ACR 2 Products Listing
ACR currently has four families of products. They are ACR2Basic, ACR2 for PCI, ACR2Enterprise and Risk Reporter. Each product has minor variations, and products may be combined in a wide variety of ways to meet customer needs.
ACR2Basic consists of a list of questions that are answered online. It then creates a standardized NIST compliant risk assessment.
ACR2 for PCI consists of a list of questions that are answered online including all of the questions from the PCI DSS. It then creates a standardized NIST compliant risk assessment.
ACR2Enterprise combines up to 256 ACR2Basic and/or ACR2 for PCI installations on a single screen, allowing risk management of multiple sites.
Risk Reporter combines ACR2Basic with automatic network scanning and automatic uploading of antivirus and intrusion detection data to provide “near real-time” reporting of risk as called for in NIST 800-39. The scanning uses one of several scanners validated under the NIST Security Content Automation Program (SCAP), which allows simultaneous compliance with 800-39 and the FDCC. Risk Reporter can use several types of Unified Threat Management (UTM) system, but only the Fortinet UTMs have the necessary NIAP and IPv6 certifications for Federal use.