{"product_id":11306,"v_id":11306,"product_name":"Trustwave AppDetectivePRO version 10.2","certification_status":"Certified","certification_date":"2023-09-20T00:00:00Z","tech_type":"Application Software","vendor_id":{"name":"Trustwave Holdings Inc","website":"www.trustwave.com"},"vendor_poc":"Anirban Chowdhuri","vendor_phone":"312-873-7500","vendor_email":"achowdhuri@trustwave.com","assigned_lab":{"cctl_name":"Acumen Security"},"product_description":"<p class=\"MsoNormal\">AppDetectivePRO (also referred to as ADP) is application software that performs scanning of databases as configured by authorized users. Authorized administrators configure the list of Windows users that may use the ADP application. Authorized users then configure databases (assets) to be scanned, associate policies applicable to each database, and review the results of the scans.</p>\r\n<p class=\"MsoNormal\">All interactions of administrators and users with the TOE is via a GUI provided by the ADP application. The TOE performs automated scanning of the configured databases hosted on the same Microsoft Windows 10 instance. The scanning functionality is referred to as the Scan Engine.</p>","evaluation_configuration":"","security_evaluation_summary":"<p class=\"MsoNormal\" style=\"mso-outline-level: 1;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) requirements and guidance.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation demonstrated that <span style=\"mso-bidi-font-style: italic;\">the TOE </span>meets the security requirements contained in the Security Target.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The criteria against which the TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 5, April 2017. The evaluation methodology used by the Evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 3.1, Revision 5, April 2017.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when delivered and configured as identified in the Trustwave AppDetectivePRO v10.2 <span style=\"mso-no-proof: yes;\">User Guide</span>, <span style=\"mso-no-proof: yes;\">July 2021</span> document, satisfies all of the security functional requirements stated in the AppDetectivePRO v10.2<span style=\"mso-no-proof: yes;\"> Security Target</span>, Version 1.9, September 20<span style=\"mso-no-proof: yes;\">, 2023</span>.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The project underwent CCEVS Validator review.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in <span style=\"mso-no-proof: yes;\">September 2023</span>.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID<span style=\"mso-no-proof: yes;\">11306-2023</span>) prepared by CCEVS.</p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"margin-bottom: 0in;\"><span style=\"mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;\">The TOE provides the security functionality required by [</span>SWAPP<span style=\"mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;\">].</span></p>\r\n<h4 style=\"margin-left: 0in; text-indent: 0in; mso-list: none;\"><strong><span style=\"mso-bidi-font-family: 'Calibri Light'; mso-bidi-theme-font: major-latin; color: windowtext;\">3.1 Cryptographic Support</span></strong></h4>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in;\"><span style=\"mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;\">The TOE does not generate keys, use a DRBG or store credentials.</span></p>\r\n<h4 style=\"margin-left: 0in; text-indent: 0in; mso-list: none;\"><strong><span style=\"mso-bidi-font-family: 'Calibri Light'; mso-bidi-theme-font: major-latin; color: windowtext;\">3.2 User Data Protection </span></strong></h4>\r\n<p class=\"MsoNormal\"><span style=\"mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;\">The TOE ensures that all sensitive application data is encrypted and protected. The TOE does not maintain sensitive information repositories and it restricts its access only to network connectivity. The TOE restricts inbound and outbound network communications only to user-initiated network communication for scanning configured databases.</span></p>\r\n<h4 style=\"margin-left: 0in; text-indent: 0in; mso-list: none;\"><strong><span style=\"mso-bidi-font-family: 'Calibri Light'; mso-bidi-theme-font: major-latin; color: windowtext;\">3.3 Security Management</span></strong></h4>\r\n<p class=\"MsoNormal\"><span style=\"mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;\">The TOE does not come with any default credentials. The user installing the TOE is automatically configured as an authorized Administrator.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Administrators may authorize additional users to execute the ADP application.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Authorized users may use the ADP application to manage Assets and Policies and execute scans.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Scan results may also be viewed. </span></p>\r\n<h4 style=\"margin-left: 0in; text-indent: 0in; mso-list: none;\"><strong><span style=\"mso-bidi-font-family: 'Calibri Light'; mso-bidi-theme-font: major-latin; color: windowtext;\">3.4 Privacy</span></strong></h4>\r\n<p class=\"MsoNormal\"><span style=\"mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;\">The TOE itself does not contain or transmit any PII.</span></p>\r\n<h4 style=\"margin-left: 0in; text-indent: 0in; mso-list: none;\"><strong><span style=\"mso-bidi-font-family: 'Calibri Light'; mso-bidi-theme-font: major-latin; color: windowtext;\">3.5 Protection of the TSF</span></strong></h4>\r\n<p class=\"MsoNormal\"><span style=\"mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;\">The TOE employs several mechanisms to ensure that it is secure on the host platform. Only documented platform APIs are used by the TOE. The TOE never allocates memory with both write and execute permission. Evaluated platform functionality is used to verify the TOE version and perform updates.</span></p>\r\n<h4 style=\"margin-left: 0in; text-indent: 0in; mso-list: none;\"><strong><span style=\"mso-bidi-font-family: 'Calibri Light'; mso-bidi-theme-font: major-latin; color: windowtext;\">3.6 Trusted Path/Channels</span></strong></h4>\r\n<p class=\"MsoNormal\">The TOE does not transmit sensitive data.</p>","features":[]}