{"product_id":4010,"v_id":4010,"product_name":"Pointsec PC Version 4.3","certification_status":"Not Certified","certification_date":"2004-01-28T00:01:00Z","tech_type":"Sensitive Data Protection","vendor_id":{"name":"Pointsec Mobile Technologies, Inc.","website":"http://www.pointsec.com"},"vendor_poc":"Jerrod Chong","vendor_phone":"1.925.788.8644","vendor_email":"jerrod.chong@pointsec.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>The TOE, Pointsec PC 4.3, is a centrally administered, whole disk encryption and mandatory access control product for use on computers (laptops, desktops, or workstations) running Microsoft Windows operating systems. Mandatory access control is provided at the startup of the computer, prior to the loading of the operating system, requiring a successful authentication before the operating system is allowed to boot. Multiple user authentication mechanisms are supported, including fixed passwords, dynamic/challenge-response authentication, smart cards, and remote help.</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Pointsec PC 4.3 TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.1 and National and International Interpretations effective on 18 June 2002. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 1.0. Science Applications International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the product is EAL 4 family of assurance requirements. The product, when configured as specified in the Pointsec PC 4.3 Administrator's Guide PA5, January 2004 and Pointsec PC 4.3 Installation Guide, PA2, January 2004, satisfies all of the security functional requirements stated in the Pointsec PC 4.3 Security Target (Version 1.08). One validator on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC. The evaluation was completed in January 2004. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, (report number CCEVS-VR-04-0057, dated 28 January 2004) prepared by CCEVS.<br />\r\n<br />\r\n</p>","environmental_strengths":"<p>Pointsec PC 4.3 has been developed for an operating environment with a moderate level of risk to identified assets. Pointsec PC 4.3 supports the following eight security functions:</p>\r\n<p><strong>Access Control:</strong> Secures desktops, workstations, and laptop from unauthorized access, using the combination of boot protection and full hard disk encryption. The TOE enforces access control for each disk partition by employing hard disk encryption, ensuring that unauthorized users are unable to access information on an encrypted device, either from available files, erased files, or temporary files.<br />\r\n<br />\r\n<strong>Auditing: </strong>The TOE collects audit data and provides an interface for authorized administrators to review audit logs. Audit information generated by the system includes date and time of the event, user ID that caused the event to be generated, computer where the event occurred, and other event specific data. The TOE also restricts log access to authorized users. <br />\r\nCryptographic Support: The TOE's cryptographic functionality is based upon code that has been certified as meeting the requirements of FIPS 140-1 Level 1. Cryptographic keys are generated, accessed, protected, and destroyed in accordance with requirements defined by FIPS 140-1 Level 1. Additionally, the TOE supports important cryptographic operations such as data and key encryption/decryption.<br />\r\n<br />\r\n<strong>Fault Tolerance: </strong>When a PC with Pointsec installed loses contact with the Pointsec Distribution Server, the TOE provides the administrator with the capability to identify an additional three Pointsec Distribution Servers for redundancy.<br />\r\n<br />\r\n<strong>Identification and Authentication: </strong>The TOE provides a flexible suite of five authentication mechanisms, enabling the administrator to assign appropriate authentication requirements for the intended environment.<br />\r\n<br />\r\n<strong>Security Management: </strong>The TOE provides a number of interfaces to manage the configuration and implementation of the various policies enforced by the TOE.<br />\r\n<br />\r\n<strong>Self-Protection:</strong> Pointsec PC implements a set of security mechanisms to ensure that other security functions such as access control cannot be bypassed and that the security functions themselves cannot be tampered with. Additionally, mechanisms such as cryptographic self-tests have been implemented to ensure that important cryptographic functions are always operating correctly.<br />\r\n<br />\r\n<strong>Trusted Path: </strong>The TOE provides a mechanism to ensure that users are communicating directly with the TOE during initial authentication.</p>\r\n<!-- InstanceEndEditable -->","features":[]}