Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Red Hat Enterprise Linux 6, including the KVM hypervisor, has been awarded a major security certification used by IT in government, financial and other mission-critical verticals. By receiving the Common Criteria Certification at Evaluation Assurance Level (EAL) 4+, which is the highest level of assurance for an unmodified commercial operating system, Red Hat can assure public sector customers looking at cloud and virtualization will meet a range of important security assurance requirements.. Notably, Red Hat Enterprise Linux 6 features Security-Enhanced Linux (SELinux), a joint project developed with the National Security Agency (NSA). The certification provides assurance that using Red Hat Enterprise Linux 6 with the KVM hypervisor allows providers to host many tenants on the same machine while keeping their virtual guests separated from each other using Mandatory Access Control technology developed by the NSA, according to Paul Smith, Red Hat. Notably, Red Hat Enterprise Linux 6 features Security-Enhanced Linux (SELinux), a joint project deve. enterprise, linux, hypervisor, awarded, major, security, certific. . LinuxSecurity.com Team
Microsoft today continued its cat fight with Google, calling out the company for apparently misleading customers about the security of its applications. The software giant alleges that Google Apps for Government doesn't meet the level of security that Google claims. . In a blog post, Microsoft's corporate vice president and deputy general counsel, David Howard, said that Google's Web-based productivity suite for government clients is not certified under the Federal Information Security Management Act. The link for this article located at CNET is no longer available. . Apple challenges Samsung over deceptive assertions regarding privacy protections for user data.. Microsoft Applications, Google Security, Government Compliance. . LinuxSecurity.com Team
In the world of security certifications, the Common Criteria is one of the strongest ways that a company can look to gain business from Government agencies. It acts as a great way to gain international business as well. And as of Thursday, the Red Hat announced that they will be seeking the same certification (but different level) for their Java software, JBOSS. What are you thoughts on the effectiveness of Common Criteria certifications on actual security, versus as a business and marketing tool? . The link for this article located at CNET.com is no longer available. . The link for this article located at CNET.com is no longer available.. world, security, certifications, common, criteria, strongest. . LinuxSecurity.com Team
The Bush Administration is giving federal civilian agencies just 45 days to comply with new recommendations for laptop encryption and two-factor authentication. The memo follows a wave of high profile data thefts and major security breeches involving remote access or the theft of government laptop computers containing sensitive personal information. The official memo (PDF) from the executive office of the U.S. president stipulates that all mobile devices containing sensitive information must have their data encrypted. . The recommendations also say that two-factor authentication must be used for remote access, that remote access must time out after 30 minutes of inactivity, and that all data extracts must be logged. The memo does not detail any specific technology recommendations beyond this broad outline, presumably leaving agencies to decide on their own specific implementations. "Most departments and agencies have these measures already in place," wrote Clay Johnson III, the Deputy Director for Management who authored the memo. That's an assertion that is hard to believe in the wake of some high profile data thefts in the past year involving government systems that were not using any encryption or two-factor authentication. The link for this article located at is no longer available. . The recommendations also say that two-factor authentication must be used for remote access, that rem. administration, giving, federal, civilian, agencies, comply, recommen. . Brittany Day
IBM and Novell announced at LinuxWorld today that SuSE Linux Enterprise Server 9 has become the first distribution to complete Evaluation Assurance Level (EAL) 4+. The high security rating will enable the operating system to be adopted by governments and government agencies for mission-critical operations, according to the firms. . In addition, IBM and Novell co-operatively achieved US Department of Defense Common Operating Environment compliance, a Defense Information Systems Agency requirement for military computing products. SuSE Linux Enterprise Server 9 on IBM eServers has achieved Controlled Access Protection Profile under the Common Criteria for Information Security Evaluation, also referred to as CAPP/EAL4+. The link for this article located at VNUNet is no longer available. . In addition, IBM and Novell co-operatively achieved US Department of Defense Common Operating Enviro. novell, announced, linuxworld, today, linux, enterprise, server, become. . LinuxSecurity.com Team
Hewlett Packard Co has completed the certification of Linux on its servers and workstations with evaluation assurance level 3 of the Common Criteria security evaluation and is now looking to the next level. . . .. 11 Oct 2004, 09:35 GMT - The certification is an important security consideration for North American and European government agencies and departments and puts Palo Alto, California-based HP's hardware running Linux on the same level as rival IBM Corp. HP has certified both Red Hat Inc Enterprise Linux and Novell Inc's SuSE Linux running on its ProLiant and Itanium systems at evaluation assurance level (EAL) 3 with Controlled Access Protection Profile (CAPP). IBM achieved the same with Red Hat in August and SuSE in January. The link for this article located at Computer Business Online is no longer available. . HP's Unix accreditation under Common Criteria tier 3 enhances its protection for public sectors across North America and Europe.. HP Linux Certification, Government Security Compliance, EAL 3 Standards. . LinuxSecurity.com Team
The U.S. Department of Transportation has dismissed a claim filed against Northwest Airlines that accused the carrier of violating its own privacy policy when it gave government officials passenger . . .. The U.S. Department of Transportation has dismissed a claim filed against Northwest Airlines that accused the carrier of violating its own privacy policy when it gave government officials passenger information related to the Sept. 11 attacks. The department ruled late last week that Northwest's privacy policy, which was published on the airline's Web site, does not preclude the company from sharing data with the federal government, specifically when asked to do so. In fact, the department found that Northwest, which is based in Eagan, Minn., is required by law to make records, including passenger data, available to federal agencies "upon demand," according to a statement. The complaint, filed by consumer privacy watchdog Electronic Privacy Information Center (EPIC), which is based in Washington, D.C., and the Minnesota Civil Liberties Union, contended that Northwest engaged in unfair and deceptive practices when it shared passenger name and record data with the National Aeronautics and Space Administration. The Ames Research Center at NASA had sought the information in the months following Sept. 11 to aid in its efforts to make air travel safer, according to the Transportation Department. . The U.S. Department of Transportation has dismissed a claim filed against Northwest Airlines that ac. department, transportation, dismissed, claim, filed, against, northwest, airlines. . LinuxSecurity.com Team
SuSE and IBM have achieved a crucial security certification that will let the US government and military choose the operating system.. . .. SuSE and IBM have achieved a crucial security certification that will let the US government and military choose the operating system. Linux seller SuSE and server maker IBM have obtained a crucial security certification that will make the operating system an option for demanding military and government customers, the companies are expected to announce on Tuesday. Many governments require certification to the international Common Criteria standard before they're allowed to purchase a specific computing product. SuSE Linux Enterprise Server 8 running on IBM's Intel-based xSeries servers achieved Evaluation Assurance Level 2 (EAL2) of the Common Criteria, the companies are expected to announce at the LinuxWorld Conference and Expo. The link for this article located at ZDNet UK is no longer available. . SuSE and IBM have achieved a crucial security certification that will let the US government and mili. achieved, crucial, security, certification, government. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.