"font-family: arial, helvetica, sans-serif;\"><strong>Identification and authentication:</strong></span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">The MDM Server requires mobile device users (MD users) and administrators to be authenticated prior to allowing any security-related functions to be performed. This includes MD users enrolling their device in the MDM Server using a corresponding MDM Agent as well as an administrator logging on to manage the MDM Server configuration, MDM policies for mobile devices, etc.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">In addition, both the MDM Server and MDM Agent utilize X.509 certificates, including certificate validation checking, in conjunction with TLS to secure communications between the MDM Server and MDM Agents as well as between the MDM Server and administrators using a web-based user interface for remote administrative access.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><span style=\"font-family: arial, helvetica, sans-serif;\"><strong>Security management:</strong></span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">The MDM Server is designed to include at least two distinct user roles: administrator and mobile device user (MD user). The former interacts directly with the MDM Server while the latter is the user of a mobile device hosting an MDM Agent. The MDM Server further supports the fine-grain assignment of role (access to management function) to defined users allowing the definition of multiple user and administrator roles with different capabilities and responsibilities.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">The MDM Server provides all the function necessary to manage its own security functions as well as to manage mobile device policies that are sent to MDM Agents. In addition, the MDM Server ensures that security management functions are limited to authorized administrators while allowing MD users to perform only necessary functions such as enrolling in the MDM Server.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">The MDM Agents provide the functions necessary to securely communicate with and enroll in a MDM Server, implement policies received from an enrolled MDM Server, and report the results of applying policies.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><span style=\"font-family: arial, helvetica, sans-serif;\"><strong>Protection of the TSF:</strong></span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">The MDM Server and MDM Agent work together to ensure that all security related communication between those components is protected from disclosure and modification.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">Both the MDM Server and MDM Agent include self-testing capabilities to ensure that they are functioning properly. The MDM Server also has the ability to cryptographically verify during start-up that its executable image has not been corrupted.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">The MDM Server also includes mechanisms (i.e., verification of the digital signature of each new image) so that the TOE itself can be updated while ensuring that the updates will not introduce malicious or other unexpected changes in the TOE.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><span style=\"font-family: arial, helvetica, sans-serif;\"><strong>TOE access:</strong></span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">The MDM Server has the capability to display an advisory banner when users attempt to login in order to manage the TOE using the web-based and command-line based user interfaces.</span></p>\r\n<p class=\"MsoNormal\" style=\"text-align: justify; mso-outline-level: 1;\"><span style=\"font-family: arial, helvetica, sans-serif;\"><strong>Trusted path/channels:</strong></span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">The MDM Server uses TLS/HTTPS to secure communication channels between itself and remote administrators accessing the TOE via a web-based user interface.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">The MDM Server can optionally be configured to use TLS to communicate with an LDAP server for user authentication.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">It also uses TLS to secure communication channels between itself and mobile device users (MD users). In this latter case, the protected communication channel is established between the MDM Server and applicable MDM Agent on the user&rsquo;s mobile device.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: arial, helvetica, sans-serif;\">In addition, the MDM Server implements a restricted shell (CLISH) that is accessible via SSH to provide access to low level management functions.</span></p>","features":[]}