Privileged Access for the Public Sector
Government agencies, the intelligence community, and defense prime contractors run the same privileged access program as any large enterprise, with stricter rules on where the software runs and who holds the keys. The AIC Enterprise Privilege Suite™ runs inside your boundary: on premises, on air-gapped networks, or in your own cloud tenancy. Your organization holds the encryption keys.
Short answers
Where does AIC Enterprise Privilege Suite™ run?
On your own servers, virtual machines, or cloud subscription, including air-gapped networks with no internet connection. See Government deployment.
Who holds the keys?
You do. Keys live in software, in your PKCS#11 Hardware Security Module (HSM), or in a key you own in a cloud key service.
What cryptography does it use?
AWS-LC, which holds a Federal Information Processing Standards (FIPS) 140-3 certificate, on server cryptographic paths.
Which frameworks does it map to?
National Institute of Standards and Technology (NIST) SP 800-53 and the other frameworks on the Frameworks page. The mappings show which controls the product supports. Your assessor decides whether a control is satisfied.
What public-sector programs use AIC Enterprise Privilege Suite™ for
| Need | What AIC Enterprise Privilege Suite™ provides | Status |
|---|---|---|
| Vault, rotate, and propagate privileged credentials | Privileged Identity Management across Windows, Linux, Unix, databases, directories, network devices, and cloud keys | Available now |
| Brokered, recorded administrator sessions | SSH, RDP, and VNC in the browser, with approvals, recording, and command restriction | Available now |
| Least privilege on workstations and servers | Endpoint privilege elevation on Windows, macOS, and Linux | Available now, wider scope planned |
| Separate networks and enclaves | One server per enclave with separate key sets, and disconnected operation | Available now |
| Air-gapped elevation | Signed elevation tokens that work with no network path to the server | Available now |
| Audit to your security operations center | Windows Event Log and syslog in RFC 5424, CEF, or LEEF, and direct delivery to common SIEM tools | Available now |
| Configuration baselines | Checks against Security Technical Implementation Guide (STIG) oriented baselines, with repair of known settings | Available now, wider scope planned |
| Assessor-ready records | Assessment Binder with sections built from live product records | Available now |
| Operational Technology (OT) access | OT inventory and brokered access for control systems | Available now, wider scope planned |
Deployment options
| Option | Status |
|---|---|
| On premises, on physical servers or virtual machines | Available now |
| Air-gapped networks | Available now |
| Your own commercial cloud subscription or account | Available now |
| STIG-hardened server images | Available now |
Need AIC Enterprise Privilege Suite™ in a government cloud such as Microsoft Azure Government or Government Community Cloud (GCC)? Contact us.
Talk to the public-sector team
Send us your requirements, or ask for a briefing on your deployment model.