Security

In Splunk 6.4, I noticed server.conf.spec has reference to Common Criteria mode. Does Splunk support that yet?

Ellen
Splunk Employee
Splunk Employee

Splunk Enterprise 6.4 release shows some .conf.spec files (eg. server.conf, authentication.conf ...) that has references to Common Criteria mode for some of the attributes.

Is Splunk 6.4 NIAP certified yet and supported?

1 Solution

Ellen
Splunk Employee
Splunk Employee

Splunk has submitted Splunk Enterprise 6.4.0 for Common Criteria evaluation.

Until we are common criteria certified we do not recommend nor support configuring Splunk Enterprise in common criteria mode.

This can also be referenced in the Splunk documentation: About securing Splunk Enterprise

View solution in original post

tchimento_splun
Splunk Employee
Splunk Employee

I am happy to say that the Splunk Enterprise 6.4.5 evaluation has been posted on NIAP’s Product Compliant List (PCL).

The posting can be found at the following URL:
https://www.niap-ccevs.org/Product/Compliant.cfm?pid=10807

0 Karma

tchimento_splun
Splunk Employee
Splunk Employee

When we are officially accepted by NIAP to start the CC certification evaluation, it will be posted to the NIAP website: https://www.niap-ccevs.org/Product/PINE.cfm

dchoi_splunk
Splunk Employee
Splunk Employee

Has there been any progress for the CC certification since then

0 Karma

dchoi_splunk
Splunk Employee
Splunk Employee

How CC certification evaluation goes? Has Splunk Enterprise 6.4.0 got the certification?
It's gone away from NIAP website

0 Karma

tchimento_splun
Splunk Employee
Splunk Employee

We have submitted to NIAP and are awaiting their response. Once accepted we will schedule the testing.

0 Karma

Ellen
Splunk Employee
Splunk Employee

Splunk has submitted Splunk Enterprise 6.4.0 for Common Criteria evaluation.

Until we are common criteria certified we do not recommend nor support configuring Splunk Enterprise in common criteria mode.

This can also be referenced in the Splunk documentation: About securing Splunk Enterprise

doksu
Contributor

Is the Protection Profile report available?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...