Skip to main content

Compliance and Authorization

AVISSAA

Avint ISSO Advisory Assistant

The ISSO's conversational guide to every control, every step, every piece of evidence.

Ask what a control requires, what it means at your baseline, what an assessor will expect as proof, and what the mandatory tasks are at each RMF step. Answers come from the NIST corpus and cite the publication. It runs on a local model inside your boundary, and it never reads your data.

What does AC-2(3) require at Moderate, and what will the SCA want to see?

Control knowledge

AC-2(3) requires that accounts be disabled within an organization defined period when they are expired, no longer associated with a user, in violation of policy, or inactive for [organization defined time period]. At Moderate the enhancement is in the baseline. An assessor will examine the account management policy for the period, the disable procedure, and records showing accounts actually disabled within it.

What the assessor will want

  • Account review export. Shows inactive accounts identified within the period
  • Disable log or ticket sample. Shows the disable action within the period
  • Policy excerpt. States the organization defined period
SP 800-53 Rev 5, AC-2(3)SP 800-53A, AC-2(3) examine and interview

Illustrative answer. Local model, NIST corpus, citations shown.

Built for the job

You know these days.

Your first month as an ISSO

Three hundred controls, a baseline you did not choose, and everyone assuming you already know what AU-6 means in practice. Ask, in your own words, and get the answer with the publication it came from.

The assessor asked for evidence you do not have

Ask what an assessor examines, interviews and tests for the control, what artifact would satisfy each, and whether what you have is sufficient, usable, relevant, reliable and effective.

The ISSE building the control

Ask what the control actually requires at your impact level, how two related controls differ, and which one applies, before you build the wrong thing.

Leadership keeps asking

The questions that used to interrupt your day get a cited answer in seconds, so the ISSO answers them once and the executive stops waiting.

How it answers

Three domains, one corpus, every answer cited

Each question is classified into a domain, the right NIST material is retrieved for it, and the answer is written from that material only. The assistant is instructed never to substitute its own training knowledge for the publication.

01

Route

The question is classified: an RMF process question, a control knowledge question, or an evidence question. The control and the RMF step are picked out of your words, or taken from the page you are on.

Domain, control, step

02

Retrieve

The control's own document, the RMF step's tasks, and the closest passages from the ingested NIST corpus: SP 800-53 Rev 5, SP 800-53A, SP 800-37 Rev 2 and OSCAL control content.

The NIST material

03

Answer

A local model writes the answer from the retrieved material and cites the publication. Evidence questions are answered against the SURRE criteria: sufficient, usable, relevant, reliable, effective.

Cited answer

Local model

The three domains

RMF process

What the mandatory tasks are at Prepare, Categorize, Select, Implement, Assess, Authorize and Monitor, and what each produces.

Control knowledge

What a control and its enhancements require, what they mean at a baseline, how related controls differ, which applies.

Evidence advisory

What an assessor will examine, interview and test, which artifact satisfies each, and how the SURRE criteria apply to what you have.

Ask it anything about a control

What does CM-6 require, and what changes at High?

Control knowledge

How is AC-6(9) different from AU-2? Which one covers privileged command logging?

Control knowledge

What evidence will the SCA expect for IR-4, and how would they test it?

Evidence advisory

Is a screenshot of the console enough for SC-8, or do I need the configuration export?

Evidence advisory

What are the mandatory tasks in the Assess step, and who owns them?

RMF process

We just had a significant change. What does Monitor require of us now?

RMF process
One of the starter questions, answered in the product: how CM-6 relates to CM-2 and what evidence satisfies both. Captured from the real AVISSAA page; the answer is written from public NIST text, so there is no customer data in it, synthetic or otherwise.

Where it lives

  • The AVISSAA page

    A conversation, with the control and RMF step you are working on carried as context, and a docx export of the session for the package.

  • Beside the evidence upload

    Inside the ATO workflow, one click asks what to collect for the control in front of you: a short list of artifacts, what each shows, and how it is assessed. The question changes once a verdict shows gaps.

    See the evidence stage
  • With PolicyForge

    Evidence and technical gaps go to AVISSAA for what would close them; policy and procedure gaps go to PolicyForge for the language.

    See PolicyForge

What it will not do

  • It does not read your data

    Advisory by design. Your evidence, documents and system data stay out of it. It tells you what a control requires and what an assessor looks for; judging your artifact against that stays with you and your assessor.

  • It does not invent guidance

    Answers are written from retrieved NIST material and cite it. Where the corpus has nothing, it says so rather than improvising.

  • It does not leave your boundary

    A local model inside your own environment, no external inference calls. Ask about your most sensitive system without the question going anywhere.

Seen in the app

The real thing, on the public NIST corpus

The page as it opens: the RMF step navigator, the control families and eight starter questions across control intent, evidence, RMF process, gap analysis and SURRE. Captured from the real product. Nothing on screen is customer data; the corpus is public NIST material.

Where the boundaries are

  • Does not perform document ingestion, processing, or evaluation of actual system artifacts

  • Integration with eMASS, XACTA, or other GRC platforms is out of scope

  • Uses NIST framework to provide guidelines and requirements that evidence must satisfy.

  • You can always use AVISSAA as a standalone guide.

Straight answers

Does it review my actual documents or system data?

No. It is scoped as an advisory tool by design, so your evidence and system data stay out of it. It tells you what a control requires and what an assessor will look for, and judging your specific artifact against that stays with you.

Where do its answers come from?

A NIST knowledge base ingested into a local vector store, searched per question: SP 800-53 Rev 5, SP 800-53A, SP 800-37 Rev 2 and OSCAL control content. It is instructed to use that retrieved content over its own training knowledge and to cite the publication.

Does my question leave the environment?

No. It runs against a local model inside your own boundary with no external inference calls.

Can I keep the answer?

Yes. A session exports to a Word document, so the reasoning behind an evidence decision can go into the package.

Ask it the question you were about to ask a colleague.

Bring a control you are struggling with to the demo. We will ask AVISSAA in front of you and read the citations together.