Operational Technology and the AIC Kits

Analog Informatics Corporation (AIC) kits provide privileged access, least privilege, continuous configuration compliance monitoring, and a shared Assessment Binder for industrial environments. Organizations in those environments often also follow IEC 62443 or NERC CIP. The kit is the privileged-access and evidence layer beside operational technology (OT) operations. It is not a control-system safety product. A secure enclave is useful in many industries. The same kits run air-gapped, on a system that is not generally connected, and they run where a general network connection exists. See Secure Enclaves and Air-Gapped Systems.

An industrial machine and control cabinet with a carefully isolated maintenance access gateway
Operational Technology and the AIC Kits

The same modules are built into the AIC Level 1, Level 2, and Level 3 kits. The Level 2 kit includes the Level 1 kit. The Level 3 kit includes the Level 2 kit. The kits receive constant feeds, generate alerts, mitigate issues, and constantly monitor configuration compliance.

Which Industry Functions Apply to Operational Technology?

Industry FunctionAIC ModuleWhere It Is Built In
Privileged account and session management (PASM) and secrets managementPrivileged Identity Management and Secure Application LaunchLevel 2 and Level 3 kits
Remote privileged access management (RPAM)Privileged Access Management and JumpLevel 2 and Level 3 kits. Level 3 adds session recording
Privilege elevation and delegation management (PEDM), just-in-time (JIT) privilege, and zero standing privileges (ZSP)Privileged User Management on Windows, Apple Mac, and Unix/LinuxLevel 2 and Level 3 kits
Identity security posture management (ISPM)Current State Compliance and configuration complianceLevel 1, Level 2, and Level 3 kits
Identity threat detection and response (ITDR)Audit and Incident ResponseLevel 2 and Level 3 kits
Machine identityPrivileged Identity ManagementLevel 2 and Level 3 kits

Physical plant controls, safety systems, and the organization's IEC 62443 or NERC CIP program stay with the organization. The Assessment Binder stores the shared record for the assessor, the Managed Service Provider (MSP), and the customer.

Screenshots

The kit checks for dangerous vendor default passwords, including on operational technology devices.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.