NIST SP 800-171 and the AIC Level 2 Kit

The 110 National Institute of Standards and Technology (NIST) Special Publication 800-171 Rev 2 security requirements are the Cybersecurity Maturity Model Certification (CMMC) Level 2 practice set for Controlled Unclassified Information (CUI). Analog Informatics Corporation (AIC) addresses that set with the AIC Level 2 kit. The Level 2 kit includes the Level 1 kit. Privileged Identity Management, Privileged Access Management, Privileged User Management, Identity Governance and Administration, Audit, training and attestation, Secure Application Launch, Jump, command restriction, Incident Response, and validated cryptography are built into the Level 2 kit. A secure enclave is useful in many industries. The same kits run air-gapped, on a system that is not generally connected, and they run where a general network connection exists. See Secure Enclaves and Air-Gapped Systems.

A carefully partitioned document vault and workstation joined by a controlled gateway
NIST SP 800-171 and the AIC Level 2 Kit

The practice-by-practice map is on the CMMC Level 2 page. An assessment organization decides the assessment outcome.

The kit receives constant feeds, generates alerts, mitigates issues, and constantly monitors configuration compliance, so the 800-171 record is continuous rather than point-in-time. NIST Special Publication 800-53 is the broader baseline. See NIST SP 800-53.

Screenshots

The control catalog lists every practice with its CMMC identifier and NIST SP 800-53 crosswalk.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.