Security Frameworks and the AIC Kits

Analog Informatics Corporation (AIC) kits help an organization work on compliance for these frameworks. The same modules are built into the Level 1, Level 2, and Level 3 kits. Availability on each framework page is product availability: available now, available now with wider scope planned, planned, or organization. An assessment organization or regulator decides the outcome. A secure enclave is useful in many industries. The same kits run air-gapped, on a system that is not generally connected, and they run where a general network connection exists. See Secure Enclaves and Air-Gapped Systems.

A structured archive of distinct technical binders linked to a precisely aligned grid of glass control tiles
Security Frameworks and the AIC Kits

Framework Pages

Screenshots

77 frameworks and 722 requirement rows are crosswalked to NIST SP 800-53 in the product.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

Frequently Asked Questions

Which frameworks do the AIC kits map to?

Cybersecurity Maturity Model Certification (CMMC), NIST SP 800-171, NIST SP 800-172, NIST SP 800-53, SOC 2, HITRUST, HIPAA, PCI DSS, GDPR, California privacy law, NERC CIP, IEC 62443, ISO/IEC 27001, NIS2, and the Essential Eight.

What does each CMMC level cover?

Level 1 covers Federal Contract Information (FCI). Level 2 covers Controlled Unclassified Information (CUI) and the 110 NIST SP 800-171 Rev 2 requirements. Level 3 adds the 24 requirements selected from NIST SP 800-172.

Who assesses my organization for CMMC?

A CMMC Third-Party Assessment Organization (C3PAO) assesses your organization. The AIC kits provide the tools, records, and Assessment Binder evidence the assessor reviews.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.