Configuration compliance for workstations and servers
Every workstation and server that touches sensitive data needs to be set up correctly and stay that way. Analog Informatics Corporation (AIC) kits check each system against an approved baseline, repair known settings right away with Fix-It, flag what needs your IT team, and rescan to prove the fix.
This is built into the AIC CMMC Completeâ„¢ Level 1, Level 2, and Level 3 kits. In industry terms it is part of identity security posture management (ISPM) and configuration compliance.
Short answers
What is checked?
Security settings on Windows and Linux workstations and servers: password and lockout policy, audit policy, session lock, cryptography settings, and malware protection, host firewall, and disk encryption status. Checks run through the endpoint agent or without an agent over SSH or WinRM.
What baselines are used?
STIG-oriented baselines. STIGs are the Security Technical Implementation Guides published by the Defense Information Systems Agency (DISA). Checks come in versioned probe packs that an administrator uploads and activates, and each pack is pinned by its hash. The packs cover selected STIG settings, not every STIG rule for every operating system.
Can it fix problems immediately?
Yes, for known settings. Fix-It pushes a repair to the system with operator confirmation, can run as a dry run first, and logs every attempt. Repairable settings include Windows password policy, audit policy, account lockout, session lock, and the FIPS cryptography setting, and Linux password aging, audit daemon, and session lock, with or without an agent.
What does it not fix?
Some findings need your IT team: for example, the host firewall and disk encryption are detected and flagged for IT, not changed remotely. Each finding says who should act: the product can repair it, it needs IT, or it is observe only.
How do you know a fix worked?
A finding is closed only when a later rescan no longer finds it. Applying a fix is not proof by itself.
Are the enclave systems built correctly from the start?
The enclave's workstations and servers are set up to STIG-oriented baselines, and the kit checks them against those baselines continuously. Windows workstations can also get an install lockdown pack that blocks unapproved software.
Can a system be blocked until it complies?
Yes. Workstation checks can be required before a person connects, so a system that fails its checks is not allowed in until it is fixed.
What is covered
Capability
- Security configuration assessment on Windows and Linux, with or without an agent
- STIG-oriented, versioned probe packs pinned by hash
- Fix-It repair with confirmation, dry run, and an audit log
- Findings labeled: product can repair, needs IT, or observe only
- Rescan to verify a fix
- Block a connection until the workstation passes its checks
- STIG-oriented enclave workstations and servers
- Windows install lockdown pack (WDAC and AppLocker)
- Full DISA STIG coverage for every operating system version
- Vulnerability analysis of systems
Screenshots
Platforms and integrations
Operating systems
All logos and trademarks are the property of their respective owners. Their use does not imply endorsement.
Related References
- CMMC: Kits, Level 1, Level 2, Level 3, Defense contractors, C3PAO
- Defense contract requirements: SPRS score, DFARS 252.204-7012, DFARS 252.204-7021, NIST SP 800-171 self-assessment, CUI marking, CMMC Phase 2