Compatibility Questionnaire: Secure Elements, Inc. (C5 EVM Version 3.0) — Archive

Important: The OVAL Compatibility Program was moved to "archive" status in December 2009, and replaced with the "OVAL Adoption Program." Under the OVAL Adoption Program product validation is performed by an external organization, allowing the OVAL Team to focus on educating vendors on best practices regarding the use and implementation OVAL and on how OVAL can continue to evolve as needed by the community.

Refer to the OVAL Adoption Program section for addition information and to review all products and services listed.

Organizational Information

Name of Your Organization:

Secure Elements, Inc.

Web Site:

Product Information

Product/Service Name:

C5 EVM Version 3.0

Compatible Categories:

OVAL Results Consumer

Product/Service Home Page:

General Capability Questions

Product Accessibility

Provide a short description of how and where your capability is made available to your customers and the public:
C5 EVM imports OVAL results from external sources and matches them to remediations to create actionable alerts that allow C5 EVM users to deploy a remediation to correct a vulernable system with through a patch based or configuration based remediation.
Accuracy Questions

Language Version Indication

Describe how and where the capability indicates the version of the OVAL Language used to validate, create, or update its content:
C5 EVM standardizes on OVAL version 5.0 as stated in the C5 EVM Administratior's manual.

Approach for Correction of Errors

Indicate how a user who discovers an error in the capability's use of OVAL can report the error:
Any error in C5 EVM's use of OVAL can be reported by email to support@secure-elements.com
Describe the approach to responding to the above error reports and how applicable fixes will be applied:
OVAL content issues will be automatically deployed to all customer sites. All code changes to the appiance will be delivered via the stanard Secure Elements patch/update process.
Documentation Questions

Compatibility Documentation

Provide a copy, or directions to the location, of where the documentation describes OVAL and OVAL Compatibility for any customers:
C5 EVM User's Guide - Chapter 3 working with Vulnerabilities

Language Support

Indicate the component schemas and/or individual OVAL Tests that the capability does not support for each category of OVAL Compatibility being applied for:
C5 EVM supports all component schemas and OVAL tests
Capability Specific Questions

Finding Elements Using OVAL

Provide details regarding how users can identify and find individual OVAL content (through OVAL-IDs) that is being consumed by the capability. For example, how can a user determine which definitions have been consumed and what the result of each definition is:
Individual OVAL content can be searched for within C5 EVM using the built in Search Feature that allows the user to search by OVAL ID.
Statements

Statement of Compatibility

Have an authorized individual sign and date the following Compatibility Statement (required):

"As an authorized representative of my organization I agree that we will abide by all of the mandatory Compatibility Requirements as well as all of the additional mandatory Compatibility Requirements that are appropriate for our specific type of capability."

Name:   Scott Carpenter
Title:   Director, Secure Elements Security Labs

Statement of Accuracy

Have an authorized individual sign and date the following accuracy Statement (recommended):

"As an authorized representative of my organization and to the best of my knowledge, there are no errors in the correctness of our capability's use of OVAL schema and logic."

Name:   Scott Carpenter
Title:   Director, Secure Elements Security Labs

Statement on Follow-on Correctness Testing Support

Have an authorized individual sign and date the following statement about your organizations willingness to support correctness testing of other capabilities, which will be managed by the Reviewing Authority and kept to reasonable levels of effort for all involved. (required):

"As an authorized representative of my organization, we agree to support the Review Authority in follow-on correctness testing activities, where appropriate types of OVAL documents might need to be exchanged with other organizations attempting to prove the correctness of their capabilities."

Name:   Scott Carpenter
Title:   Director, Secure Elements Security Labs

Page Last Updated: December 17, 2009