{"product_id":11371,"v_id":11371,"product_name":"Veeam ONE v12","certification_status":"Certified","certification_date":"2023-08-18T00:00:00Z","tech_type":"Application Software","vendor_id":{"name":"Veeam Software Corporation","website":"www.veeam.com"},"vendor_poc":"Jose R. Mendoza","vendor_phone":"678-353-2156","vendor_email":"jose.mendoza@veeam.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p class=\"Body\">The Target of Evaluation (TOE) is Veeam ONE v12. The TOE provides a monitoring and analytics solution for backup, virtual and physical environments, providing support for Veeam Backup &amp; Replication&trade; and Veeam Agents, as well as VMware, Hyper-V and Nutanix AHV<span style=\"font-family: 'Calibri',sans-serif;\">.</span></p>\r\n<p class=\"Body\">Veeam ONE v12 is a software application. In its evaluated configuration, it is installed on an instance of Microsoft Windows Server 2019 executing on an x86-64 processor with the following additional software components, which are included in the Veeam ONE setup package:</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; text-indent: -.5in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\"><span style=\"mso-list: Ignore;\">&bull;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Microsoft .NET Framework 4.7.2 or later</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; text-indent: -.5in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\"><span style=\"mso-list: Ignore;\">&bull;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Microsoft .NET Core Runtime 3.1.16</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; text-indent: -.5in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\"><span style=\"mso-list: Ignore;\">&bull;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Microsoft Visual C++ 2015-2019 Redistributable (x64)</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; text-indent: -.5in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\"><span style=\"mso-list: Ignore;\">&bull;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Microsoft System CLR Types for SQL Server 2014</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; text-indent: -.5in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\"><span style=\"mso-list: Ignore;\">&bull;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Microsoft SQL Native Client 2012</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; text-indent: -.5in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\"><span style=\"mso-list: Ignore;\">&bull;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Microsoft SQL Server 2014 Management Objects</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; text-indent: -.5in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\"><span style=\"mso-list: Ignore;\">&bull;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Microsoft SQL Server 2012 Management Objects</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; text-indent: -.5in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\"><span style=\"mso-list: Ignore;\">&bull;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Microsoft OLE DB Driver for SQL Server</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; text-indent: -.5in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\"><span style=\"mso-list: Ignore;\">&bull;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Microsoft XML 6.0 Parser and SDK</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; text-indent: -.5in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\"><span style=\"mso-list: Ignore;\">&bull;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Microsoft ASP.NET Core Shared Framework 3.1.16</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; text-indent: -.5in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\"><span style=\"mso-list: Ignore;\">&bull;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Microsoft Universal C Runtime</p>\r\n<p class=\"Body\" style=\"margin-left: .75in; text-indent: -.5in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;\"><span style=\"mso-list: Ignore;\">&bull;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Microsoft SQL Server 2016 (Microsoft SQL Server 2016 Express edition is included in Veeam ONE setup).</p>\r\n<p class=\"Body\">The TOE additionally requires Microsoft SQL Server installed on the same host platform and a workstation with a web browser to connect to the TOE&rsquo;s user interface.</p>\r\n<p class=\"Body\">The TOE connects to an instance of the separately evaluated Veeam Backup and Replication (VBR) software to retrieve event logs of backup and recovery tasks performed by VBR and infrastructure information of the hosts to which VBR connects.</p>","evaluation_configuration":"","security_evaluation_summary":"<p><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme for the&nbsp;<em>Protection Profile for Application Software</em>, Version 1.4. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 release 5. The product, when delivered and configured as identified in the guidance documentation, satisfies all of the security functional requirements stated in the <em>Veeam ONE v12 Security Target</em>, Version 1.6, 9 July 2023. The evaluation was completed in August 2023. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report (report number CCEVS-VR-VID11371-2023) prepared by CCEVS.</span></p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Cryptographic Support</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE invokes platform-provided cryptography to protect data at rest and in transit.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">User Data Protection</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE accesses the minimum amount of Windows Server hardware and data in order to perform its function. The TOE stores database connectivity information in the Windows Registry and stores other TOE configuration information in the SQL Server database. </span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Security Management</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Both the TOE binary components themselves and the configuration settings they use are stored in locations recommended for Microsoft Windows Server.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE includes a console user interface (UI). Users must login to Windows and have permissions to access the UI in order to access the TOE.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Administrators may configure which VBR instances have their Event Logs analyzed by the TOE, and access reports resulting from that analysis.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Privacy</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE does not process any personally identifiable information (PII).</span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Protection of the TSF</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE enforces various mechanisms to prevent itself from being used as an attack vector to its Windows platform. The TOE implements address space layout randomization (ASLR), does not allocate any memory with both write and execute permissions, does not write user-modifiable files to directories that contain executable files, and is compatible with the Windows Defender security features of its host platform.</span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE contains libraries and invokes system APIs that are well known and explicitly identified. </span></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE has a mechanism to display its current software version.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE can be used to determine if software updates for it are available.<span style=\"mso-spacerun: yes;\">&nbsp; </span>If so, an administrator uses out of band mechanisms to acquire, validate, and install the update securely.</span></p>\r\n<p class=\"MsoNormal\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE developer provides a secure mechanism for receiving reports of security flaws.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>Product vulnerabilities are tracked and addressed. Availability of updates is announced via email sent to customers as well as via the Veeam website.</span></p>\r\n<p class=\"Body\">&nbsp;</p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 0in; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\"><span style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">Trusted Path/Channels</span></em></strong></p>\r\n<p class=\"Body\"><span style=\"font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;\">The TOE protects data in transit with remote administrators by invoking the platform-provided IIS.</span></p>","features":[{"id":1516,"feature_name":"Certificate Authentication"},{"id":1517,"feature_name":"Certificate Validation"},{"id":1518,"feature_name":"Credential Storage"},{"id":1519,"feature_name":"DRBG"},{"id":1520,"feature_name":"HTTPS Client"},{"id":1521,"feature_name":"HTTPS Server with Mutual Authentication"},{"id":1522,"feature_name":"PBKDF"}]}