Common Criteria EAL+ certification for SDoT Security Gateway Cross Domain Solution

INFODAS GmbH

PR93097

 

COLOGNE, Germany, Nov. 18, 2021 /PRNewswire=KYODO JBN/ --

 

The SDoT Security Gateway [

https://www.infodas.de/en/products/sdot_cross_domain_solutions/security-gateway-ieg-guard/

] received an ISO/IEC 15408 Common Criteria (CC) certification evaluation

assurance level (EAL) 4+ [

https://www.commoncriteriaportal.org/files/epfiles/1129c_pdf.pdf ]from the

German Federal Office of Information Security (BSI). INFODAS and its product

met one of the most demanding evaluation in the global Cybersecurity industry.

Once again SDoT cross domain solutions and their development excel in quality,

reliability, integrity and security. The bi-directional High Assurance Guard

allows to filter structured and unstructured data and already holds general

German, NATO and EU SECRET approvals.

 

In the past, sensitive systems and data in the military, government agencies or

critical infrastructure were isolated. Even today many classified information

protection regulations do not reflect the technological advances in cross

domain solutions. These practices and regulations prevent end-to-end

digitization of mission critical IT environments, dealing with the IT expert

shortage and requirements for rapid decision making among government agencies,

military units or multi-national partners. Today, only trusted solutions with

an CC EAL4+ certification or national security agency approvals can change this

reality. They combine a protocol break with in-depth inspection, transformation

and monitoring of data transfers, ensuring only correct and authorized

information crosses systems at different security levels.

 

The German BSI ISO/IEC 15408 common criteria standard schema [

https://www.commoncriteriaportal.org/ccra/index.cfm ] is the global benchmark

in Cybersecurity. A growing number of domestic and international end-users

expect IT vendors to produce trusted and reliable evidence for the

Cybersecurity capabilities of their products. The CC evaluation process applies

objective and verifiable criteria on specified evidence. The depth of

evaluation is marked by the evaluation assurance level (EAL) from 1-7. Contrary

to the popular collaborative protection profiles [

https://www.commoncriteriaportal.org/pps/collaborativePP.cfm?cpp=1&CFID=60120751&CFTOKEN=ba5f3aa13a5a2905-DA99A521-155D-974A-5E73520CAE4EF222

] (cPPs) which are mostly based on CC EAL 1/2, the SDoT Security Gateway had

to meet CC EAL4+ [ https://www.commoncriteriaportal.org/products/#BP ]. This

included extensive penetration tests, vulnerability analysis and source code

analysis by independent CC auditors.

 

The certification process started in 2019 and was conducted by atsec

information security GmbH, a German based BSI certified CC auditor, under

supervision of the BSI [

https://www.bsi.bund.de/SharedDocs/Zertifikate_CC/CC/Netzwerk_und_Kommunikationsprodukte/1129.html;jsessionid=0E3ED2933CF4C0AF9C0E1A821D4CDD50.internet472?nn=513260

]. Beyond the product, INFODAS GmbH had to provide evidence about its research

& development practices, product documentation, product support or relevant

company processes. The audit benefited from activities related to the German,

NATO and EU SECRET approvals. Unlike a common criteria certification that can

be initiated by any IT vendor [

https://www.bsi.bund.de/EN/Topics/Certification/certified_products/certified_products_node.html;jsessionid=F115E0C494B45C0D15B17E3050AE19D9.internet472

], national security authority approvals require a public sector sponsor.

"The SDoT Security Gateway's CC EAL4+ certification meets customer demands in

various sectors and underlines our leading position in the global cross domain

solution market. This shows the strength of our team and that true "zero trust

security" products can come from Germany", said Dr. Alexander Konen, Director

Solutions. According to Hanns Benigno Groeschke, INFODAS' CC expert: "BSI

accredited CC auditors are highly regarded around the world: They

independently, diligently, relentlessly and systematically apply CC standards.

In parallel, the Federal Office of Information Security continuously reviews

audit results to ensure the highest quality of their CC certifications".

 

All elements of the Secure Domain Transition (SDoT) Product Family [

https://www.infodas.de/en/products/sdot_cross_domain_solutions/security-gateway-ieg-guard/

] meet the highest requirements for hardware and software security at the

SECRET and below interoperability level (SABI). They are developed and

manufactured in Germany with full supply chain transparency. They are available

as 19", 1U appliances or smaller deployable sizes for vehicles. Other products

include the SDoT Security Gateway Express [

https://www.infodas.de/en/products/sdot_cross_domain_solutions/security-gateway-ieg-guard/

] optimized for near real-time, low latency filtering of structured data such

as XML or JSON. Just like the SDoT Diode [

https://www.infodas.de/en/products/sdot_cross_domain_solutions/data_diode/ ]

for unidirectional data transfer up to 9.1 Gbit/s, both products hold a general

NATO, EU and German SECRET approvals [

https://www.bsi.bund.de/DE/Themen/Oeffentliche-Verwaltung/Zulassung/Liste-zugelassener-Produkte/liste-zugelassener-produkte_node.html

]. They are complemented by the SDoT Labelling Service [

https://www.infodas.de/en/products/sdot_cross_domain_solutions/labelling-service-data-classification/

] for NATO STANAG 4774/8 compliant data classification with XML security labels

that are cryptographically bound to any data object such as MS Office documents.

 

About INFODAS – connect more.be secure

INFODAS is an independent, family owned business founded in 1974 in Germany.

The company develops innovative cross domain solutions based on

security-by-design principles and provides Cybersecurity, IT and AI consulting

to government, defense and commercial clients. INFODAS SDoT product family

cross domain solutions (SDoT Security Gateway, SDoT Diode, SDoT Labelling

Service, PATCH.works) are approved up to German, EU, NATO SECRET and are listed

in the NATO information assurance catalogue. Combined with OPSWAT Metadefender,

Kiosk and Vault, SDoT products protect ensure malware free data entry, storage

and retrieval. For the past 15 years SDoT products have been used in the

toughest and mission critical environments around the world. They are designed

and manufactured in Germany following the security-by-design principle and

supply chain transparency.

- Website - https://www.infodas.de/en

- LinkedIn - https://www.linkedin.com/company/infodas/

- Twitter - https://twitter.com/infodas

 

Contact

Dr. Alexander Schellong

VP Global Business

Tel. +49 (0)221 70912234

marketing@infodas.de

 

Photo - https://mma.prnewswire.com/media/1690047/INFODAS_1.jpg

Photo - https://mma.prnewswire.com/media/1690048/INFODAS_2.jpg

Photo - https://mma.prnewswire.com/media/1690049/INFODAS_3.jpg

Logo - https://mma.prnewswire.com/media/1690050/INFODAS_Logo.jpg

    

Source: INFODAS GmbH

本プレスリリースは発表元が入力した原稿をそのまま掲載しております。また、プレスリリースへのお問い合わせは発表元に直接お願いいたします。

このプレスリリースには、報道機関向けの情報があります。

プレス会員登録を行うと、広報担当者の連絡先や、イベント・記者会見の情報など、報道機関だけに公開する情報が閲覧できるようになります。

プレスリリース受信に関するご案内

SNSでも最新のプレスリリース情報をいち早く配信中