Detect, Respond, and Remediate
Analog Informatics Corporation (AIC) kits help you find intruders early, respond in order, fix what they find, and keep the record. The tools are built into the AIC CMMC Completeâ„¢ Level 1, Level 2, and Level 3 kits. In industry terms they cover identity threat detection and response (ITDR) and identity security posture management (ISPM) for the systems the kits manage.

Short Answers
How does the kit detect attacks?
How does the kit handle an incident?
How does the kit remediate?
How does the kit limit the blast radius?
Does it help with incident reporting?
Tools by Stage
| Stage | Tool |
|---|---|
| Detect | Attack / Threat Report mapped to MITRE ATT&CK |
| Detect | Append-only logon audit |
| Detect | Threat intelligence deny at sign-in |
| Detect | Live security event feed |
| Detect | Known vendor default password checks |
| Respond | Incident Response process with email and text alert groups |
| Respond | Session Control: watch, approve, deny, or terminate privileged sessions |
| Respond | Syslog forwarding to a security information and event management (SIEM) system |
| Remediate | Current State Compliance rescan and control drift history |
| Remediate | Fix-It for findings the product can repair; findings that need IT are flagged |
| Remediate | On-demand credential rotation |
| Remediate | Plan of Action and Milestones and risk register |
| Document | Assessment Binder shared by the organization, its MSP, and its assessor |
| Detect | Vulnerability analysis (add-on module) |
Screenshots
Related Controls
| Framework | Controls |
|---|---|
| NIST SP 800-53 | AU-6, CA-7, IR-4, IR-5, IR-6, IR-8, RA-5, SI-4 |
| NIST SP 800-171 | 3.3.5, 3.6.1, 3.6.2, 3.11.2, 3.12.3, 3.14.6, 3.14.7 |
| CMMC | IR.L2-3.6.1, IR.L2-3.6.2, CA.L2-3.12.3, SI.L2-3.14.6 |
An assessment organization, and in some cases the government, decides whether an organization meets a framework.
An assessment organization, certification body, or regulator decides whether a requirement is satisfied.
How It Works
Detect
Identify attacks and configuration drift.
Respond
Send incident alerts and initiate response.
Remediate
Apply corrective action to findings.
Verify
Rescan and retain the resulting records.