AIC capabilities
Analog Informatics Corporation (AIC) builds privileged access, identity, audit, and compliance evidence as modules on one platform. Those modules ship in two products. The AIC Enterprise Privilege Management Suiteâ„¢ is the set of modules enterprise buyers score. AIC CMMC Completeâ„¢ is a new, separate kit for Cybersecurity Maturity Model Certification (CMMC) Level 1, Level 2, and Level 3. Modules are not sold one by one. The Level 2 kit includes the Level 1 kit. The Level 3 kit includes the Level 2 kit. Both products run in the cloud or on premises, in a secure enclave, and on air-gapped systems.
The kits receive constant feeds, generate alerts, mitigate issues, and constantly check each system against its baseline configuration where a feed path exists. That makes continuous compliance possible instead of a point-in-time check. Training is free. We work with the reseller, Managed Service Provider, or service provider the customer already uses.
Capability list
| Capability | What it does |
|---|---|
| Privileged Identity Management (PIM) | Discover systems, accounts, privileged group membership, password age, SSH keys, and cloud access keys. Find where each credential is used, change it, and push the new value to every service, task, application pool, COM+ and DCOM application, connection string, and configuration file that uses it. Covers Windows, macOS, Linux and Unix, Active Directory and LDAP, databases, cloud accounts, network and hardware devices, and applications. Extend to any other platform with SSH and Telnet scripts, browser automation, or the REST API (OpenAPI). Vault and check out credentials. See Privileged Identity Management. |
| Blast radius | Report how many hosts and services each shared credential reaches, and reduce it by rotating and propagating or by splitting the account into one managed service account per host, with a preview first. |
| Browser automation | Change credentials on devices and services that are managed only through a web page. Ready-made automations ship with the kit. Build your own in the console with a visual workflow builder. |
| Privileged Access Management (PAM) | Live SSH, RDP, and VNC sessions in the browser through a broker, approvals, and command restriction that blocks dangerous commands as they are typed. |
| Session recording | Recorded SSH, RDP, and VNC sessions with replay on the Level 3 kit. |
| Jump | Managed access path for privileged sessions. The Level 3 kit isolates Jump and records sessions. |
| Privileged User Management (PUM) | Privilege elevation and delegation management: endpoint elevation, delegation, least privilege, application and command control, just-in-time elevation, and privileged activity auditing. Elevate through the Agent on the system or by remote control from the AIC Server, with one-time activation codes, challenge and response, signed grants, or agentless WinRM and SSH. Windows is the most complete today. Apple Mac and Unix/Linux are expanding. See Privileged User Management. |
| Identity Governance and Administration (IGA) | Account lifecycle and periodic access review for kit accounts. Governance across other applications is planned. |
| Secure Application Launch | Start an application with credentials the user never sees. |
| Document sharing vault | Store and share sensitive files with classification marking. |
| Data classification | CMMC, US government, NATO, and national markings with clearances, mandatory access control, and audited formal release. See Data classification. |
| Conditional access | Allow, step up, or deny sign-in by country, network address, multifactor authentication, and session policy. See Conditional access and threat defense. |
| Threat intelligence and attack report | Deny sign-in from addresses on threat feeds, and report blocked and failed attempts mapped to MITRE ATT&CK. |
| Audit and event forwarding | Privileged-action and session records, Windows Event Log, and syslog in RFC 5424, CEF, or LEEF. Route each event type to its own destinations: Splunk, Microsoft Sentinel, Azure Monitor, Datadog, Amazon CloudWatch, Google Cloud Logging, any web service, another AIC Server, email, and ServiceNow or Jira tickets. Text message notices through seven providers. See Logging, SIEM, and event forwarding. |
| Assessment Binder | Living evidence package shared by the assessor, the Managed Service Provider, and the customer. |
| Current State Compliance | Ledger of control findings with rescan. |
| Configuration compliance | Check workstations and servers against STIG-oriented baselines, repair known settings with Fix-It, flag what needs IT, and optionally block a system until it complies. See Configuration compliance. |
| Known default credential detection | Scan networks, match systems and devices to licensed public default-password dictionaries, and flag dangerous defaults still in use. See Known default credentials. |
| VM power scheduling | Power off idle workstations and session capacity on a schedule or after idle time, and start them on demand, to cut cloud cost and shrink the attack surface. See VM power scheduling. |
| Incident Response | Incident records, detectors, and email or text alerts when a messaging path is configured. |
| Training and attestation | Assign documents to named people and collect a signed attestation. |
| Governed mail | Mail for Federal Contract Information or Controlled Unclassified Information inside the kit. |
| Cryptography and key custody | AWS-LC, which holds a FIPS 140-3 certificate, on server cryptographic paths. Keys in software, in a PKCS#11 HSM, or in a customer-owned AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS key. Separate key sets per system group, with rotation and re-encryption. See Key management. |
| Directory sign-in | Active Directory and LDAP sign-in, and Microsoft Entra ID, Okta, Ping Identity, and other OpenID Connect and Security Assertion Markup Language (SAML) 2.0 providers, with another step beyond a password. |
| High availability | Automatic database failover on customer-supplied hosts. |
| Air-gapped operation | The kits run on connected and fully air-gapped systems on Windows, Linux, and Apple Mac, in the cloud or on premises. The Agent rotates passwords on schedule from a shared seed with local propagation and no server connection, and handles elevation on the system itself. See Air-gapped systems. |
| Managed Service Provider operation | A Managed Service Provider can administer inside the customer boundary. |
| Localization | The operator console ships with 18 language packs. See Localization. |
| Evidence feeds | Records can feed Competitors and other compliance packages through export and syslog. |
| Certificate lifecycle management | Discovery, renewal, and governance of certificates across certificate authorities. |
| Cloud infrastructure entitlement management | Analysis of cloud account permissions. |
| Vulnerability analysis | Analysis of discovered systems for known vulnerabilities. Planned as an add-on module. |
| Universal host logon banner | One banner pushed to every system. |
The industry terms for these capabilities are on Industry functions.
Screenshots
More on Product screenshots.
Related References
- CMMC: Kits, Level 1, Level 2, Level 3, Defense contractors, C3PAO
- Defense contract requirements: SPRS score, DFARS 252.204-7012, DFARS 252.204-7021, NIST SP 800-171 self-assessment, CUI marking, CMMC Phase 2