Privileged Access for the Public Sector

Government agencies, the intelligence community, and defense prime contractors run the same privileged access program as any large enterprise, with stricter rules on where the software runs and who holds the keys. The AIC Enterprise Privilege Suite™ runs inside your boundary: on premises, on air-gapped networks, or in your own cloud tenancy. Your organization holds the encryption keys.

AIC Enterprise Privilege Suite™ inside the agency boundaryA large rectangle labeled Your boundary. Inside it are boxes labeled AIC Enterprise Privilege Suite™ server, Your keys, Your directory, and Managed systems. Outside the rectangle is a crossed-out cloud labeled Vendor cloud not required.Your boundaryAIC Enterprise PrivilegeSuite™ serverYour keysYour directoryManaged systemsVendor cloud notrequired
AIC Enterprise Privilege Suite™ runs inside the agency network and holds its keys there. Nothing depends on a vendor cloud.

Short answers

Where does AIC Enterprise Privilege Suite™ run?

On your own servers, virtual machines, or cloud subscription, including air-gapped networks with no internet connection. See Government deployment.

Who holds the keys?

You do. Keys live in software, in your PKCS#11 Hardware Security Module (HSM), or in a key you own in a cloud key service.

What cryptography does it use?

AWS-LC, which holds a Federal Information Processing Standards (FIPS) 140-3 certificate, on server cryptographic paths.

Which frameworks does it map to?

National Institute of Standards and Technology (NIST) SP 800-53 and the other frameworks on the Frameworks page. The mappings show which controls the product supports. Your assessor decides whether a control is satisfied.

What public-sector programs use AIC Enterprise Privilege Suite™ for

Need What AIC Enterprise Privilege Suite™ provides Status
Vault, rotate, and propagate privileged credentials Privileged Identity Management across Windows, Linux, Unix, databases, directories, network devices, and cloud keys Available now
Brokered, recorded administrator sessions SSH, RDP, and VNC in the browser, with approvals, recording, and command restriction Available now
Least privilege on workstations and servers Endpoint privilege elevation on Windows, macOS, and Linux Available now, wider scope planned
Separate networks and enclaves One server per enclave with separate key sets, and disconnected operation Available now
Air-gapped elevation Signed elevation tokens that work with no network path to the server Available now
Audit to your security operations center Windows Event Log and syslog in RFC 5424, CEF, or LEEF, and direct delivery to common SIEM tools Available now
Configuration baselines Checks against Security Technical Implementation Guide (STIG) oriented baselines, with repair of known settings Available now, wider scope planned
Assessor-ready records Assessment Binder with sections built from live product records Available now
Operational Technology (OT) access OT inventory and brokered access for control systems Available now, wider scope planned

Deployment options

Option Status
On premises, on physical servers or virtual machines Available now
Air-gapped networks Available now
Your own commercial cloud subscription or account Available now
STIG-hardened server images Available now

Need AIC Enterprise Privilege Suite™ in a government cloud such as Microsoft Azure Government or Government Community Cloud (GCC)? Contact us.

Talk to the public-sector team

Send us your requirements, or ask for a briefing on your deployment model.

Contact us