Skip to content

Commit 75bb91c

Browse files
committed
add distributed TOE clarification statement to MDM agent description
1 parent 10144ef commit 75bb91c

1 file changed

Lines changed: 22 additions & 31 deletions

File tree

input/mdm.xml

Lines changed: 22 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -305,38 +305,29 @@ DONE:
305305
consist of a separate Mobile Application Store (MAS) server or a subordinate MDM server.
306306

307307
<!-- 1.3.1 TOE Boundary -->
308-
<section id="tb" title="TOE Boundary"> The MDM system operational environment consists of the MD on which the MDM agent resides,
309-
the platform on which the MDM server runs, and an untrusted wireless network over which they communicate, as pictured below.
310-
<h:br/><h:br/>
308+
<section id="tb" title="TOE Boundary">
309+
<h:p>
310+
The MDM system operational environment consists of the MD on which the MDM agent resides, the platform on which the MDM server runs, and an untrusted wireless network over which they communicate, as pictured below.
311+
</h:p>
312+
<h:p>
311313
<figure entity="images/MDMSystem.png" title="MDM System Operating Environment" id="agentoperatingenvironment"/>
312-
<h:br/><h:br/>
313-
The <h:b>MDM server</h:b> is software (an application, service, etc.) on a general-purpose platform, a network device, or cloud architecture executing
314-
in a trusted network environment. The MDM server provides administration of MD policies and reporting on the device behavior.
315-
The MDM server is responsible for managing device enrollment, configuring and sending policies to the MDM agents, collecting reports on device
316-
status, and sending commands to the agents. The MDM server may be standalone or distributed, where a distributed TOE is one that requires
317-
multiple distinct components to operate as a logical whole in order to fulfill the requirements of this PP (a more extensive description of
318-
distributed MDMs is given in section 3).
319-
<h:br/><h:br/>
320-
The <h:b>MDM agent</h:b> establishes a secure connection back to the
321-
MDM server controlled by an enterprise administrator and configures the
322-
MD per the administrator's policies. The MDM agent is addressed in the <xref to="mod-mdmagent"/>. If the MDM agent is installed on a MD as an application
323-
developed by the MDM developer, the PP-Module extends this PP and is included in the TOE. In this case, the TOE security
324-
functionality specified in this PP must be
325-
addressed by the MDM agent in addition to the MDM
326-
Server. Otherwise, the MDM agent is provided by the MD vendor
327-
and is out of scope of this PP; however, MDMs are
328-
required to indicate the device platforms supported by the MDM server and
329-
must be tested against the native MDM agent of those platforms.
330-
<h:br/><h:br/>
331-
The <h:b>Mobile Application Store (MAS)</h:b> hosts applications for the enterprise, authenticates agents, and securely transmits
332-
applications to enrolled MDs. The MAS functionality can be included as part of the MDM server Software or can be logically
333-
distinct. If the MAS functionality is on a physically separate server, then the TOE is
334-
distributed with the MDM server and MAS server being
335-
separate components.<h:br/><h:br/>
336-
The <h:b>Subordinate MDM Server</h:b> is an optional, physically separate, server that sits between a primary MDM server and an MDM agent on a managed device. The purpose of the subordinate MDM server is to forward signed policies from a primary MDM server to an MDM agent on a managed device for which the subordinate MDM is responsible. The subordinate MDM server can either directly pass these signed policies to the managed device, or can interpret the policy into a different format if necessary. This interpretation process will follow well defined rules to ensure that the resulting interpreted policy matches the actions defined in the original policy. This interpreted policy is signed by the subordinate MDM server for delivery to the MDM agent. Any alerts or notifications generated by an MDM agent will be passed by the subordinate MDM server back to the primary MDM server to alert the enterprise administrators.
337-
<h:br/><h:br/>
314+
</h:p>
315+
<h:p>
316+
The <h:b>MDM server</h:b> is software (an application, service, etc.) on a general-purpose platform, a network device, or cloud architecture executing in a trusted network environment. The MDM server provides administration of MD policies and reporting on the device behavior. The MDM server is responsible for managing device enrollment, configuring and sending policies to the MDM agents, collecting reports on device status, and sending commands to the agents. The MDM server may be standalone or distributed, where a distributed TOE is one that requires multiple distinct components to operate as a logical whole in order to fulfill the requirements of this PP (a more extensive description of distributed MDMs is given in section 3).
317+
</h:p>
318+
<h:p>
319+
The <h:b>MDM agent</h:b> establishes a secure connection back to the MDM server controlled by an enterprise administrator and configures the MD per the administrator's policies. The MDM agent is addressed in the <xref to="mod-mdmagent"/>. If the MDM agent is installed on a MD as an application developed by the MDM developer, the PP-Module extends this PP and is included in the TOE. In this case the TOE security functionality specified in this PP must be addressed by the MDM agent in addition to the MDM Server, additionally the TOE can be considered distributed. Otherwise, the MDM agent is provided by the MD vendor and is out of scope of this PP; however, MDMs are required to indicate the device platforms supported by the MDM server and must be tested against the native MDM agent of those platforms.
320+
</h:p>
321+
<h:p>
322+
The <h:b>Mobile Application Store (MAS)</h:b> hosts applications for the enterprise, authenticates agents, and securely transmits applications to enrolled MDs. The MAS functionality can be included as part of the MDM server Software or can be logically
323+
distinct. If the MAS functionality is on a physically separate server, then the TOE is distributed with the MDM server and MAS server being separate components.
324+
</h:p>
325+
<h:p>
326+
The <h:b>Subordinate MDM Server</h:b> is an optional, physically separate, server that sits between a primary MDM server and an MDM agent on a managed device. The purpose of the subordinate MDM server is to forward signed policies from a primary MDM server to an MDM agent on a managed device for which the subordinate MDM is responsible. The subordinate MDM server can either directly pass these signed policies to the managed device, or can interpret the policy into a different format if necessary. This interpretation process will follow well defined rules to ensure that the resulting interpreted policy matches the actions defined in the original policy. This interpreted policy is signed by the subordinate MDM server for delivery to the MDM agent. Any alerts or notifications generated by an MDM agent will be passed by the subordinate MDM server back to the primary MDM server to alert the enterprise administrators. The subordinate MDM server and primary MDM servers are two separate TOE's and would be evaluated independently of each-other, they do not form a distributed TOE.
327+
</h:p>
328+
<h:p>
338329
<figure entity="images/SubordinateMDMSystem.png" title="MDM System with Subordinate MDM" id="subordinateMDMDiagram"/>
339-
<h:br/><h:br/>
330+
</h:p>
340331
</section>
341332
</section>
342333

@@ -1114,7 +1105,7 @@ DONE:
11141105
Only those SFRs included in the ST are required to be audited. The ST for a distributed TOE must include a mapping of SFRs to each of the components
11151106
of the TOE. (Note that this deliverable is examined as part of the ASE_TSS.1 and AVA_VAN.1 Evaluation Activities.) The ST for a distributed TOE
11161107
may also introduce a "minimum configuration" and identify components that may have instances added to an operational configuration without affecting
1117-
the validity of the CC certification. Appendix E describes Evaluation Activities relating to these equivalency aspects of a distributed TOE (and
1108+
the validity of the CC certification. <xref to="EACDT"/> describes Evaluation Activities relating to these equivalency aspects of a distributed TOE (and
11181109
hence what is expected in the ST).
11191110
</section>
11201111

0 commit comments

Comments
 (0)