00:00:00:00 - 00:00:00:24 Well, Marilyn, 00:00:00:24 - 00:00:02:15 thank you very much for the introduction. 00:00:02:15 - 00:00:03:17 it's a pleasure to be here. 00:00:03:17 - 00:00:04:22 When I reached out to Michaela, 00:00:04:22 - 00:00:06:10 I was very thrilled to hear that 00:00:06:10 - 00:00:07:14 she was willing to take us on 00:00:07:14 - 00:00:09:13 today to present to the community. 00:00:09:13 - 00:00:11:07 And we're really excited to show 00:00:11:07 - 00:00:14:01 you all how using OSCAL to generate real time 00:00:14:01 - 00:00:15:23 compliance insights and drive 00:00:15:23 - 00:00:18:08 continuous authorization with automation 00:00:18:08 - 00:00:21:14 and Agentic AI using the ComplySyncATO platform. 00:00:22:02 - 00:00:24:10 All right, well, I'm going start us off with the agenda 00:00:24:10 - 00:00:26:14 for how we're going to go through this presentation. 00:00:26:14 - 00:00:28:12 We're going to start off with a 15 minute presentation 00:00:28:13 - 00:00:31:02 where we're going to introduce the ComplySyncATO team. 00:00:31:02 - 00:00:35:08 Go through the conception of ComplySyncATO with how we initially created it. 00:00:35:09 - 00:00:40:11 And walk yall through how it facilitates RMF workflows, followed by our cybersecurity 00:00:40:11 - 00:00:42:12 compliance framework that we use ComplySyncATO 00:00:42:12 - 00:00:46:18 to apply for a whole holistic approach end to end compliance workflows. 00:00:46:18 - 00:00:49:22 Once that's completed, we're going to do a live walkthrough of the product, 00:00:49:22 - 00:00:52:14 and we'll conclude with about a 20 minute Q&A session. 00:00:53:11 - 00:00:57:00 So as Marilyn, stated earlier, we're the ComplySyncATO team. 00:00:57:00 - 00:00:58:07 I'd like to introduce myself. 00:00:58:16 - 00:01:01:16 I'm John Kimberl, I'm the business development specialist at ASSYST. 00:01:01:16 - 00:01:03:15 I've been with ASSYST for the past four years, 00:01:03:15 - 00:01:06:16 and I'm leading the go to market campaign for ComplySyncATO 00:01:06:16 - 00:01:08:18 And through that four years, I've really been able 00:01:08:18 - 00:01:12:04 to embrace how engaged ASSYST is with cybersecurity 00:01:12:04 - 00:01:16:05 dating back to the days of die cap, where it controls were in the low hundreds. 00:01:16:05 - 00:01:20:07 And now with NIST, the controls have expanded to over 1500. 00:01:20:13 - 00:01:24:03 And that really drove a need for us to match the pace of compliance 00:01:24:03 - 00:01:27:20 with the speed of business and delivery, leading to the development of ComplySyncATO, 00:01:27:24 - 00:01:30:02 which was led by Vijay. And I'll pass along to Vijay. 00:01:30:13 - 00:01:31:04 Thanks, John. 00:01:31:04 - 00:01:36:22 I'm Vijay Narasimhan with ASSYST over 20+ years supporting various federal agencies. 00:01:37:00 - 00:01:41:13 OPM, SCC, EOC, FDA, Department of War and so forth. 00:01:41:13 - 00:01:47:16 Those challenges, ATO challenges and the solution was the ComplySyncATO with OSCAL 00:01:47:18 - 00:01:48:20 based on AI. 00:01:48:20 - 00:01:50:00 Let me turn it over to Joe 00:01:50:09 - 00:01:53:01 Thank you, Vijay. I'm the COO of ASSYST. 00:01:53:01 - 00:01:56:16 Vijay and I have been working together for the past 25 years. 00:01:56:18 - 00:02:02:04 Just to provide you a quick background on how we got here back in 2019, 00:02:02:04 - 00:02:05:18 around the time when GSA and NIST were establishing the 00:02:05:18 - 00:02:09:18 OSCAL data specification standard, ASSYST with standing up 00:02:09:19 - 00:02:14:09 its green accelerator program, which was essentially built out to provide 00:02:14:09 - 00:02:18:06 innovative solutions to solve specific problems 00:02:18:06 - 00:02:22:07 that we were experiencing within the federal government operating environments. 00:02:22:07 - 00:02:27:16 In 2021, Vijay brought a concept to me which is ComplySyncATO, 00:02:27:16 - 00:02:29:19 which we’ll be demonstrating shortly. 00:02:29:19 - 00:02:33:07 And what was happening is we were experiencing delays in 00:02:33:07 - 00:02:36:10 the ATO process on several of our DevSecOps 00:02:36:10 - 00:02:39:14 modernization contracts within the federal space. 00:02:39:14 - 00:02:42:15 Now, the original charter and white paper that he and I 00:02:42:15 - 00:02:45:18 wrote was principally to equip our teams 00:02:45:18 - 00:02:50:14 with an automated method to expedite ATO processes on the contracts 00:02:50:14 - 00:02:51:20 we were currently supporting. 00:02:51:20 - 00:02:53:04 We knew the solution. 00:02:53:04 - 00:02:57:17 It needed to automate the ATO process in a machine readable way. 00:02:57:17 - 00:03:01:20 The original charter had in it that we needed to use 00:03:01:20 - 00:03:07:01 AI to generate and consume OSCAL compliant artifacts. 00:03:07:01 - 00:03:11:16 We needed to integrate with the CICD pipeline as well as the CMDB, 00:03:11:16 - 00:03:16:14 because we knew that had to be done if we were ever to achieve continuous ATO, 00:03:16:14 - 00:03:19:08 we knew our solution needed to be cloud agnostic 00:03:19:08 - 00:03:23:22 because our customers operate in any one of the major cloud providers. 00:03:23:22 - 00:03:26:24 We also needed our solution to be agnostic 00:03:26:24 - 00:03:30:18 to any of the GRC enterprise level technologies. 00:03:30:18 - 00:03:34:01 And, the first test of the proof of concept at ASSYST. 00:03:34:01 - 00:03:37:21 It happened within the Defense Human Resource Activity, 00:03:37:21 - 00:03:41:00 where we consolidated and modernized seven different applications. 00:03:41:00 - 00:03:43:02 And the reason we chose that first 00:03:43:02 - 00:03:47:06 is because that was the most lengthy ATO process that we were experiencing. 00:03:47:06 - 00:03:51:24 And it took anywhere from 3 to 4 months to get an ATO completed. 00:03:51:24 - 00:03:55:02 And in the initial stages, we were having to go to CISOs 00:03:55:02 - 00:03:57:20 or the CIO to get waivers done. 00:03:57:20 - 00:04:00:21 And there was just too much of sharing screenshots 00:04:00:21 - 00:04:02:16 back and forth through email. 00:04:02:16 - 00:04:05:04 so we brought in our technology 00:04:05:04 - 00:04:09:12 and gave it to our DevSecOps teams, and we were able to reduce that ATO 00:04:09:12 - 00:04:12:20 I think the most recent one, we got completed in three weeks. 00:04:12:20 - 00:04:17:01 Just to give you an idea of the efficiency that this technology can bring 00:04:17:01 - 00:04:18:12 to the federal marketplace. 00:04:18:12 - 00:04:21:01 About five months back, GSA, 00:04:21:03 - 00:04:24:08 FedRAMP 20 X learned about our solution. 00:04:24:09 - 00:04:25:12 And we met with them, 00:04:25:13 - 00:04:27:21 we had several demonstrations with them. 00:04:27:21 - 00:04:30:07 And they said, yeah, we want to look at this further. 00:04:30:07 - 00:04:34:20 And so they started conducting their independent assessment of ComplySync 00:04:34:20 - 00:04:39:20 And six weeks back, GSA, FedRAMP 20 X, they certified our solution. 00:04:39:20 - 00:04:42:16 And now it's listed on the GSA marketplace. 00:04:42:16 - 00:04:47:03 Now in parallel, ServiceNow had learned about it and they contacted us 00:04:47:03 - 00:04:51:17 and they opened up their Sand box to us around the same time frame. 00:04:51:17 - 00:04:55:24 And a week after GSA certified our solution, 00:04:55:24 - 00:05:00:17 ServiceNow then added ComplySyncATO to their marketplace. 00:05:00:19 - 00:05:04:21 and then six weeks later, we're here with Marilyn and Michaela 00:05:04:21 - 00:05:08:14 talking to the OSCAL 44th meeting of the working group. And, 00:05:08:14 - 00:05:10:13 Thank you for that, John. Back to you. 00:05:11:13 - 00:05:13:06 Thank you Joe, for sharing our story. 00:05:13:06 - 00:05:15:05 It really was a long road to get us here. 00:05:15:05 - 00:05:18:22 But, as Joe predicated on, the necessity drives innovation. 00:05:18:24 - 00:05:22:02 I'd like to talk about the challenge that we were coming across. 00:05:22:02 - 00:05:26:01 and really the industry comes across with regards to the ATO bottleneck. 00:05:26:01 - 00:05:28:14 And as you see here, a lot goes in 00:05:28:14 - 00:05:32:10 and little comes out and we noticed that the biggest holdup 00:05:32:10 - 00:05:37:03 was documentation: written text and PDF documents and word documents, 00:05:37:06 - 00:05:40:23 different Excel spreadsheets, static spreadsheets that were getting collected 00:05:40:23 - 00:05:44:05 from point in time rather than continuously being updated. 00:05:44:06 - 00:05:46:09 And there was the gap between delivery. 00:05:46:09 - 00:05:49:09 You get your package ready to deploy, but 00:05:49:09 - 00:05:52:14 then you get slowed down by this cumbersome ATO process. 00:05:52:14 - 00:05:56:13 And with the ISSOs involved ensuring that compliance was met 00:05:56:13 - 00:06:00:13 with each different deployment, you have them chasing around documentation 00:06:00:13 - 00:06:03:21 and performing administration work rather than managing risk, 00:06:03:21 - 00:06:05:22 which is what their job was supposed to be. 00:06:05:22 - 00:06:08:22 And that's really what kind of drove this was that we noticed that 00:06:08:22 - 00:06:12:18 we weren't utilizing ISSOs properly to really facilitate compliance 00:06:12:18 - 00:06:16:12 and risk management activities, rather, they doing more administration work. 00:06:16:12 - 00:06:21:05 and this led to slowdowns in getting systems deployed, FISMA systems 00:06:21:05 - 00:06:25:03 or ATO packages, waivers for federal government customers. 00:06:25:03 - 00:06:27:06 And it just became very complicated. 00:06:27:06 - 00:06:30:11 So we've really had to find a way to adapt with the times. 00:06:30:11 - 00:06:33:16 And that's what led us to OSCAL and how we can use 00:06:33:16 - 00:06:37:10 a portable, interoperable package to instantaneously share 00:06:37:10 - 00:06:41:09 that information across different systems within your security ecosystem. 00:06:41:09 - 00:06:45:16 To facilitate real time compliance, that you can address compliance efficiencies 00:06:45:16 - 00:06:47:01 on the fly, on the go. 00:06:47:01 - 00:06:51:12 And it really lined with the CICD pipeline so that when any compliance deficiency 00:06:51:12 - 00:06:55:07 or gap was identified early, you could address that in the next iteration. 00:06:55:07 - 00:06:58:08 Really marrying compliance with agile practices. 00:06:58:08 - 00:07:00:07 So that's kind of what led us to 00:07:00:07 - 00:07:04:03 addressing this problem and ultimately creating ComplySyncATO 00:07:04:03 - 00:07:07:03 So talking about RMF workflows 00:07:07:03 - 00:07:09:10 and how ComplySyncATO fits in with that, 00:07:09:10 - 00:07:11:11 we wanted to find a way that it was 00:07:11:11 - 00:07:14:03 a facilitator of risk management processes 00:07:14:03 - 00:07:15:13 rather than just replacing it. 00:07:15:13 - 00:07:17:06 So there's a place where in every single 00:07:17:06 - 00:07:19:15 swim lane with regards to conducting 00:07:19:15 - 00:07:21:18 the end to end NIST risk management framework, 00:07:21:18 - 00:07:23:07 you still have the humans in the loop with 00:07:23:11 - 00:07:26:18 preparing and categorizing controls prior to implementing them. 00:07:26:18 - 00:07:27:19 That's always going to be there. 00:07:27:19 - 00:07:30:11 But then ComplySyncATO can then select the controls 00:07:30:11 - 00:07:33:00 and map it to the proper controls that is 00:07:33:00 - 00:07:34:08 dictated within your implementation 00:07:34:08 - 00:07:35:14 statements to NIST, 00:07:35:14 - 00:07:38:09 which saves a significant amount of time. 00:07:38:09 - 00:07:41:21 Then, with the AI analysis, we can automatically notify 00:07:41:21 - 00:07:44:01 whether or not it's been satisfied or not, 00:07:44:01 - 00:07:44:21 whether or not it's been 00:07:44:21 - 00:07:46:11 effectively implemented 00:07:46:11 - 00:07:49:10 automatically flagging a baseline for these controls. 00:07:49:10 - 00:07:51:06 And that really comes from OSCAL. 00:07:51:06 - 00:07:53:23 That way we can connect ConMon operations 00:07:53:23 - 00:07:56:03 with compliance operations to flag 00:07:56:03 - 00:07:58:09 whether or not controls have been implemented or not. 00:07:58:09 - 00:07:59:19 We're collecting live telemetry 00:07:59:19 - 00:08:02:19 from security stacks, using that to notify 00:08:02:19 - 00:08:06:14 whether or not we are meeting those compliance measures as dictated by NIST. 00:08:06:19 - 00:08:07:15 Assessing too. 00:08:07:15 - 00:08:10:16 ComplySyncATO helps with the assessors and stakeholders 00:08:10:16 - 00:08:12:11 really assess the compliance health 00:08:12:11 - 00:08:13:21 of their FISMA systems 00:08:13:21 - 00:08:14:24 within their environment. 00:08:14:24 - 00:08:16:10 Using that OSCAL data, 00:08:16:10 - 00:08:18:09 they can slice and dice the data 00:08:18:09 - 00:08:20:03 into really reflect key indicators 00:08:20:03 - 00:08:21:21 that they're really trying to focus on. 00:08:21:21 - 00:08:24:08 That way, we can hone in on the points 00:08:24:08 - 00:08:25:14 that need to be addressed, 00:08:25:14 - 00:08:28:24 rather than sorting through a bunch of different documents, SSPs 00:08:28:24 - 00:08:33:09 and Excel spreadsheets, ultimately too we want to authorize the system. 00:08:33:09 - 00:08:36:11 So ComplySyncATO when it creates this machine readable packages. 00:08:36:11 - 00:08:38:16 And this is really where FedRAMP 20 X comes in. 00:08:38:16 - 00:08:40:10 We can submit it directly to FedRAMP. 00:08:40:10 - 00:08:43:03 they can continuously authorize the system rather than need to 00:08:43:03 - 00:08:46:16 wait out this 18 month process and then give you an ATO, 00:08:46:16 - 00:08:48:04 if you are in fact, compliant. 00:08:48:04 - 00:08:49:11 Then lastly with monitoring again, 00:08:49:11 - 00:08:52:00 going back to ConMon operations, 00:08:52:00 - 00:08:54:11 ComplySyncATO leverages that OSCAL data feeds 00:08:54:11 - 00:08:56:23 that come from your vulnerability scanners 00:08:56:23 - 00:08:59:17 using live evidence and live scan results 00:08:59:17 - 00:09:01:16 to flag baseline drifts. 00:09:01:16 - 00:09:04:08 Identify the controls are operating as said 00:09:04:08 - 00:09:08:04 within your implementation statements, so that you can continuously address 00:09:08:04 - 00:09:11:10 any compliance deficiencies as they arise, rather than wait 00:09:11:10 - 00:09:14:00 until after the fact weeks of not months later, 00:09:14:00 - 00:09:15:23 and then try to scramble everything up together. 00:09:15:23 - 00:09:20:20 So this really brings together the holistic approach towards continuous ATO. 00:09:20:22 - 00:09:22:11 I'll go on to the next slide. 00:09:22:11 - 00:09:24:07 When we talk about ComplySyncATO 00:09:24:07 - 00:09:26:09 and how it facilitates the compliance framework. 00:09:26:09 - 00:09:29:08 it integrates into an assortment of different 00:09:29:08 - 00:09:31:17 systems within your security ecosystem. 00:09:31:20 - 00:09:34:17 that also includes systems the delivery side. 00:09:34:17 - 00:09:36:17 So it can be your JIRA platform service. 00:09:36:17 - 00:09:39:12 ServiceNow, any vulnerability scanners, 00:09:39:12 - 00:09:42:18 LMS training platforms, your DevOps pipelines, 00:09:42:20 - 00:09:44:20 that really comes from using OSCAL 00:09:44:20 - 00:09:46:10 the fact that we're able to collect 00:09:46:10 - 00:09:48:14 all that information in the OSCAL format 00:09:48:14 - 00:09:50:17 really keeps us agnostic. 00:09:50:17 - 00:09:54:15 with any system out there that can collect live telemetry 00:09:54:15 - 00:09:58:02 or use that data to facilitate any workflows, 00:09:58:08 - 00:10:02:08 creating PoAMs or addressing vulnerability compliance drifts. 00:10:02:08 - 00:10:06:03 So that is where we really wanted to use OSCAL to make 00:10:06:03 - 00:10:10:00 us not a system that is needed for one other platform 00:10:10:00 - 00:10:13:23 or one environment, and our customers wouldn't need address or 00:10:13:23 - 00:10:16:09 Evolve with the platform and adapt with it. 00:10:16:09 - 00:10:19:17 So that's really where OSCAL kind of came into play with our platform. 00:10:19:17 - 00:10:21:16 So that allowed us to be more agnostic. 00:10:21:16 - 00:10:24:13 And on that note, I'm gonna send us into the live demo. 00:10:24:13 - 00:10:26:07 Is everyone able to see my screen? 00:10:26:07 - 00:10:27:11 Yes. Fantastic. 00:10:27:11 - 00:10:30:14 So as you see here we have the trust center. 00:10:30:14 - 00:10:32:18 This is ComplySyncATO’s home page. 00:10:32:18 - 00:10:38:00 And it gives you access to all of ComplySync’s modules, capabilities and features 00:10:38:00 - 00:10:41:05 to facilitate the compliance process and accelerate your ATO. 00:10:41:05 - 00:10:44:23 I'm going to take us into the meat and potatoes of the compliance frameworks. 00:10:44:23 - 00:10:48:13 And this is where a lot of the magic happens for ISSOs 00:10:48:13 - 00:10:53:12 and delivery teams to ensure that controls are in fact in compliance with NIST. 00:10:53:12 - 00:10:56:09 So as you see here, we have an organization 00:10:56:09 - 00:10:59:00 and I'll show us ASSYST for this one. 00:10:59:00 - 00:11:02:01 And I'm going demonstrate how we can upload 00:11:02:01 - 00:11:05:18 an authorization package using an OSCAL formatted package. 00:11:05:18 - 00:11:11:05 So here I'm going to go ahead and I'm going to show an OSCAL formatted SSP. 00:11:11:18 - 00:11:15:08 As you see here we have the SSP for Acme system security plan. 00:11:15:08 - 00:11:19:13 And just so I can demonstrate I'm going to find a control. 00:11:20:07 - 00:11:21:19 We're going to go to AC-3. 00:11:23:21 - 00:11:24:19 And here we have the 00:11:24:19 - 00:11:29:00 implementation statement that was written in our SSP for this control right here. 00:11:29:00 - 00:11:31:22 Now I'm going to go ahead I'm going to minimize this. 00:11:31:22 - 00:11:33:22 And I'm going to create the package name. 00:11:35:22 - 00:11:37:08 Now this can be based off 00:11:37:08 - 00:11:40:20 of whichever version of NIST SP 800-53 you're using. 00:11:40:20 - 00:11:42:15 We can do Rev-5 or Rev-4 00:11:42:15 - 00:11:45:09 Organizations that aren't at Rev-5 yet, they can do Rev-4 00:11:45:09 - 00:11:49:12 and whichever baseline controls you’re applying here, low, moderate or high. 00:11:49:12 - 00:11:51:17 For the sake of this demo we'll do a moderate. 00:11:51:17 - 00:11:52:19 And I'm going to go ahead. 00:11:52:19 - 00:11:54:22 I'm going to import that JSON file. 00:11:58:06 - 00:11:59:08 Import the package. 00:12:00:21 - 00:12:01:10 Fantastic. 00:12:01:16 - 00:12:05:17 And now you see we have Acme systems SSP uploaded with all seated 00:12:05:17 - 00:12:08:07 NIST family controls listed down here on the catalog. 00:12:08:09 - 00:12:13:13 I'm going to go to that same control that I highlighted on the OSCAL SSP. 00:12:13:17 - 00:12:15:11 as you see here, access enforcement. 00:12:15:11 - 00:12:17:17 And the implementation statement is written 00:12:17:17 - 00:12:20:24 in here as it was written on the OSCAL formatted SSP. 00:12:21:13 - 00:12:24:23 And I'm going to highlight here So the implementation status is flagged 00:12:24:23 - 00:12:28:12 as implemented, that we have it in fact implemented into our system environment. 00:12:28:14 - 00:12:32:16 I'm going to go back to that later though, and we're going to use the AI analysis 00:12:32:16 - 00:12:36:18 to analyze this information and give us a notification on whether or not 00:12:36:18 - 00:12:38:22 the control has in fact met compliance. 00:12:38:22 - 00:12:42:11 as you see here, it's been partially implemented with justifications for why it’s 00:12:42:11 - 00:12:46:17 partially implemented and action items for how to meet compliance with NIST. 00:12:46:17 - 00:12:50:17 This is very key too for anyone needs to read through complex 00:12:50:17 - 00:12:53:15 technical documents, rather than needing to map out 00:12:53:15 - 00:12:57:09 all the complex technical content that's written on SSP with 00:12:57:09 - 00:13:00:13 what’s written in NIST to validate that the control has in fact passed. 00:13:00:13 - 00:13:03:19 You simply have the AI run, and that allows the ISSOs 00:13:03:19 - 00:13:07:20 to act more as risk facilitators rather than document analyzers. 00:13:07:20 - 00:13:12:20 So for the sake of time of this demo, I'm going to go to ComplySyncATO 00:13:12:20 - 00:13:16:04 to a different package we've already uploaded that has our automation scripts 00:13:16:04 - 00:13:21:08 already written in it and I'm going to pick that same control for AC-3. 00:13:21:08 - 00:13:24:13 I'm going to show you how collect, OSCAL formatted telemetry 00:13:25:01 - 00:13:26:14 using automation scripts. 00:13:26:14 - 00:13:28:07 I'm going to go ahead and I'm going to run this. 00:13:30:24 - 00:13:33:21 And integrates directly with your security stack to collect 00:13:33:21 - 00:13:36:01 that evidence that will reflect whether or not 00:13:36:01 - 00:13:39:11 the implementations whether or not the control is operating as set 00:13:39:11 - 00:13:42:12 within the implementation statement while that runs. 00:13:43:22 - 00:13:45:06 Bear with me for a second. 00:13:48:07 - 00:13:49:15 While that runs too I'm going to 00:13:49:15 - 00:13:50:07 Oh here we go 00:13:51:22 - 00:13:56:14 So as you see here, we have the output of the evidence scan in a machine readable 00:13:56:14 - 00:14:00:21 format that will forwarded to your file repository that stores all of your evidence. 00:14:00:21 - 00:14:04:24 And we can also get in a human readable format the result of the scan. 00:14:04:24 - 00:14:07:24 And as you see here, the validation results have passed. 00:14:09:12 - 00:14:11:02 Not all of them as you see here. 00:14:11:02 - 00:14:14:02 It will also provide information as to why it actually failed. 00:14:14:03 - 00:14:17:06 We see here we must force a change password control. 00:14:17:15 - 00:14:19:18 But all this information is then going to be stored 00:14:19:18 - 00:14:21:08 within your evidence repository. 00:14:21:08 - 00:14:22:10 Exit out of this. 00:14:22:23 - 00:14:25:09 Now we’ve gone about and collected that evidence 00:14:25:24 - 00:14:28:18 that can be reflected on our SSP package, that we can 00:14:28:18 - 00:14:33:16 then share to FedRAMP in live time to reflect the status of our controls. 00:14:33:19 - 00:14:37:09 I'm going to go ahead and I'm going to export that SSP on a JSON file. 00:14:37:15 - 00:14:39:03 And we'll go down here. 00:14:43:09 - 00:14:44:16 Here we go. 00:14:44:16 - 00:14:45:14 Fantastic. 00:14:45:14 - 00:14:49:09 As you see here, we have the status of the implementation statement 00:14:49:12 - 00:14:52:13 that has been implemented, the implementation statement itself 00:14:52:13 - 00:14:55:20 and the AI analysis written down on that SSP 00:14:55:20 - 00:14:58:20 to kind of reflect how you are analyzing your controls. 00:14:58:20 - 00:15:01:12 And that can be shared with your GRC platform. 00:15:01:12 - 00:15:04:03 can be shared with FedRAMP and it can be shared across 00:15:04:03 - 00:15:07:01 different security environments just by downloading this package. 00:15:08:01 - 00:15:11:10 So let's say you're an organization that 00:15:11:10 - 00:15:15:00 isn't ready for machine readable yet, or you haven't made shift yet. 00:15:15:10 - 00:15:18:04 So I like to go down here and like to highlight another control. 00:15:18:04 - 00:15:20:17 So we're going focus on flaw remediation. 00:15:20:17 - 00:15:23:03 And as we see here been fully implemented. 00:15:23:03 - 00:15:25:00 And we have the implementation status. 00:15:25:00 - 00:15:26:04 Flaws and vulnerabilities 00:15:26:04 - 00:15:31:07 are systematically discovered by using Nessus and OpenVAS, and NodeZero 00:15:31:07 - 00:15:32:13 I'm going to show you how we're going 00:15:32:13 - 00:15:36:07 transform a word document into an OSCAL format at SSP. 00:15:36:07 - 00:15:38:14 And I'm going to go back to SI-2 00:15:39:05 - 00:15:41:03 And here we Nessus scan right here. 00:15:43:10 - 00:15:43:20 Go ahead. 00:15:43:20 - 00:15:46:04 And I'm going to change this to an OWASP-ZAP 00:15:46:17 - 00:15:47:11 I’m gonna save it. 00:15:48:16 - 00:15:49:14 Let that save. 00:15:50:06 - 00:15:54:10 And I’m going to go back to the ComplySyncATO package. 00:15:54:10 - 00:15:56:00 And I'm just going to import the word document. 00:15:56:18 - 00:16:00:24 And this is going to demonstrate how we're using AI to transform 00:16:00:24 - 00:16:05:13 traditional Word based SSPs into an OSCAL format to really expedite 00:16:05:13 - 00:16:09:11 this shift towards machine readable for system owners and organizations. 00:16:09:11 - 00:16:12:20 So as you see here, it's identified a bunch of controls that have been updated 00:16:12:20 - 00:16:16:18 within the SSP that will be reflected on ComplySyncATO 00:16:17:01 - 00:16:19:21 Now I'm going to go back down to ComplySyncATO 00:16:19:21 - 00:16:21:17 And I'm going to pick out that same control. 00:16:22:19 - 00:16:23:20 And there we see the change. 00:16:23:20 - 00:16:26:08 We change it from Nessus to OWASP-ZAP 00:16:26:08 - 00:16:30:12 Again, this is how we're using AI to push the change from traditional 00:16:30:12 - 00:16:35:10 static documents to a more dynamic, continuous, machine readable format. 00:16:35:10 - 00:16:36:16 Now that's fantastic. 00:16:36:16 - 00:16:38:05 We got the data in there, 00:16:38:05 - 00:16:41:20 analyzing it, and we're ensuring that the controls are in alignment with NIST. 00:16:41:20 - 00:16:44:05 What do we do with that data though from a program level? 00:16:44:05 - 00:16:46:24 A lot of times people want to strategize and plan 00:16:46:24 - 00:16:50:01 how they're going to meet compliance with these controls and standards. 00:16:50:01 - 00:16:52:09 So that's where the integration hub comes in 00:16:52:09 - 00:16:55:09 All that live telemetry is being stored within the integration 00:16:55:10 - 00:16:57:19 hub for each business system within your environment. 00:16:57:19 - 00:17:01:10 And it's stored within your GitHub repository in that OSCAL format. 00:17:01:12 - 00:17:05:14 And that way we can kind of slide and dice the data to reflect key indicators 00:17:05:14 - 00:17:07:14 for FISMA systems within your environment. 00:17:07:14 - 00:17:11:11 as you see here we have the Compliance Insights dashboard that reflects all key 00:17:11:11 - 00:17:14:15 indicators for your physical systems across the board. 00:17:14:15 - 00:17:16:15 And it's based off of each family control. 00:17:16:15 - 00:17:17:18 And it reflects things 00:17:17:18 - 00:17:19:22 such as whether or not the control has been implemented, 00:17:19:22 - 00:17:22:00 partially implemented, not implemented at all, 00:17:22:00 - 00:17:25:19 or isn't applicable to your operations, along with whether or not the documentation 00:17:25:19 - 00:17:26:19 has been collected. 00:17:26:19 - 00:17:30:03 And we also provide insights into the packages, the implementation 00:17:30:03 - 00:17:33:05 coverage compliance gaps, which is key for system owners 00:17:33:11 - 00:17:36:20 need to meet timelines and need to address these compliance deficiencies in time 00:17:37:02 - 00:17:40:21 along with the coverage of implementation, how much assessments has been conducted, 00:17:40:21 - 00:17:41:15 and controls. 00:17:42:16 - 00:17:43:23 Also authorization data. 00:17:44:05 - 00:17:46:09 I'm going to go to ComplySyncATO on this one. 00:17:46:09 - 00:17:48:20 I'm going to highlight this right now. And we'll get back to it later. 00:17:48:20 - 00:17:52:10 with the implementation status we have a 53% implementation status 00:17:52:11 - 00:17:53:18 That is how many of the controls 00:17:53:18 - 00:17:56:04 we need to meet compliance have have been implemented 00:17:56:04 - 00:17:57:07 along with the coverage, 00:17:57:07 - 00:18:01:06 the assessment pass rate, assessment coverage to amount controls and gaps. 00:18:01:09 - 00:18:03:09 again, we have it broken down by each family. 00:18:03:24 - 00:18:07:17 You can also monitor authorization trends based off of the consistency 00:18:07:17 - 00:18:10:24 of your assessments how consistent is your implementation. 00:18:10:24 - 00:18:14:13 And this is great to for organizations that are trying to adopt AI, 00:18:14:14 - 00:18:18:09 but need to obtain some more confidence in it, that way you can kind of track, how 00:18:18:09 - 00:18:19:06 well is this running? 00:18:19:06 - 00:18:20:00 Is it there yet? 00:18:20:00 - 00:18:23:00 To the point that we're ready to let AI manage the analysis 00:18:23:00 - 00:18:26:16 of our controls, use automation to continuously scan the telemetry 00:18:26:16 - 00:18:30:13 feeds, really break down that barrier reviewing static documentation. 00:18:30:13 - 00:18:32:23 So this is a key aspect for organizations that 00:18:32:23 - 00:18:35:08 want to gain confidence in the use of their AI. 00:18:36:06 - 00:18:39:13 Now I also talked about how ComplySyncATO can kind of brings a holistic 00:18:39:13 - 00:18:44:10 approach towards engaging with security operations standards and ConMon operations. 00:18:44:10 - 00:18:48:14 So with the risk and compliance operations module, we're using OSCAL to collect 00:18:48:16 - 00:18:52:22 live vulnerability scan data in that OSCAL format and reflect it 00:18:52:22 - 00:18:54:08 on the vulnerability dashboard. 00:18:54:08 - 00:18:59:02 So I'm going to go ahead here and I'm going to show us a vulnerability scan. 00:18:59:02 - 00:19:03:15 And this provides insights into detections within the security ecosystem 00:19:03:15 - 00:19:04:17 based off of each control. 00:19:04:17 - 00:19:09:01 So I'm going to highlight SI-2 that flaw remediation control. 00:19:09:05 - 00:19:13:07 as you see here we have vulnerabilities detected with that flaw remediation. 00:19:13:10 - 00:19:15:23 I'm going to go back to this later because that was a control 00:19:15:23 - 00:19:18:14 that was implemented when we looked in the compliance frameworks. 00:19:19:11 - 00:19:21:20 we're going to process that OSCAL package. 00:19:25:13 - 00:19:25:23 And here. 00:19:25:23 - 00:19:30:09 All those vulnerabilities that were detected using your scanners has been reported here 00:19:30:09 - 00:19:34:04 on the vulnerability dashboard that allows you to facilitate this 00:19:34:04 - 00:19:37:08 vulnerability information across different security tools, 00:19:37:08 - 00:19:40:15 GRC platforms and within ComplySyncATO as well too 00:19:40:23 - 00:19:43:11 This kind of automates brings together that whole loop 00:19:43:11 - 00:19:46:23 of security operations with risk management operations. 00:19:47:01 - 00:19:48:13 now we have that data in here. 00:19:48:13 - 00:19:51:17 I'm just going to pick up we have SI-2 vulnerabilities detected 00:19:51:20 - 00:19:55:15 along with the description, the severity level of it and the CVE 00:19:55:16 - 00:19:57:00 that's associated with it 00:19:57:14 - 00:19:59:20 Now we're going to go back to our compliance frameworks. 00:19:59:23 - 00:20:03:02 And this is how we automate this baseline drift workflow. 00:20:03:04 - 00:20:05:20 And we're going to go back to flaw remediation. 00:20:07:18 - 00:20:08:05 There. 00:20:08:05 - 00:20:10:15 The implementation status has not been implemented now. 00:20:10:15 - 00:20:14:12 because we use the automation to detect that vulnerability. 00:20:14:12 - 00:20:16:14 We're going to flag that within the compliance framework 00:20:16:14 - 00:20:18:21 so that the ISSO knows. this has not been implemented. 00:20:18:21 - 00:20:19:19 We need to address this. 00:20:19:19 - 00:20:22:20 And that provides feedback directly to the delivery team so that they can 00:20:22:21 - 00:20:26:05 in fact address that deficiency within your compliance frameworks. 00:20:26:08 - 00:20:29:23 it's also reflected right here too as we pass on the first examination. 00:20:29:23 - 00:20:34:05 This one has failed and it's auto flipped due to the vulnerability being detected. 00:20:34:05 - 00:20:37:05 So it kind of goes beyond just checking the scanners and making sure 00:20:37:11 - 00:20:40:10 the lights are working. No, we're also bringing in vulnerability data 00:20:40:10 - 00:20:43:21 to see if there is a vulnerability with that associated control. 00:20:44:11 - 00:20:48:03 And this can also be viewed from a high level executive side as well. 00:20:48:03 - 00:20:51:09 That will also reflected on your authorization data dashboard. 00:20:51:09 - 00:20:54:03 So as you see here the implementation status has dropped. 00:20:54:03 - 00:20:56:24 That control is not being recognized as being implemented anymore. 00:20:56:24 - 00:21:00:22 That way, as a program manager, a CISO, CIO or system owner, 00:21:00:22 - 00:21:03:00 You don't have to read the vulnerability reports anymore 00:21:03:00 - 00:21:04:10 to notice that there's vulnerabilities 00:21:04:12 - 00:21:06:00 within your system, and that the implications 00:21:06:00 - 00:21:06:21 need to be addressed. 00:21:06:21 - 00:21:08:24 This way you just need to know that your implementation 00:21:08:24 - 00:21:10:15 status is not being met as needed. 00:21:10:15 - 00:21:11:24 So that's kind of how we're bringing 00:21:11:24 - 00:21:15:12 OSCAL data to facilitate and bring together the whole aspect of 00:21:15:12 - 00:21:18:20 managing and maintaining risk across the board with ComplySyncATO. 00:21:19:17 - 00:21:22:22 Lastly, I’d like to go through our settings and documentation 00:21:22:22 - 00:21:27:04 and just show how we're machine readable formats from NIST to continuously update 00:21:27:04 - 00:21:30:01 the frameworks that come out of the box with ComplySyncATO, 00:21:30:01 - 00:21:34:12 We integrate directly with NIST GitHub using the most latest version of NIST seated schema. 00:21:35:00 - 00:21:38:03 As you see here, we're fetching live data from NIST GitHub 00:21:38:05 - 00:21:41:01 to continuously update that schema we'd be using. 00:21:41:01 - 00:21:43:23 This way ComplySyncATO ingest the schema from NIST, 00:21:43:23 - 00:21:47:19 so that each family controls and seeded controls will automatically map 00:21:47:19 - 00:21:50:15 with the controls that are listed within your implementation statement. 00:21:50:15 - 00:21:52:18 And that can be done for Rev-4 as well. 00:21:52:18 - 00:21:57:08 Rev-5 we do with FedRAMP 20 X and CMMC level two. 00:21:58:21 - 00:22:01:14 Lastly, I'll just go through this, the automation center. 00:22:01:14 - 00:22:03:23 This allows you to kind of configure automation scripts 00:22:03:23 - 00:22:07:19 so that you can schedule how frequently you want your telemetry feeds to be fed 00:22:08:00 - 00:22:09:15 using the evidence scanning capability 00:22:09:15 - 00:22:12:02 with the system you wanted to collect data from, 00:22:12:02 - 00:22:15:05 and then that evidence eventually stored within the evidence repository. 00:22:16:15 - 00:22:18:24 And on that note, I'm going to go ahead. 00:22:20:00 - 00:22:21:21 And I'll open the door up for any questions.