{"product_id":4002,"v_id":4002,"product_name":"Microsoft Windows 2000 Professional, Server, and Advanced Server with SP3 and Q326886 Hotfix","certification_status":"Not Certified","certification_date":"2002-10-25T00:10:00Z","tech_type":"Network Management, Operating System, Sensitive Data Protection, Virtual Private Network","vendor_id":{"name":"Microsoft Corporation","website":"https://www.microsoft.com"},"vendor_poc":"Tim Myers","vendor_phone":"+1 425-882-8080","vendor_email":"wincc@microsoft.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>The Windows 2000 Target of Evaluation (TOE) is a general-purpose, distributed, network operating system that provides controlled access between subjects and user data objects. Windows 2000 has a broad set of security capabilities including single network logon; access control and data encryption; extensive security audit collection; and Light-weight Directory Access Protocol (LDAP) Directory-based resource management. The Windows 2000 TOE provides the following security services: user data protection, audit, identification and authentication, security management, protection of the TOE Security Functions (TSF), resource quotas and TOE access banners. The Windows 2000 security policies provide network-wide controlled access protection (access control), encrypted data/key protection, and encrypted file protection. These policies enforce access limitations between individual users and data objects. The TOE is capable of auditing security relevant events that occur within a Windows 2000 network. All these security controls require users to identify themselves and be authenticated prior to using any node on the network.</p>\r\n<p>The Windows 2000 ST contains the following additional sections:</p>\r\n<ul>\r\n<li>TOE Description (Section 2) &ndash; Provides an overview of the TOE security functions and boundary. </li>\r\n<li>Security Environment (Section 3) &ndash; Describes the threats, organizational security policies and assumptions that pertain to the TOE. </li>\r\n<li>Security Objectives (Section 4) &ndash; Identifies the security objectives that are satisfied by the TOE and the TOE environment. </li>\r\n<li>IT Security Requirements (Section 5) &ndash; Presents the security functional and assurance requirements met by the TOE. </li>\r\n<li>TOE Summary Specification (Section 6) &ndash; Describes the security functions provided by the TOE to satisfy the security requirements and objectives. </li>\r\n<li>Protection Profile Claims (Section 7) &ndash; Presents the rationale concerning compliance of the ST with the CAPP. </li>\r\n<li>Rationale (Section 8) &ndash; Presents the rationale for the security objectives, requirements, and TOE summary specifications as to their consistency, completeness and suitability. </li>\r\n</ul>","evaluation_configuration":null,"security_evaluation_summary":"<p>None.</p>","environmental_strengths":"<p>The evaluation of Windows 2000 provides a moderate level of independently assured security in a conventional TOE and is suitable for the environment specification in this ST. The assurance requirements and the minimum strength of function were chosen to be consistent with this goal and to be compliant with the Controlled Access Protection Profile (CAPP). The TOE assurance level is Evaluation Assurance Level (EAL) 4 augmented with ALC_FLR.3 and the TOE minimum strength of function is SOF-medium.</p>\r\n<!-- InstanceEndEditable -->","features":[]}