Detect, Respond, and Remediate

Analog Informatics Corporation (AIC) kits help you find intruders early, respond in order, fix what they find, and keep the record. The tools are built into the AIC CMMC Completeâ„¢ Level 1, Level 2, and Level 3 kits. In industry terms they cover identity threat detection and response (ITDR) and identity security posture management (ISPM) for the systems the kits manage.

A precision radar instrument detecting a small anomaly, connected to a containment boundary and a repaired modular server
Detect, Respond, and Remediate

Short Answers

How does the kit detect attacks?

The Attack / Threat Report maps blocked and failed attempts to MITRE ATT&CK. The logon audit records every sign-in attempt. Threat intelligence feeds deny known-bad addresses. A live event feed shows activity as it happens.

How does the kit handle an incident?

Incident Response follows a six-step process from intake to auditor evidence, and sends email and text alerts to named groups. Operators can watch or terminate privileged sessions.

How does the kit remediate?

Current State Compliance rescans controls and records drift. Each finding is labeled by who should act: the product can repair it, it needs IT, or it is observe only. Findings flow into a Plan of Action and Milestones (POA&M).

How does the kit limit the blast radius?

Just-in-time elevation removes standing administrator rights. Credentials are vaulted and rotated. Privileged sessions go through one gateway, can be recorded, and dangerous commands can be blocked. Sign-in can be limited by country, address, and threat feed.

Does it help with incident reporting?

Yes. The records the kit keeps help you report a cyber incident and show how you responded. DFARS 252.204-7012 requires reporting within 72 hours.

Tools by Stage

StageTool
DetectAttack / Threat Report mapped to MITRE ATT&CK
DetectAppend-only logon audit
DetectThreat intelligence deny at sign-in
DetectLive security event feed
DetectKnown vendor default password checks
RespondIncident Response process with email and text alert groups
RespondSession Control: watch, approve, deny, or terminate privileged sessions
RespondSyslog forwarding to a security information and event management (SIEM) system
RemediateCurrent State Compliance rescan and control drift history
RemediateFix-It for findings the product can repair; findings that need IT are flagged
RemediateOn-demand credential rotation
RemediatePlan of Action and Milestones and risk register
DocumentAssessment Binder shared by the organization, its MSP, and its assessor
DetectVulnerability analysis (add-on module)

Screenshots

Failed sign-ins are mapped to MITRE ATT&CK technique T1110 Brute Force, with top sources and most-tried usernames.
A live security event feed shows sign-ins, configuration changes, and vault activity as they happen.
Incident Response follows a six-step process and sends email and text alerts to named groups.
Session Control lets an operator approve, deny, watch, or terminate privileged sessions.
Control state history records drift over time, the core of continuous compliance.

Related Controls

FrameworkControls
NIST SP 800-53AU-6, CA-7, IR-4, IR-5, IR-6, IR-8, RA-5, SI-4
NIST SP 800-1713.3.5, 3.6.1, 3.6.2, 3.11.2, 3.12.3, 3.14.6, 3.14.7
CMMCIR.L2-3.6.1, IR.L2-3.6.2, CA.L2-3.12.3, SI.L2-3.14.6

An assessment organization, and in some cases the government, decides whether an organization meets a framework.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

How It Works

  1. Detect

    Identify attacks and configuration drift.

  2. Respond

    Send incident alerts and initiate response.

  3. Remediate

    Apply corrective action to findings.

  4. Verify

    Rescan and retain the resulting records.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.