Clearswift announced today that its DeepSecure 2.1 message security software has passed common criteria Evaluation Assurance Level 4 (EAL4), making it the worlds only EAL4 certified ACP 145 compliant security solution.
DeepSecure is specifically designed to meet the needs of organisations where security is paramount, such as in the military, government and defence industries.
DeepSecure is a messaging security solution that enables organisations to safely transmit highly sensitive information via electronic communications whilst maintaining network integrity. As well as providing virus scanning, DeepSecure also enables file type fingerprinting and word search on messages that may be signed or encrypted.
DeepSecure provides assured network separation: messages are stored, and then forwarded through an intermediary rather than through a data stream. This prevents messaging protocols being subverted and being used for external network attacks or unauthorised transfer of confidential data. DeepSecure maintains separate channels for message flow between networks, thus allowing different security policies to be applied in each direction.
ACP 145 (Allied Communications Protocol 145) is a messaging interoperability standard designed to support communication between military messaging systems. Currently, most systems operate under their own standards, making interoperability between organisations difficult. ACP145 has been designed as an Esperanto standard that will allow nations to interoperate both syntactically and semantically.
Clearswifts DeepSecure, which counts NATO among its customers, is the only boundary security solution for military messaging on the planet that has been evaluated to EAL4. It is vital that military organisations are able to communicate securely with each other and we are delighted that DeepSecure 2.1 has been certified to fulfil such a critical role in enabling that communication, VP Sales EMEA, Michael Paterson, said.
The EAL4 Certificate was formally presented to Clearswift on Wednesday 20th of Sep at the 7th International Common Criteria Conference in Lanzarote, Spain. Achieving the common criteria EAL4 certification demonstrates that DeepSecure has complied to a stringent set of quality assurance requirements, which customers working with sensitive information demand, Mr Paterson said.
The previous version of DeepSecure provided exceptional standards of security and was also compliant with ACP 145. However, with DeepSecure 2.1 there is no longer a requirement for messages to be converted from the X.400 messaging standard into a MIME (Multi-Purpose Internet Mail Extensions) format before the content can be examined and policies applied.
When selecting security products, it is critical that the security product not become an avenue for exploitation itself, said Charles Kolodgy, Research Director, Security Products at IDC. To validate that level of trust, many more companies are turning to the international Common Criteria evaluation program. By gaining Common Criteria certification, especially at EAL 4, Clearswift is demonstrating a commitment to building secure products.
We are also pleased to announce other improvements to DeepSecure including simplified policy capabilities which can be easily enforced and altered by e-mail administrators through the highly intuitive GUI, Mr Paterson said.
DeepSecure 2.1 continues to deliver an enhanced security solution that enables secure and encrypted messages, as well as standard e-mails, to be audited at the gateway, whilst preventing eaves-dropping attacks.
Key feature updates include Security Label support with X.841 SPIFs, making DeepSecure 2.1 the only EAL4 evaluated ACP 145 compliant product, and providing the only EAL4 evaluated X.841 SPIF Editor. Inclusion of both SMTP/MIME and X.400 message protocol conformance validation within the EAL4 evaluation - again making DeepSecure the only mail guard product to include this protocol conformance validation within EAL4 evaluation.
Inclusion of the intuitive ClearPoint Management Interface within the scope of EAL4 evaluation provides easily understood yet EAL4 assured visual representation of complex policies, and monitoring and control of gateway operation. Conditional policies allow any policy option to be made dependent on the outcome of any other policy check, nested to any depth, to allow creation of policies to meet any requirement, however complex.
Finally, EAL4 evaluated plug-in APIs provide clear separation between evaluated and other functions, allowing the functions beyond evaluation (such as virus scanners) to be updated without affecting the evaluated state of the core product.
[
Best Security Software Pricing UK]
[
Best Security Software Pricing US]
BIOS, Oct 10, 06 | Print | Send |
Comments (0) | Posted In
Networking