Privileged access and identity functions in the AIC kits
Analog Informatics Corporation (AIC) Level 2 and Level 3 kits perform privileged account and session management (PASM), privilege elevation and delegation management (PEDM), secrets management, remote privileged access management (RPAM), just-in-time (JIT) privilege management, zero standing privileges (ZSP) for elevation, identity governance and administration (IGA) for kit accounts, identity threat detection and response (ITDR), and machine identity for service accounts. Cloud infrastructure entitlement management (CIEM) is planned. Identity security posture management (ISPM) is built into the Level 1, Level 2, and Level 3 kits. The modules are built into the kits and are not sold one by one. The same privileged access functions are offered for general-purpose use in the AIC Enterprise Privilege Management Suite™. The Level 2 kit includes the Level 1 kit. The Level 3 kit includes the Level 2 kit.
Which industry functions do the AIC modules perform?
These answers use the privileged-access and identity terms customers search for. Each function is built into the AIC kit named in the answer.
Does AIC perform privileged account and session management?
Yes. Analog Informatics Corporation (AIC) performs privileged account and session management (PASM) in the AIC Level 2 and Level 3 kits through Privileged Identity Management, Privileged Access Management, Audit, Secure Application Launch, and Jump.
Does AIC perform privilege elevation and delegation management?
Yes. Analog Informatics Corporation (AIC) performs privilege elevation and delegation management (PEDM) in the AIC Level 2 and Level 3 kits through Privileged User Management. It covers endpoint privilege elevation, delegation, least-privilege enforcement, application and command control, just-in-time elevation, and privileged activity auditing. Windows coverage is the most complete today. Apple Mac and Unix/Linux coverage is expanding.
Does AIC perform secrets management?
Yes. Analog Informatics Corporation (AIC) performs secrets management in the AIC Level 2 and Level 3 kits through Privileged Identity Management and Secure Application Launch.
Does AIC perform cloud infrastructure entitlement management?
Planned. Cloud infrastructure entitlement management (CIEM), the analysis of cloud permissions across cloud accounts, is on the Analog Informatics Corporation (AIC) roadmap. Today the kits control privileged access to the systems they manage.
Does AIC perform remote privileged access management?
Yes. Analog Informatics Corporation (AIC) performs remote privileged access management (RPAM) in the AIC Level 2 and Level 3 kits through Privileged Access Management and Jump. The Level 3 kit adds session recording on Jump.
Does AIC perform just-in-time privilege management?
Yes. Analog Informatics Corporation (AIC) performs just-in-time (JIT) privilege management in the AIC Level 2 and Level 3 kits through Privileged User Management.
Does AIC perform zero standing privileges?
Yes, for elevation. Analog Informatics Corporation (AIC) removes standing administrator rights on enrolled systems and grants time-bound elevation through Privileged User Management in the AIC Level 2 and Level 3 kits. Creating short-lived accounts on demand is planned.
Does AIC perform identity governance and administration?
Yes, for kit accounts. Analog Informatics Corporation (AIC) performs identity governance and administration (IGA) for accounts the kit manages in the AIC Level 2 and Level 3 kits: account lifecycle and periodic access review. Governance across other business applications is planned.
Does AIC perform identity threat detection and response?
Yes. Analog Informatics Corporation (AIC) performs identity threat detection and response (ITDR) in the AIC Level 2 and Level 3 kits through Audit and Incident Response. The kit receives constant feeds, generates alerts, and mitigates issues.
Does AIC perform identity security posture management?
Yes. Analog Informatics Corporation (AIC) performs identity security posture management (ISPM) in the AIC Level 1, Level 2, and Level 3 kits through Current State Compliance and configuration compliance. The kit constantly monitors system configuration compliance.
Does AIC perform machine identity management?
Yes, for service and machine accounts. Analog Informatics Corporation (AIC) vaults and rotates service and machine account credentials through Privileged Identity Management in the AIC Level 2 and Level 3 kits. Certificate lifecycle management is planned.
These are the industry terms for privileged access and identity. Privileged account and session management (PASM), privilege elevation and delegation management (PEDM), secrets management, cloud infrastructure entitlement management (CIEM), and remote privileged access management (RPAM) are the privileged-access tool categories. Just-in-time (JIT) privilege management and zero standing privileges (ZSP) are functions in that scope. Identity governance and administration (IGA), identity threat detection and response (ITDR), and identity security posture management (ISPM) are adjacent identity terms.
| Capability (AIC module) | What it does | Industry function performed | Built into |
|---|---|---|---|
| Assessment Binder | Living evidence package an assessor can read | Shared audit record for the C3PAO, the MSP, and the customer | AIC Level 1, Level 2, and Level 3 kits |
| Current State Compliance | Ledger of control-oriented findings, with rescan | Identity security posture management (ISPM) | AIC Level 1, Level 2, and Level 3 kits |
| Privileged Identity Management (PIM) | Credential lifecycle and vaulted identities | Privileged account and session management (PASM); secrets management; machine identity | AIC Level 2 and Level 3 kits |
| Privileged Access Management (PAM) | Session connect and open, Jump, command restriction, and session recording on Level 3 | Privileged account and session management (PASM); remote privileged access management (RPAM) | AIC Level 2 and Level 3 kits |
| Privileged User Management (PUM) | Privilege Elevation and Delegation Management (PEDM): endpoint privilege elevation, delegation, least-privilege enforcement, application and command control, just-in-time (JIT) elevation, and privileged activity auditing on Windows, Apple Mac, and Unix/Linux | Privilege elevation and delegation management (PEDM); just-in-time (JIT) privilege management; zero standing privileges (ZSP) | AIC Level 2 and Level 3 kits |
| Identity Governance and Administration (IGA) | Account lifecycle and periodic access review | Identity governance and administration (IGA) for kit accounts. Cloud infrastructure entitlement management (CIEM) is planned | AIC Level 2 and Level 3 kits |
| Audit | Privileged-action and session records on product paths, and Windows Event Log or syslog when configured | Privileged account and session management (PASM) session audit; identity threat detection and response (ITDR) | AIC Level 2 and Level 3 kits |
| Document sharing vault | Store and share FCI and Controlled Unclassified Information (CUI) | Protected information sharing. Not a privileged-access tool category | AIC Level 1, Level 2, and Level 3 kits |
| Training and attestation | Assign documents and collect a signed attestation | Workforce attestation. Not a privileged-access tool category | AIC Level 2 and Level 3 kits |
| Secure Application Launch | Start an application with credentials the user does not see | Secrets management; privileged account and session management (PASM) | AIC Level 2 and Level 3 kits |
| Jump | Managed access path for sessions. The Level 3 kit adds session recording | Remote privileged access management (RPAM); privileged account and session management (PASM) | AIC Level 2 and Level 3 kits |
| Incident Response | Incident records and notification | Identity threat detection and response (ITDR) | AIC Level 2 and Level 3 kits |
| Federal Information Processing Standards (FIPS) cryptography | Cryptography on product paths | Cryptographic protection of kit paths. Not a privileged-access tool category | AIC Level 2 and Level 3 kits |
| Configuration compliance | Check system configuration against an approved baseline, with an optional block, when workstations connect | Identity security posture management (ISPM) | AIC Level 1, Level 2, and Level 3 kits |
| Governed mail | Mail for FCI or CUI | Mail for FCI and CUI. Not a privileged-access tool category | Optional on the AIC Level 1 kit. Built into the AIC Level 2 and Level 3 kits |
Screenshots
More on Product screenshots.
Related References
- CMMC: Kits, Level 1, Level 2, Level 3, Defense contractors, C3PAO
- Defense contract requirements: SPRS score, DFARS 252.204-7012, DFARS 252.204-7021, NIST SP 800-171 self-assessment, CUI marking, CMMC Phase 2