{"product_id":11420,"v_id":11420,"product_name":"Cisco Email Security Appliance with AsyncOS 15.5","certification_status":"Certified","certification_date":"2024-09-13T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Cisco Systems, Inc.","website":"https://www.cisco.com"},"vendor_poc":"Petra Manche","vendor_phone":"+442088243415","vendor_email":"certteam@cisco.com","assigned_lab":{"cctl_name":"Lightship Security USA, Inc."},"product_description":"<p><span style=\"font-size: 12.0pt; font-family: 'Times New Roman', serif; color: black;\">The TOE, which consists of the Cisco Email Security Appliance, is a network device.</span></p>","evaluation_configuration":"<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">The TOE is a hardware and software solution that makes up the Cisco ESA. The TOE hardware includes the following: C195, C395, C695, C695F and the C100v, C300v, C600v running on Cisco UCS servers. The TOE software is the ESA AsyncOS software version 15.5. See table 5 in section 1.5 of the <em>Cisco Email Security Appliance Common Criteria Security Target</em> for a detailed specification for each TOE model.</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">&nbsp;</p>\r\n<p style=\"text-align: justify; margin: 0in; font-size: 10pt; font-family: Times, serif;\">In addition, if the TOE is to be remotely administered, then the management workstation must be connected to an internal network, SSHv2 must be used to remotely connect to the appliance for the CLI interface and HTTPS/TLS for the GUI interface.&nbsp;</p>\r\n<p><span style=\"font-size: 10.0pt; font-family: Times, serif;\">A syslog server is used to store audit records, and the connection is secured using SCP over SSHv2.&nbsp; It is recommended that these servers be installed on the internal (trusted) network.&nbsp; The internal (trusted) network is meant to be separated effectively from unauthorized individuals and user traffic, in a controlled environment where implementation of security policies can be enforced.</span></p>","security_evaluation_summary":"<p><span style=\"font-size: 10.0pt; font-family: Times, serif;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the&nbsp;<span style=\"font-size: 12.0pt; font-family: 'Times New Roman', serif;\">Cisco Email Security Appliance with AsyncOS 15.5</span> was evaluated are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 Rev. 5. The product, when configured as identified in the <em><span style=\"font-size: 12.0pt; font-family: 'Times New Roman', serif;\">Cisco Email Security Appliance running AsyncOS 15.5 Common Criteria Operational User Guidance And Preparative Procedures</span></em>, satisfies all of the security functional requirements stated in the <em><span style=\"font-size: 12.0pt; font-family: 'Times New Roman', serif;\">Cisco Email Security Appliance Common Criteria Security Target</span></em>. The project underwent CCEVS Validator review. The evaluation was completed in September 2024. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.</span></p>","environmental_strengths":"<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><strong>Security Audit</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The Cisco Email Security Appliance provides extensive auditing capabilities. The TOE generates a comprehensive set of audit logs that identify specific TOE operations. For each event, the TOE records the date and time of each event, the type of event, the subject identity, and the outcome of the event.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Auditable events include:</p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">failure on invoking cryptographic functionality such as establishment, termination and failure of cryptographic session establishments and connections;</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">modifications to the group of users that are part of the Authorized Administrator roles;</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">all use of the user identification mechanism;</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">any use of the authentication mechanism;</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Administrator lockout due to excessive authentication failures;</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">any change in the configuration of the TOE;</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">changes to time;</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">initiation of TOE update;</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">indication of completion of TSF self-test;</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">maximum sessions being exceeded;</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">termination of a remote session;</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">attempts to unlock a termination session and &nbsp;</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">initiation and termination of a trusted channel</li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE is configured to transmit its audit messages to an SCP server on a remote syslog server. Communication with the syslog server is protected using SCP over SSHv2, and the TOE can determine when communication with the syslog server fails.&nbsp; If the connection fails, the session will need to be reestablished following the configuration settings described in the Cisco Email Security Appliance (ESA) Common Criteria Configuration Guide document.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The audit logs can be viewed on the TOE using the appropriate CLI commands and GUI webpages.&nbsp; The records include the date/time the event occurred, the event/type of event, the user associated with the event, and additional information of the event and its success and/or failure.&nbsp; The TOE does not have an interface to modify audit records, though there is an interface available for the Authorized Administrator to clear audit data stored locally on the TOE.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><strong>Cryptographic Support</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE provides cryptography in support of other TOE security functionality.&nbsp; All the algorithms claimed have CAVP certificates, based on ESA on the platforms and processors as noted in section 3.1.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE provides cryptography in support of other Cisco ESA security functionality. The ESA software calls the Cisco FIPS Object Module (FOM) v7.3a that has been validated in accordance with the specified standards to meet the requirements listed below and all the algorithms claimed have CAVP certificates.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Refer to tables 9 and 10 in the <em>Cisco Email Security Appliance Common Criteria Security Target</em> for algorithm certificate references.&nbsp;</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE provides cryptography in support of remote administrative management via SSHv2 for the CLI and HTTPS/TLS for the GUI.&nbsp; SCP over SSHv2 is used to secure the transmission of audit records to the SCP server on the remote syslog server.&nbsp; In addition, the TOE uses the X.509v3 certificate for securing the TLS connections.&nbsp;</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE also authenticates software updates to the TOE using a published hash.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><strong>Identification and authentication</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE provides authentication services for administrative users connecting to the TOE&rsquo;s secure CLI and GUI administrative interfaces, using SSHv2 and HTTPS/TLS, respectively, to secure the connections.&nbsp; Prior to an administrator logging in, a login banner is presented at both the CLI and GUI interfaces. The TOE requires Authorized Administrators to be successfully identified and authenticated prior to being granted access to the TOE and any of the management functionality.&nbsp; The TOE can be configured to require a minimum password length of 15 characters as well as character complexity rules.&nbsp;</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE also provides an automatic lockout when a user attempts to authenticate but enters invalid information.&nbsp; When the threshold for a defined number of authentication attempt failures has exceeded the configured allowable attempts, the user is locked out until an Authorized Administrator can re-enable the user account.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE uses X.509v3 certificates as defined by RFC 5280 to support authentication for TLS connections.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><strong>Security Management</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE provides secure administrative services for management of general TOE configuration and the security functionality provided by the TOE.&nbsp; All TOE administration occurs either through a secure HTTPS/TLS (GUI interface), SSHv2 (CLI interface) session or via a direct local console connection.&nbsp; The TOE provides the ability to securely manage:</p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">ability to administer the TOE locally and remotely</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">ability to configure the access banner</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">ability to configure the session inactivity time before session termination or locking</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">ability to update the TOE, and to verify the updates using published hash prior to installing those updates</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">ability to configure the authentication failure parameters</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">ability to configure the cryptographic functionality</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">ability to re-enable an administrator account</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">ability to configure the audit behavior</li>\r\n<li style=\"margin: 0in 0in 6pt 0px; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">ability to set the time</li>\r\n</ul>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The CLI is the main interface used to administer the TOE, since all functionality to configure, securely manage and to monitor the TOE is available via the CLI. The GUI can also be used, but not all functionality to configure the TOE is available in the GUI.&nbsp; Therefore, in the evaluated configuration it is recommended to use the CLI to perform all configuration and setting of the security functions and to securely mange the TOE.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE supports the security administrator role and is referred to as the Authorized Administrator.&nbsp;&nbsp; Only the Authorized Administrator can perform the above security relevant management functions.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Authorized Administrators can create configurable login banners to be displayed at time of login and can define an inactivity timeout threshold for each admin interface to terminate sessions after a set period of inactivity has been reached.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><strong>Protection of the TSF</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE protects against interference and tampering by untrusted subjects by implementing identification, authentication, and access controls to limit configuration to Authorized Administrators. &nbsp;The TOE prevents reading of cryptographic keys and passwords.&nbsp; Additionally, Cisco AsyncOS is not a general-purpose operating system, and access to Cisco AsyncOS memory space is restricted to only Cisco AsyncOS functions.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE performs testing to verify correct operation of the TOE itself and of the cryptographic module.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE internally maintains the date and time.&nbsp; This date and time are used as the timestamp applied to audit records generated by the TOE.&nbsp; The TOE provides the Authorized Administrators the capability to update the TOE&rsquo;s clock manually to maintain a reliable timestamp.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">Finally, the TOE is able to verify any software updates prior to the software updates being installed on the TOE to avoid the installation of unauthorized software.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><strong>TOE Access</strong></p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE can terminate inactive sessions after an Authorized Administrator configurable time period.&nbsp; Once a session has been terminated, the TOE requires the user to be successfully re-identified and re-authenticated to establish a new session.&nbsp; Sessions can also be terminated if an Authorized Administrator enters the &ldquo;exit&rdquo; command.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\">The TOE can display an Authorized Administrator specified banner on the CLI and GUI management interfaces prior to allowing any administrative access to the TOE.</p>\r\n<p style=\"margin: 0in 0in 6pt; text-align: justify; line-height: 11pt; font-size: 10pt; font-family: Times, serif;\"><strong>Trusted path/Channels</strong></p>\r\n<p><span style=\"font-size: 10.0pt; font-family: Times, serif;\">The TOE allows trusted path to be established to itself from remote administrators over SSHv2 for the CLI and HTTPS/TLS for the GUI.&nbsp; The TOE also uses SCP over SSHv2 to push the audit logs to a SCP server on a remote syslog server.</span></p>","features":[{"id":2813,"feature_name":"Asymmetric Key Generation"},{"id":2809,"feature_name":"Auditing"},{"id":2826,"feature_name":"Certificate Authentication"},{"id":2820,"feature_name":"Certificate Validation"},{"id":2816,"feature_name":"Cryptographic Hashing"},{"id":2814,"feature_name":"Cryptographic Key Establishment"},{"id":2815,"feature_name":"Cryptographic Signature Verification"},{"id":2811,"feature_name":"DRBG"},{"id":2825,"feature_name":"HTTPS Server without Mutual Authentication"},{"id":2810,"feature_name":"Key Destruction"},{"id":2819,"feature_name":"Keyed-hash message authentication"},{"id":2823,"feature_name":"SSH Client"},{"id":2824,"feature_name":"SSH Server"},{"id":2827,"feature_name":"TLS 1.1"},{"id":2828,"feature_name":"TLS 1.2"},{"id":2821,"feature_name":"TLS Server without Mutual Authentication"},{"id":2812,"feature_name":"Virtual Network Device"}]}