NIS2 and the AIC Kits

The NIS2 Directive (EU) 2022/2555 sets cybersecurity risk-management measures for essential and important entities in the European Union. Analog Informatics Corporation (AIC) kits cover access control, cryptography, incident handling, and continuous monitoring on paths the kit manages. The national competent authority decides compliance. The kits run in a secure enclave, air-gapped or generally connected.

An interconnected regional critical infrastructure network with redundant protected channels and a technical policy binder
NIS2 and the AIC Kits

What Availability Means

Article 21(2) Measures

Measure What the Kit Does
(a) Risk analysis and information system security policies Current State Compliance records findings. Policy stays with the organization.
(b) Incident handling Incident Response records the event and can alert.
(c) Business continuity, backup, disaster recovery, and crisis management Recovery stays with the organization. High-availability database failover is available.
(d) Supply chain security Supplier review stays with the organization.
(e) Security in acquisition, development, and maintenance, including vulnerability handling Findings can be recorded. Vulnerability analysis is planned as an add-on module. Maintenance sessions go through Privileged Access Management.
(f) Assessing the effectiveness of risk-management measures Current State Compliance and the Assessment Binder.
(g) Basic cyber hygiene and cybersecurity training Training and attestation, and configuration compliance.
(h) Cryptography and encryption Validated cryptography on kit paths.
(i) Human resources security, access control, and asset management Privileged access, access review on kit accounts, and inventory of enrolled systems.
(j) Multi-factor or continuous authentication and secured communications Kit sign-in with another step beyond a password. Secured voice and video stay with the organization.

Screenshots

Incident Response follows a six-step process and sends email and text alerts to named groups.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.