AI Assistant & RAG for Cybersecurity Compliance
Customer Challenge
The Department of Navy (DON) and its Naval Warfare Center Training Systems Division seek artificial intelligence (AI) to assist the cybersecurity workforce in developing and maintaining Authority to Operate (ATO) packages via the Risk Management Framework (RMF).
Innovative Solution
Illumination Works offers our modular Odin-RMF solution to apply assisted intelligence to RMF/ATO package creation. Odin-RMF reduces the manual burden of detecting security control implementations and generates high-quality initial ATO content using large language models (LLM), prompt engineering, and retrieval augmented generation (RAG) for cornerstone documents such as the System Security Plan (SSP). Illumination Works is also validating a human-in-the-loop interactive user interface and chatbot that captures subject matter expert input and enables continuous refinement, ensuring accuracy, compliance, and consistency across the RMF/ATO process.
Benefits/Outcomes
- Apply AI techniques coupled with expert knowledge to speed identification of security controls
- Support human-in-the-loop review through an intuitive user interface to ensure cybersecurity professionals remain the decision makers
- Perform guided software risk assessments
- Generate initial text for completing the SSP
Toolbox
- Data Science, LLM, RAG, Generative AI
- Cybersecurity, RMF
- Integrative Design, UI Development, Chatbot
- Solution Architecture, App Development, Data Pipelines, Data Architecture
Domain Expertise
- Security controls
Business Value
- Significantly reduce time, manpower, and costs associated with creating and maintaining an ATO package
- Provide fast, efficient method to determine security control implementation and answer ATO questions, aligned with industry standards
- Improve ATO standardization and scalability of the RMF/ATO process across the enterprise
Other Odin Solutions
- Automate Data Rights Understanding Learn More
- Automated Data Curation, Crosslinking & Document Generation Learn More
- Data-Driven Financial Budget Planning Learn More