{"product_id":4036,"v_id":4036,"product_name":"IBM DB2 Content Manager for Multiplatforms V8.2","certification_status":"Not Certified","certification_date":"2004-12-22T00:12:00Z","tech_type":"DBMS","vendor_id":{"name":"IBM Corporation","website":"https://www.ibm.com"},"vendor_poc":"Landes Wong","vendor_phone":"408.463.4547","vendor_email":"landesw@us.ibm.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>The TOE, IBM DB2 Content Manager for Multiplatforms V8.2 is a database and data management system (content management system) that provides a foundation for managing, accessing, and integrating critical business information on demand. </p>\r\n<p>The main components of the TOE include a Library Server, one or more Resource Managers, System Administration Client, and Client for Windows. </p>\r\n<p>The Library Server is the key component of the Content Manager system. The Library Server performs the functions that a library catalog file in a real library performs. The Library Server manages the content metadata (resources) and is responsible for identification and authentication for users requesting services from Content Manager and access control to the resources residing on Resource Managers. </p>\r\n<p>The Resource Manager stores resources for Content Manager. The Resource Manager can be installed on the same workstation as the Library Server, or it can be installed on its own workstation. Users store and retrieve metadata (resources) on the Resource Manager. A single Library Server can support multiple Resource Managers. Access decisions to grant access to metadata (resources) are made by the Library Server. The Resource Manager enforces access decisions. </p>\r\n<p>The System Administration Client oversees the entire Content Manager system. From the system administration client, an administrator performs various administrative functions, such as define the data model, creating users and defining their access to the system and specific objects, and managing storage and storage objects in the system. The System Administration Client can be installed on any workstation with the other components or on its own workstation. </p>\r\n<p>The Client for Windows provides a user interface that enables users to import documents into Content Manager, view them, work with them, store them, and retrieve them. </p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the IBM DB2 Content Manager for Multiplatforms V8.2 TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.1 and International Interpretations effective on 14 November 2003. The evaluation methodology used by the Evaluation Team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 1.0. Science Applications International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the product is EAL3 augmented with ALC_FLR.1 family of assurance requirements. The product, when configured as specified in the IBM DB2 Content Manager for Multiplatforms Version 8 Release 2 Planning and Installing Your Content Management System, dated September 2004 satisfies all of the security functional requirements stated in the IBM DB2 Content Manager Security Target, Version 1.0, 22 November 2004. The supported platforms are; z/OS v1.3, Linux RedHat 3.0, Linux SUSE 8, Sun Solaris 2.8, AIX 5.1, Windows 2000, (this includes all combinations of Advanced Server, Server, Professional, Service Packs and hotfixes), and Microsoft Windows XP (this includes all combinations of Standard, Enterprise, Service Packs and hotfixes). One validator on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC. </p>\r\n<p>The evaluation was completed in November 2004. Results of the evaluation can be found in the Validation Report prepared by the National Information Assurance Partnership (NIAP) CCEVS-VR-04-0081. </p>","environmental_strengths":"<p>IBM DB2 Content Manager for Multiplatforms V8.2 is a database and data management system (content management system) that provides a foundation for managing, accessing, and integrating critical business information on demand. Content Manager is able to integrate all forms of data - document, Web, image, rich media - across diverse business processes and applications, including Siebel, PeopleSoft, and SAP, presenting the data in a integrated context for later use. IBM DB2 Content Manager for Multiplatforms V8.2 supports the following five security functions: </p>\r\n<ul><strong>Audit Function:</strong> All security-related events within Content Manager are logged. The audited events are tied to the user/administrator that performed the action, as well as the action performed, and the time it was performed. These audit records are stored in a central location where an authorized administrator can review them. Authorized non-administrative users can review the audit records generated for resources that they have been granted access. The IT environment provides tools that are utilized by the TOE Administrators to review the audit records. </ul>\r\n    <ul><strong>Identification and Authentication:</strong> Content Manager requires users to be identified and authenticated before any other actions can be performed. The user is required to provide a user name and password, which will be verified by the Library Server database table. If the verification is successful, access into the TOE is granted. </ul>\r\n        <ul><strong>User Data Protection:</strong> Access to the resources and its information is governed by the object's ACL that identifies the user and the privileges allowed. The Library Server verifies that the user has the required privilege and the ACL associated to the requested object grants access. </ul>\r\n            <ul><strong>Security Management:</strong> System Administration Clients provide the authorized administrator the capability to manage the security-related functions and attributes, such as the audit function, management of users, and their associated data. </ul>\r\n                <ul><strong>Protection of the TSF:</strong> Content Manager provides various mechanisms to protect the TSF data in transmit and to enforce the access control policy ensuring that only authorized users with the appropriate privilege(s) are given access to the resources. </ul>","features":[]}