PAM, identity security, and GRC terms AIC supports

Industry analysts and buyers use a shared set of terms to describe privileged access, identity security, and governance, risk, and compliance (GRC) software. This page lists each term Analog Informatics Corporation (AIC) supports, what AIC does for it, its status, and the page that explains it. AIC offers two products on one platform: AIC Enterprise Privilege Management Suite™ and AIC CMMC Complete™. Governance, risk, and compliance (GRC) modules sit in the enterprise suite.

Two products on one platformTwo boxes side by side labeled AIC Enterprise Privilege Management Suite and AIC CMMC Complete. Under both, one wide bar labeled "One AIC platform".AIC Enterprise PrivilegeManagement Suite™AIC CMMC Complete™One AIC platform
The AIC Enterprise Privilege Management Suite™ and AIC CMMC Complete™ share one AIC platform.

Status words on this page: Available now means it ships today. Available now, wider scope planned means it ships today with the scope shown, and more is on the roadmap. Planned means it is on the roadmap and does not ship today.

Privileged access and credential management terms

TermAcronymWhat AIC doesStatusPage
Privileged access managementPAMControls who opens privileged sessions, through which path, and records what happenedAvailable nowCapabilities
Privileged identity managementPIMVaults privileged credentials and rotates them on a scheduleAvailable nowCapabilities
Privileged account and session managementPASMVaulting, checkout, launch, and session control for privileged accountsAvailable nowIndustry functions
Privileged password management and credential vaulting-Stores, rotates, and releases privileged passwords under approvalAvailable nowCapabilities
Privilege elevation and delegation managementPEDMElevates approved applications and commands without standing administrator rights. Windows coverage is the most complete. Apple Mac and Unix/Linux coverage is expandingAvailable now, wider scope plannedIndustry functions
Endpoint privilege managementEPMThe same Privileged User Management elevation and least-privilege control on endpointsAvailable now, wider scope plannedIndustry functions
Least privilege and application control-Removes standing administrator rights and allows or denies named applicationsAvailable now, wider scope plannedIndustry functions
Just-in-time privileged accessJITGrants time-bound elevation and access that expireAvailable nowIndustry functions
Zero standing privilegesZSPNo standing administrator rights on enrolled systems. Short-lived accounts created on demand are plannedAvailable now, wider scope plannedIndustry functions
Remote privileged access managementRPAMBrokers remote sessions through Jump, with recording in the Level 3 kitAvailable nowIndustry functions
Vendor and third-party privileged access-Vendors and contractors reach systems through the same Jump path, approvals, and recordingAvailable nowIndustry functions
Session management and session recording-Brokers SSH, RDP, and VNC sessions in the browser, with recording and replay on the Level 3 kitAvailable nowCapabilities
Command filtering and command control-Allows or denies commands inside privileged sessionsAvailable nowCapabilities
Secure application launch and credential injection-Opens tools with the credential supplied, never shown to the userAvailable nowCapabilities
Secrets management-Stores and releases secrets for people and servicesAvailable nowIndustry functions
Machine identity and non-human identityNHIManages service accounts and their credentialsAvailable now, wider scope plannedIndustry functions
Privileged account and device discovery-Finds systems and default or weak passwords in useAvailable nowKnown default credentials
Cloud infrastructure entitlement managementCIEMAnalysis of cloud permissions across cloud accountsPlannedIndustry functions
Certificate lifecycle managementCLMDiscovery, renewal, and replacement of certificatesPlannedIndustry functions

Identity security terms

TermAcronymWhat AIC doesStatusPage
Identity and access managementIAMBuilt-in identity for small and midsize businesses and CMMC enclaves, or sign-in with the organization's directoryAvailable nowDeployment and integrations
Role-based access controlRBACRoles and permissions on every console and enclave actionAvailable nowDeployment and integrations
Multifactor authenticationMFAA password plus a second step at sign-inAvailable nowConditional access
Single sign-on and federationSSOMicrosoft Active Directory, Microsoft Entra ID, Okta, Ping Identity, and other OpenID Connect providers, plus Security Assertion Markup Language (SAML) 2.0 federationAvailable nowDeployment and integrations
Conditional access and adaptive access-Sign-in rules by country, network address, threat intelligence, and MFAAvailable nowConditional access
Zero trust access decisions-Every sign-in and session is checked against policy, with least privilege by defaultAvailable nowConditional access
Threat intelligence-Known-bad network addresses are blocked at sign-inAvailable nowConditional access
Identity threat detection and responseITDRDetects identity attacks, alerts, and respondsAvailable nowIndustry functions
Identity security posture managementISPMFinds identity configuration weaknesses and exposuresAvailable nowIndustry functions
Identity governance and administrationIGAAccount lifecycle and periodic access review for accounts the kit manages. Governance across other business applications is plannedAvailable now, wider scope plannedIndustry functions
Access reviews and access certification-Periodic review of who holds access to managed accountsAvailable now, wider scope plannedIndustry functions

Governance, risk, and compliance terms

TermAcronymWhat AIC doesStatusPage
Governance, risk, and complianceGRCEvidence, findings, risk register, plan of action and milestones, training, and attestation in one consoleAvailable nowContinuous compliance
Continuous controls monitoringCCMRescans controls and shows current status for each findingAvailable nowContinuous compliance
Compliance automation and evidence collection-The product gathers its own evidence and assembles it for assessorsAvailable nowContinuous compliance
Audit management-Assessment Binder sections built from live product recordsAvailable nowContinuous compliance
Risk register-Records risks, owners, and decisionsAvailable nowDetect, respond, remediate
Plan of action and milestonesPOA&MTracks remediation items to closureAvailable nowDetect, respond, remediate
Security configuration management and configuration compliance-Checks systems against a baseline configuration and reports configuration driftAvailable nowConfiguration compliance
Security awareness training and attestation-Assigns documents, sends reminders, and records signed attestationsAvailable nowCapabilities
Incident responseIRDetections, notices, and response recordsAvailable nowDetect, respond, remediate
Security information and event management integrationSIEMSends events to a SIEM through syslog and the Windows Event LogAvailable nowDetect, respond, remediate
MITRE ATT&CK mapping-Maps detections to MITRE ATT&CK techniquesAvailable nowDetect, respond, remediate
Data classification and marking-Classification labels on records and access rules by labelAvailable nowClassification
Regulatory framework mapping-CMMC, NIST SP 800-171, NIST SP 800-53, ISO/IEC 27001, and other frameworksAvailable nowFrameworks

CMMC and secure enclave terms

TermAcronymWhat AIC doesStatusPage
Cybersecurity Maturity Model Certification enclaveCMMC enclaveA customer-controlled enclave with the tools for CMMC Level 1, Level 2, and Level 3Available nowSecure enclaves
Controlled Unclassified Information enclaveCUI enclaveA bounded environment for handling Controlled Unclassified InformationAvailable nowSecure enclaves
CMMC Level 1, Level 2, and Level 3 kits-Kits that include the tools, workflows, and evidence for each levelAvailable nowCMMC requirements and features
Air-gapped operation-Runs with no general network reachAvailable nowAir-gapped systems

Key management and cryptography terms

TermAcronymWhat AIC doesStatusPage
Cloud key management serviceKMSStored secrets protected by a customer-owned AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS keyAvailable nowKey management
Hardware security moduleHSMKey custody on a hardware security moduleAvailable nowKey management
Bring your own keyBYOKThe organization supplies and holds the keyAvailable nowKey management
FIPS 140-3 validated cryptographyFIPSThe default cryptographic library is AWS-LC, which holds a Federal Information Processing Standards 140-3 certificate. Optional HSMs and cloud KMS keys carry their own certification, which the customer confirmsAvailable nowKey management

Operational technology terms

TermAcronymWhat AIC doesStatusPage
Operational technology privileged accessOTPrivileged access, credential rotation, and least privilege for industrial and control systemsAvailable nowOperational technology

See it on your use case

Request a demo