ISO/IEC 27001 and the AIC Kits

Analog Informatics Corporation (AIC) kits support the technological and record-keeping work in an ISO/IEC 27001 information security management system. ISO/IEC 27001:2022 Annex A groups 93 controls into four themes: organizational, people, physical, and technological. The control text is licensed by ISO, so this page maps themes and topics in our own words. An accredited certification body decides certification.

A precise management-system ring surrounding an information archive and a technical policy binder
ISO/IEC 27001 and the AIC Kits

What Availability Means

Theme and Topic Map

Theme and Topic What the Kit Does
Organizational: policies and roles The organization writes policy. The Assessment Binder stores it.
Organizational: access control and identity Privileged access, least privilege, and access review on kit accounts.
Organizational: supplier relationships Supplier review stays with the organization.
Organizational: incident management Incident Response records the event and can alert.
Organizational: continuity Recovery stays with the organization. High-availability database failover is available.
Organizational: compliance and independent review The Assessment Binder supports review.
People: screening and terms Screening stays with the organization.
People: awareness and training Training and attestation records a signature.
Physical: facilities and equipment Facilities stay with the organization.
Technological: privileged access rights Privileged Access Management and Privileged User Management.
Technological: authentication Kit sign-in with another step beyond a password.
Technological: malware protection Host malware protection stays with the organization.
Technological: vulnerability management Findings can be recorded. Vulnerability analysis is planned as an add-on module.
Technological: configuration management Configuration compliance.
Technological: logging and monitoring Audit, alerts, and continuous monitoring.
Technological: cryptography Validated cryptography on kit paths.
Technological: use of privileged utility programs Command restriction and application control.

Screenshots

77 frameworks and 722 requirement rows are crosswalked to NIST SP 800-53 in the product.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.