| Access Control3.1 |
Provided |
Role-based access with per-client walls; multi-factor authentication enforced for administrator and privileged accounts, available for every user. You provision people and assign roles. |
| Awareness & Training3.2 |
Customer |
Your security-awareness program. We train your administrators and operators at install. |
| Audit & Accountability3.3 |
Provided |
A tamper-evident, write-once activity log records every login, search, file open, and support action — traceable to a named person. You set retention and review cadence. |
| Configuration Management3.4 |
Provided |
A sealed, single-purpose appliance ships hardened; only signed updates can change it, and users cannot install software. Least-functionality by construction. |
| Identification & Authentication3.5 |
Provided |
Every person has a unique identity on the appliance; multi-factor authentication is enforced for privileged accounts. No shared logins required. |
| Incident Response3.6 |
Customer |
Your incident-response plan. The activity log and health alerts feed your detection and reporting. |
| Maintenance3.7 |
Shared |
Support reaches a constrained console that cannot open a client file. Access is one-time, dual-approval, least-privilege, and fully recorded. In the air-gapped posture, remote maintenance does not exist. |
| Media Protection3.8 |
Shared |
Client data is encrypted at rest (AES-256) and in transit (TLS 1.2+). We provide a documented drive-sanitization procedure for decommission; you own the physical media and execute it. |
| Personnel Security3.9 |
Customer |
Your screening and your access-revocation-on-departure processes. |
| Physical Protection3.10 |
Customer |
The appliance sits in a facility you control. Physical access, escort, and monitoring are yours — deliberately, and a strength for controlled data. |
| Risk Assessment3.11 |
Customer |
Your risk-management program. We supply the security posture of the appliance and its components for your scope. |
| Security Assessment3.12 |
Customer |
Your System Security Plan, POA&M, and assessment cadence. Our control-mapping package is an input to it. |
| System & Communications Protection3.13 |
Provided |
A self-contained enclave: no inbound ports, encryption in transit and at rest, and — in the air-gapped posture — no path off the box at all. No shared, multi-tenant platform. |
| System & Information Integrity3.14 |
Shared |
Flaws are remediated through signed updates we security-review before release. You layer your network monitoring and endpoint controls around the appliance. |