HITRUST and the AIC Kits
Analog Informatics Corporation (AIC) kits include an auditing package for organizations working toward a HITRUST assessment. Audit records and the Assessment Binder are built in. The same records can feed Competitors, or another package the organization already runs. A HITRUST assessor and HITRUST decide the result. The kits run in a secure enclave, air-gapped or generally connected.

The 19 Assessment Domains
| Domain | What the Kit Does |
|---|---|
| 01 Information Protection Program | The organization writes the program. The Assessment Binder stores it. |
| 02 Endpoint Protection | Configuration compliance checks enrolled systems. Host malware protection stays with the organization. |
| 03 Portable Media Security | Portable media outside the kit stays with the organization. |
| 04 Mobile Device Security | Mobile device management stays with the organization. |
| 05 Wireless Security | Wireless design stays with the organization. |
| 06 Configuration Management | Configuration compliance and Current State Compliance. |
| 07 Vulnerability Management | Findings can be recorded. Vulnerability analysis is planned as an add-on module. |
| 08 Network Protection | Jump is the managed privileged path. Network devices stay with the organization. |
| 09 Transmission Protection | Validated cryptography on kit paths. |
| 10 Password Management | Privileged Identity Management vaults and rotates credentials. |
| 11 Access Control | Privileged Access Management, Privileged User Management, and access review on kit accounts. |
| 12 Audit Logging and Monitoring | Audit, Windows Event Log, syslog, alerts, and continuous monitoring. |
| 13 Education, Training, and Awareness | Training and attestation assigns material and records a signature. |
| 14 Third Party Assurance | Supplier review stays with the organization. A Managed Service Provider can operate inside the kit. |
| 15 Incident Management | Incident Response records the event and can alert. |
| 16 Business Continuity and Disaster Recovery | Recovery stays with the organization. High-availability database failover is available. |
| 17 Risk Management | Current State Compliance records findings. Risk acceptance stays with the organization. |
| 18 Physical and Environmental Security | Facilities stay with the organization. |
| 19 Data Protection and Privacy | Document sharing vault and validated cryptography on kit paths. Privacy requests stay with the organization. |
See HIPAA for the Security Rule safeguards and Partners and Migration for evidence feeds.
Screenshots
More on Product Screenshots.
An assessment organization, certification body, or regulator decides whether a requirement is satisfied.