Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

Thursday, December 19, 2019

Red Hat JBoss EAP 7.2 secures Common Criteria Certification to deliver solutions for regulated industries

Red Hat, provider of open source solutions, announced Red Hat JBoss Enterprise Application Platform (JBoss EAP) 7.2 has been awarded Common Criteria Certification at Evaluation Assurance Level (EAL) 4+ by the Italian Common Criteria scheme Organismo di Certificazione della Sicurezza Informatica (OCSI). 

The certification provides government agencies, financial institutions, and customers in other security-sensitive and regulated environments the assurance and confidence that JBoss EAP 7.2 meets government security standards.


This achievement demonstrates Red Hat’s position in technology and security. This is the third time JBoss EAP has achieved Common Criteria certification. 

JBoss EAP 7 is built to provide simplified deployment and full Java EE performance for applications in any environment. Whether on-premise or in virtual, private, public and hybrid clouds, JBoss EAP features a modular architecture that starts services only as they are required. JBoss EAP 7 is built for performance and flexibility in modern application environments. Its modular architecture and services-driven set of components reduces scale-out times and provides flexibility for applications deployed in different environments.

In 2015, JBoss EAP 6.2 also achieved recognition at the EAL4+ assurance level. Red Hat’s latest certification will be recognized by all countries under the Common Criteria Recognition Arrangement (CCRA) at Evaluation Assurance Level 2 since there is no generally agreed criteria for higher assurance levels.


The Common Criteria is an internationally recognized set of standards used by the federal government and organizations to assess the security and assurance of technology offerings. EAL categorizes the depth and rigor of the evaluation, and EAL4+ assures consumers that the software has been methodically designed, tested, and reviewed to meet the evaluation criteria.

Red Hat worked with atsec information security, a government accredited laboratory in the United States, Germany, Sweden, Singapore and Italy to complete the certification. atsec tested and validated the security, performance and reliability of the solution against the Common Criteria Standard for Information Security Evaluation (ISO/IEC 15408) at EAL4+.

"We're exceptionally proud that Red Hat JBoss Enterprise Application Platform again has achieved the Common Criteria Certification. It is important that our customers know they are getting the highest standard of security when they use JBoss EAP,  especially those in highly regulated industries,” said Paul Smith, senior vice president and general manager, Public Sector, Red Hat. “Common Criteria accreditation is a rigorous security standard and means customers can confidently trust Red Hat with sensitive applications, services and data. Repeatedly achieving this accreditation is a key value of the Red Hat subscription, and one that differentiates enterprise-class open source, and proves our on-going dedication to providing top solutions to security-conscious customers." 

Thursday, December 12, 2019

SolarWinds Orion Suite v4.0 experiences Common Criteria Evaluation that includes Server Configuration Monitor, Log Analyzer

SolarWinds announced that the SolarWinds Orion Suite for Federal Government v4.0 is undergoing evaluation for Common Criteria to Evaluation Assurance Level (EAL) 2+ under the Netherlands Scheme for Certification in the Area of IT Security (NSCIB). 


The Common Criteria is an international set of guidelines and specifications designed to ensure information security products meet agreed-upon security standards for government deployments in 30 nations. Conformance is verified through laboratory evaluation and scheme certification.


SolarWinds SCM is designed to detect, track, and compare system and application changes. SolarWinds Log Analyzer allows IT professionals to collect, consolidate and manage logs. Both products are built on the SolarWinds Orion Platform, which provides a unified view and full visibility into the performance and availability of an IT environment.


“SolarWinds continues to invest in both the security of its IT products and new product development to better meet the needs of IT professionals in the public sector,” said Sandy Orlando, senior vice president of product, SolarWinds. “This year, two new products that are part of the Orion Suite, Server Configuration Monitor (SCM) and Log Analyzer, are undergoing Common Criteria evaluation for the first time.”

Wednesday, December 11, 2019

Red Hat extends security profile of its Enterprise Linux platform, renews FIPS 140-2 validation for Red Hat Enterprise Linux 7.6

Red Hat announced Tuesday the renewal of the Federal Information Processing Standard 140-2 (FIPS 140-2) security validations for Red Hat Enterprise Linux 7.6. Driven by the National Institute of Standards and Technology (NIST), FIPS 140-2 is a computer security standard that specifies the requirements for cryptographic modules -- including both hardware and software components -- used within a security system to protect sensitive information.


This renewed validation maintains and extends Red Hat’s leadership in providing mission-critical-ready open source technologies to government agencies and regulated industries, such as healthcare and telecommunications. 

With Red Hat’s FIPS 140-2 validated solutions, these industries can better meet necessary information security guidelines without compromising on the need for flexible software solutions. Red Hat maintains a strong commitment to providing open, more secure IT innovation to the public sector, with the company’s technologies now holding more than 20 active FIPS validations that meet the criteria for use by U.S. government agencies.


FIPS 140-2 validation is needed when agencies determine that specific information systems should use cryptography to protect data; if cryptography is required, then it must be validated. In order to achieve FIPS 140-2 validation, cryptographic modules are subject to testing by NIST-accredited independent Cryptographic and Security Testing Laboratories. 

The validation for Red Hat Enterprise Linux 7.6 was performed by Atsec information security corporation’s Cryptographic and Security Testing Laboratory in Austin, Texas. Atsec is an independent organization with long-standing experience in IT security standards.


In addition to the renewed certification of Red Hat Enterprise Linux 7.6, Red Hat Enterprise Linux 7.7 and Red Hat Enterprise Linux 8.1 are currently on the NIST "Implementation Under Test" list with the intent to extend FIPS 140-2 validation to the latest releases of the Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8 platforms.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...