{"product_id":11520,"v_id":11520,"product_name":"SailPoint IdentityIQ v8.3p5","certification_status":"Certified","certification_date":"2025-02-12T00:00:00Z","tech_type":"Enterprise Security Management","vendor_id":{"name":"SailPoint Technologies, Inc.","website":"www.sailpoint.com/"},"vendor_poc":"Dan Martilotti","vendor_phone":"512-346-2000","vendor_email":"dan.martillotti@sailpoint.com","assigned_lab":{"cctl_name":"Booz Allen Hamilton Common Criteria Testing Laboratory"},"product_description":"<p>IdentityIQ is a governance-based Identity and Access Management (IAM) software solution. It integrates compliance management and provisioning in a unified solution that leverages a common identity governance framework. IdentityIQ provides a variety of IAM processes that include automated access certifications, policy management, access request and provisioning, password management and identity intelligence.</p>","evaluation_configuration":"<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; font-family: Calibri, sans-serif;\">The TOE is a software product. The physical boundary of the TOE includes the IdentityIQ software that is installed on top of the Apache Tomcat application server. The TOE does not include the hardware or operating systems of the systems on which it is installed. It also does not include the third-party software which is required for the TOE to run. The following table lists the software components that are required for the TOE&rsquo;s use in the evaluated configuration. These Operational Environment components are expected to be patched to include the latest security fixes for each component.</span></p>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><strong><span style=\"font-family: Calibri, sans-serif;\">&nbsp;</span></strong></span></p>\r\n<table class=\"MsoNormalTable\" style=\"border-collapse: collapse; border: none;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\r\n<tbody>\r\n<tr>\r\n<td style=\"width: 151.05pt; border: solid windowtext 1.0pt; background: black; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><strong><span style=\"line-height: 115%; font-family: Calibri, sans-serif; color: white;\">Component</span></strong></span></p>\r\n</td>\r\n<td style=\"width: 292.45pt; border: solid windowtext 1.0pt; border-left: none; background: black; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"text-align: center; line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><strong><span style=\"line-height: 115%; font-family: Calibri, sans-serif; color: white;\">Requirement</span></strong></span></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 151.05pt; border: solid windowtext 1.0pt; border-top: none; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><strong><span style=\"line-height: 115%; font-family: Calibri, sans-serif; color: black;\">Server OS</span></strong></span></p>\r\n</td>\r\n<td style=\"width: 292.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"text-align: center; line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">Microsoft Windows Server 2022</span></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 151.05pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><strong><span style=\"line-height: 115%; font-family: Calibri, sans-serif;\">OS Type</span></strong></span></p>\r\n</td>\r\n<td style=\"width: 292.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"text-align: center; line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif;\">64-bit</span></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 151.05pt; border: solid windowtext 1.0pt; border-top: none; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><strong><span style=\"line-height: 115%; font-family: Calibri, sans-serif; color: black;\">Application Server</span></strong></span></p>\r\n</td>\r\n<td style=\"width: 292.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"text-align: center; line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">Apache Tomcat 9.0</span></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 151.05pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><strong><span style=\"line-height: 115%; font-family: Calibri, sans-serif;\">Database</span></strong></span></p>\r\n</td>\r\n<td style=\"width: 292.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"text-align: center; line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif;\">Oracle 19c</span></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 151.05pt; border: solid windowtext 1.0pt; border-top: none; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><strong><span style=\"line-height: 115%; font-family: Calibri, sans-serif; color: black;\">Authentication Store</span></strong></span></p>\r\n</td>\r\n<td style=\"width: 292.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; background: #D9D9D9; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"text-align: center; line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">Windows Server 2022 Active Directory</span></p>\r\n</td>\r\n</tr>\r\n<tr>\r\n<td style=\"width: 151.05pt; border: solid windowtext 1.0pt; border-top: none; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><strong><span style=\"line-height: 115%; font-family: Calibri, sans-serif;\">Java Platform</span></strong></span></p>\r\n</td>\r\n<td style=\"width: 292.45pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.75pt 0in 5.75pt;\">\r\n<p style=\"text-align: center; line-height: 115%; break-after: avoid; margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif;\">Oracle JDK 17</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\">&nbsp;</p>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><span style=\"font-family: Calibri, sans-serif;\">In addition to the server requirements, a web browser is required for any system used to administer the TOE. In the evaluated configuration, the TOE was tested using Chrome version 118 or later and the compatibility of other browsers was not assessed</span><span style=\"font-family: Calibri, sans-serif;\">.</span></span></p>","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. SailPoint IdentityIQ version 8.3p5 was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 3.1 Revision 4. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 Revision 4. The product, when installed and configured per the instructions provided in the preparative guidance, satisfies all of the security functional requirements stated in the SailPoint IdentityIQ v8.3p5 Security Target Version 1.0. The evaluation underwent CCEVS Validator review. The evaluation was completed in January 2025. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, (report number CCEVS-VR-VID11520-2025, dated February 2025) prepared by CCEVS.</p>","environmental_strengths":"<h3 style=\"margin: 10pt 0in 6pt 0.5in; text-indent: -0.5in; line-height: 115%; break-after: avoid; border: none; padding: 0in; font-size: 12pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">Enterprise Security Management</span></h3>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; font-family: Calibri, sans-serif; color: black;\">The TOE performs enterprise user authentication using Active Directory as well as its own authentication mechanisms within the Operational Environment. IdentityIQ requires each user to enter valid identification in the form of a username and authentication in the form of a password to gain access to the TOE.</span></p>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; font-family: Calibri, sans-serif; color: black;\">&nbsp;</span></p>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><span style=\"font-family: Calibri, sans-serif; color: black;\">IdentityIQ uses connectors that are provided by the Operational Environment to communicate with third-party ESM products. In the evaluated configuration, IdentityIQ connects to Active Directory using the ADSI connector. The TOE will read and directly manage user data as well as configuration information, such as policy data, from any connected Active Directory. The TOE will also push user data to any instance of Active Directory to allow enterprise users to be centrally managed and address any conflicts of user data throughout the enterprise.</span><span style=\"font-family: Calibri, sans-serif; color: black;\"> </span></span></p>\r\n<h3 style=\"margin: 10pt 0in 6pt 0.5in; text-indent: -0.5in; line-height: 115%; break-after: avoid; border: none; padding: 0in; font-size: 12pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">Security Audit</span></h3>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><span style=\"font-family: Calibri, sans-serif; color: black;\">The TOE generates audit records of its behavior and administrator activities. Audit data includes date, time, event type, subject identity, and other data as required. Audit data is written to a remote Oracle 19c database. The communication between the TOE and the remote database is secured using TLS that is provided by the JRE&rsquo;s JDBC that resides in the Operational Environment</span><span style=\"font-family: Calibri, sans-serif; color: black;\">.</span></span></p>\r\n<h3 style=\"margin: 10pt 0in 6pt 0.5in; text-indent: -0.5in; line-height: 115%; break-after: avoid; border: none; padding: 0in; font-size: 12pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">Identification and Authentication</span></h3>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; font-family: Calibri, sans-serif; color: black;\">When an administrator authenticates to the TOE, the TOE will associate the username with a principal. The principal, along with the capabilities, rights, and dynamic scopes determine the access that the administrator will have while logged into the TOE.</span></p>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\">&nbsp;</p>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><span style=\"font-family: Calibri, sans-serif; color: black;\">The TOE provides mechanisms to reduce the likelihood of unauthorized access. The TOE is able to lock out an administrative account after a specific number of unsuccessful authentication attempts. This setting is defaulted to lockout users after five failed authentication attempts but is configurable by an administrator. Password complexity, history, length, and lifetime can be configured by administrators. These security parameters are used to reduce the likelihood of a successful brute force attack to gain unauthorized access to the system</span><span style=\"font-family: Calibri, sans-serif; color: black;\">.</span></span></p>\r\n<h3 style=\"margin: 10pt 0in 6pt 0.5in; text-indent: -0.5in; line-height: 115%; break-after: avoid; border: none; padding: 0in; font-size: 12pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">Security Management</span></h3>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; font-family: Calibri, sans-serif; color: black;\">The TOE is managed by authorized administrators using a web GUI. All administrative actions are performed via the web GUI. The TOE uses capabilities to control user access to functionality within the product. Users or a group of users can be assigned to one or more of the 46 out-of-the-box capabilities. The TOE also allows administrators to create or modify capabilities and assign them to users or groups of users.</span></p>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\">&nbsp;</p>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt;\"><strong><span style=\"font-family: Calibri, sans-serif; color: black;\">Protection of the TSF</span></strong></span></p>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; font-family: Calibri, sans-serif; color: black;\">In the evaluated configuration, the TOE requests the JRE to encrypt administrator credentials before being sent to the Operational Environment&rsquo;s Oracle database. The TOE does not store any cleartext password data in memory and there are no credentials stored locally on the TOE. Similarly, the answers to user security questions (used if the user has forgotten their password) are stored in an encrypted format in the Oracle database. In the evaluated configuration, the TOE does not store any secret or private keys and thus, there is no mechanism to disclose this information.</span></p>\r\n<h3 style=\"margin: 10pt 0in 6pt 0.5in; text-indent: -0.5in; line-height: 115%; break-after: avoid; border: none; padding: 0in; font-size: 12pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">TOE Access</span></h3>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; font-family: Calibri, sans-serif; color: black;\">The TOE can display a warning banner prior to allowing any administrative actions to be performed. In the event that the maximum timeout value for inactivity has been reached, the TOE will terminate the remote session. A user can also terminate their own session by selecting the logout button.</span></p>\r\n<h3 style=\"margin: 10pt 0in 6pt 0.5in; text-indent: -0.5in; line-height: 115%; break-after: avoid; border: none; padding: 0in; font-size: 12pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 12pt; line-height: 115%; font-family: Calibri, sans-serif; color: black;\">Trusted Path/Channels</span></h3>\r\n<p style=\"margin: 0in; font-size: 12pt; font-family: 'Book Antiqua', serif;\"><span style=\"font-size: 12pt; font-family: Calibri, sans-serif; color: black;\">The TOE&rsquo;s evaluated configuration enforces secure communication between the TOE and IT entities in the operational environment by using the Operational Environment&rsquo;s JNDI, ADSI, and JDBC installed on the local system. These trusted channels transfer TOE data, enterprise user data, and IdentityIQ administrator data to and from IT entities within the Operational Environment. When users log on to the TOE via a web GUI, a trusted path is established, and it is secured using HTTPS that is provided by Apache Tomcat using its OpenSSL module.</span></p>","features":[{"id":803,"feature_name":"Auditing"},{"id":802,"feature_name":"Enterprise Security Management"}]}