Oracle Corporation

12/03/2024 | Press release | Distributed by Public on 12/02/2024 22:11

Oracle Identity Governance completes Common Criteria certification

Oracle is pleased to share that Oracle Identity Governance (OIG) has completed Common Criteria certification. OIG 12c (build 12.2.1.4.0) conforms to the Standard Protection Profile for Enterprise Security Management Identity and Credential Management version 2.1. This evaluation was performed using the Common Methodology for Information Technology Security Evaluation, version 3.1 revision 5, for conformance to the Common Criteria for Information Technology Security Evaluation, version 3.1 revision 5. The evaluation was performed in an environment with Oracle Unified Directory 12c as the identity store, Oracle Database 19c as the database server, and Oracle Linux 8.

With this certification, Oracle Identity Governance 12c is included on the NIAP Product Compliant List (PCL), a requirement for information communication technology (ICT) products sold to the United States Department of Defense (DoD).

Providing enhanced security
Architecture diagram for the evaluation environment
Figure 1: Oracle Identity Governance evaluation environment architecture, where the target of evaluation (TOE) is OIG.
OIG provides complete user lifecycle management and rich access entitlement controls across a wide range of services for both on-premises and cloud. It supports microservices to discover common access patterns, optimize role-based access control, and automate the process of role publishing to Oracle Identity Governance. OIG also manages user provisioning and deprovisioning and provides actionable identity intelligence that enables rapid remediation of high-risk user entitlements.

Common Criteria is an international framework (ISO/IEC 15408) that defines a standard approach for evaluating security features and capabilities of ICT products. Common Criteria provides assurance that these products have been evaluated in a rigorous, standardized, and repeatable manner at a level commensurate with the target environment in which it's used.

External security evaluations are part of the Oracle security assurance process and provide more assurance in the security of certain Oracle products to commercial, government, and military agencies. These evaluations and the criteria on which they're based are designed to help establish an acceptable level of confidence for IT purchasers and vendors alike.

Want to know more?
For a matrix of Oracle security evaluations currently in progress and completed, refer to the Oracle Security Evaluations page. To view a complete list of Oracle product Common Criteria security certifications that are completed and in progress, see the Oracle Common Criteria certifications page. You can also try Oracle Identity Governance on Oracle Cloud Infrastructure for yourself today!