Configuration compliance for workstations and servers

Every workstation and server that touches sensitive data needs to be set up correctly and stay that way. Analog Informatics Corporation (AIC) kits check each system against an approved baseline, repair known settings right away with Fix-It, flag what needs your IT team, and rescan to prove the fix.

This is built into the AIC CMMC Completeâ„¢ Level 1, Level 2, and Level 3 kits. In industry terms it is part of identity security posture management (ISPM) and configuration compliance.

Short answers

What is checked?

Security settings on Windows and Linux workstations and servers: password and lockout policy, audit policy, session lock, cryptography settings, and malware protection, host firewall, and disk encryption status. Checks run through the endpoint agent or without an agent over SSH or WinRM.

What baselines are used?

STIG-oriented baselines. STIGs are the Security Technical Implementation Guides published by the Defense Information Systems Agency (DISA). Checks come in versioned probe packs that an administrator uploads and activates, and each pack is pinned by its hash. The packs cover selected STIG settings, not every STIG rule for every operating system.

Can it fix problems immediately?

Yes, for known settings. Fix-It pushes a repair to the system with operator confirmation, can run as a dry run first, and logs every attempt. Repairable settings include Windows password policy, audit policy, account lockout, session lock, and the FIPS cryptography setting, and Linux password aging, audit daemon, and session lock, with or without an agent.

What does it not fix?

Some findings need your IT team: for example, the host firewall and disk encryption are detected and flagged for IT, not changed remotely. Each finding says who should act: the product can repair it, it needs IT, or it is observe only.

How do you know a fix worked?

A finding is closed only when a later rescan no longer finds it. Applying a fix is not proof by itself.

Are the enclave systems built correctly from the start?

The enclave's workstations and servers are set up to STIG-oriented baselines, and the kit checks them against those baselines continuously. Windows workstations can also get an install lockdown pack that blocks unapproved software.

Can a system be blocked until it complies?

Yes. Workstation checks can be required before a person connects, so a system that fails its checks is not allowed in until it is fixed.

What is covered

Capability

  • Security configuration assessment on Windows and Linux, with or without an agent
  • STIG-oriented, versioned probe packs pinned by hash
  • Fix-It repair with confirmation, dry run, and an audit log
  • Findings labeled: product can repair, needs IT, or observe only
  • Rescan to verify a fix
  • Block a connection until the workstation passes its checks
  • STIG-oriented enclave workstations and servers
  • Windows install lockdown pack (WDAC and AppLocker)
  • Full DISA STIG coverage for every operating system version
  • Vulnerability analysis of systems

Screenshots

Every workstation and server shows its configuration findings and open findings, with rescan and Fix-It actions.
Fix-It repairs known settings with operator confirmation, and logs every attempt.
Measurement and Mitigation checks the environment against the selected framework and level.
Privileged User Management applies application control packs across Windows, Linux, and macOS, with live counts.

Platforms and integrations

Operating systems

  • Microsoft Windows
  • Linux
  • Red Hat Enterprise Linux
  • Ubuntu
  • Apple macOS

All logos and trademarks are the property of their respective owners. Their use does not imply endorsement.

See it on your use case

Request a demo