PAM, identity security, and GRC terms AIC supports
Industry analysts and buyers use a shared set of terms to describe privileged access, identity security, and governance, risk, and compliance (GRC) software. This page lists each term Analog Informatics Corporation (AIC) supports, what AIC does for it, its status, and the page that explains it. AIC offers two products on one platform: AIC Enterprise Privilege Management Suite™ and AIC CMMC Complete™. Governance, risk, and compliance (GRC) modules sit in the enterprise suite.
Status words on this page: Available now means it ships today. Available now, wider scope planned means it ships today with the scope shown, and more is on the roadmap. Planned means it is on the roadmap and does not ship today.
Privileged access and credential management terms
| Term | Acronym | What AIC does | Status | Page |
|---|---|---|---|---|
| Privileged access management | PAM | Controls who opens privileged sessions, through which path, and records what happened | Available now | Capabilities |
| Privileged identity management | PIM | Vaults privileged credentials and rotates them on a schedule | Available now | Capabilities |
| Privileged account and session management | PASM | Vaulting, checkout, launch, and session control for privileged accounts | Available now | Industry functions |
| Privileged password management and credential vaulting | - | Stores, rotates, and releases privileged passwords under approval | Available now | Capabilities |
| Privilege elevation and delegation management | PEDM | Elevates approved applications and commands without standing administrator rights. Windows coverage is the most complete. Apple Mac and Unix/Linux coverage is expanding | Available now, wider scope planned | Industry functions |
| Endpoint privilege management | EPM | The same Privileged User Management elevation and least-privilege control on endpoints | Available now, wider scope planned | Industry functions |
| Least privilege and application control | - | Removes standing administrator rights and allows or denies named applications | Available now, wider scope planned | Industry functions |
| Just-in-time privileged access | JIT | Grants time-bound elevation and access that expire | Available now | Industry functions |
| Zero standing privileges | ZSP | No standing administrator rights on enrolled systems. Short-lived accounts created on demand are planned | Available now, wider scope planned | Industry functions |
| Remote privileged access management | RPAM | Brokers remote sessions through Jump, with recording in the Level 3 kit | Available now | Industry functions |
| Vendor and third-party privileged access | - | Vendors and contractors reach systems through the same Jump path, approvals, and recording | Available now | Industry functions |
| Session management and session recording | - | Brokers SSH, RDP, and VNC sessions in the browser, with recording and replay on the Level 3 kit | Available now | Capabilities |
| Command filtering and command control | - | Allows or denies commands inside privileged sessions | Available now | Capabilities |
| Secure application launch and credential injection | - | Opens tools with the credential supplied, never shown to the user | Available now | Capabilities |
| Secrets management | - | Stores and releases secrets for people and services | Available now | Industry functions |
| Machine identity and non-human identity | NHI | Manages service accounts and their credentials | Available now, wider scope planned | Industry functions |
| Privileged account and device discovery | - | Finds systems and default or weak passwords in use | Available now | Known default credentials |
| Cloud infrastructure entitlement management | CIEM | Analysis of cloud permissions across cloud accounts | Planned | Industry functions |
| Certificate lifecycle management | CLM | Discovery, renewal, and replacement of certificates | Planned | Industry functions |
Identity security terms
| Term | Acronym | What AIC does | Status | Page |
|---|---|---|---|---|
| Identity and access management | IAM | Built-in identity for small and midsize businesses and CMMC enclaves, or sign-in with the organization's directory | Available now | Deployment and integrations |
| Role-based access control | RBAC | Roles and permissions on every console and enclave action | Available now | Deployment and integrations |
| Multifactor authentication | MFA | A password plus a second step at sign-in | Available now | Conditional access |
| Single sign-on and federation | SSO | Microsoft Active Directory, Microsoft Entra ID, Okta, Ping Identity, and other OpenID Connect providers, plus Security Assertion Markup Language (SAML) 2.0 federation | Available now | Deployment and integrations |
| Conditional access and adaptive access | - | Sign-in rules by country, network address, threat intelligence, and MFA | Available now | Conditional access |
| Zero trust access decisions | - | Every sign-in and session is checked against policy, with least privilege by default | Available now | Conditional access |
| Threat intelligence | - | Known-bad network addresses are blocked at sign-in | Available now | Conditional access |
| Identity threat detection and response | ITDR | Detects identity attacks, alerts, and responds | Available now | Industry functions |
| Identity security posture management | ISPM | Finds identity configuration weaknesses and exposures | Available now | Industry functions |
| Identity governance and administration | IGA | Account lifecycle and periodic access review for accounts the kit manages. Governance across other business applications is planned | Available now, wider scope planned | Industry functions |
| Access reviews and access certification | - | Periodic review of who holds access to managed accounts | Available now, wider scope planned | Industry functions |
Governance, risk, and compliance terms
| Term | Acronym | What AIC does | Status | Page |
|---|---|---|---|---|
| Governance, risk, and compliance | GRC | Evidence, findings, risk register, plan of action and milestones, training, and attestation in one console | Available now | Continuous compliance |
| Continuous controls monitoring | CCM | Rescans controls and shows current status for each finding | Available now | Continuous compliance |
| Compliance automation and evidence collection | - | The product gathers its own evidence and assembles it for assessors | Available now | Continuous compliance |
| Audit management | - | Assessment Binder sections built from live product records | Available now | Continuous compliance |
| Risk register | - | Records risks, owners, and decisions | Available now | Detect, respond, remediate |
| Plan of action and milestones | POA&M | Tracks remediation items to closure | Available now | Detect, respond, remediate |
| Security configuration management and configuration compliance | - | Checks systems against a baseline configuration and reports configuration drift | Available now | Configuration compliance |
| Security awareness training and attestation | - | Assigns documents, sends reminders, and records signed attestations | Available now | Capabilities |
| Incident response | IR | Detections, notices, and response records | Available now | Detect, respond, remediate |
| Security information and event management integration | SIEM | Sends events to a SIEM through syslog and the Windows Event Log | Available now | Detect, respond, remediate |
| MITRE ATT&CK mapping | - | Maps detections to MITRE ATT&CK techniques | Available now | Detect, respond, remediate |
| Data classification and marking | - | Classification labels on records and access rules by label | Available now | Classification |
| Regulatory framework mapping | - | CMMC, NIST SP 800-171, NIST SP 800-53, ISO/IEC 27001, and other frameworks | Available now | Frameworks |
CMMC and secure enclave terms
| Term | Acronym | What AIC does | Status | Page |
|---|---|---|---|---|
| Cybersecurity Maturity Model Certification enclave | CMMC enclave | A customer-controlled enclave with the tools for CMMC Level 1, Level 2, and Level 3 | Available now | Secure enclaves |
| Controlled Unclassified Information enclave | CUI enclave | A bounded environment for handling Controlled Unclassified Information | Available now | Secure enclaves |
| CMMC Level 1, Level 2, and Level 3 kits | - | Kits that include the tools, workflows, and evidence for each level | Available now | CMMC requirements and features |
| Air-gapped operation | - | Runs with no general network reach | Available now | Air-gapped systems |
Key management and cryptography terms
| Term | Acronym | What AIC does | Status | Page |
|---|---|---|---|---|
| Cloud key management service | KMS | Stored secrets protected by a customer-owned AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS key | Available now | Key management |
| Hardware security module | HSM | Key custody on a hardware security module | Available now | Key management |
| Bring your own key | BYOK | The organization supplies and holds the key | Available now | Key management |
| FIPS 140-3 validated cryptography | FIPS | The default cryptographic library is AWS-LC, which holds a Federal Information Processing Standards 140-3 certificate. Optional HSMs and cloud KMS keys carry their own certification, which the customer confirms | Available now | Key management |
Operational technology terms
| Term | Acronym | What AIC does | Status | Page |
|---|---|---|---|---|
| Operational technology privileged access | OT | Privileged access, credential rotation, and least privilege for industrial and control systems | Available now | Operational technology |