Cyber Factory: AI-Driven Automation for RMF Compliance and Accelerated ATO

M. Oberlin, J. Greenberg
SimVentions, Virginia, United States

Keywords: RMF automation, knowledge graph, retrieval-augmented generation, CMMC, Authorization to Operate

Cyber Factory is a suite that pairs automation with AI — knowledge graphs, retrieval-augmented generation, and natural-language processing — to streamline the most labor-intensive parts of DoW Risk Management Framework (RMF) compliance, shortening the path to Authorization to Operate (ATO). At its foundation, a central repository maps STIGs, SRGs, and vendor security guidance to a system's hardware and software components. When a component changes — an OS upgrade, for example — the impact propagates automatically across every dependent mapping and artifact, keeping documentation synchronized with the system. Layered on that foundation, an ontology-driven knowledge graph correlates system and cybersecurity data for continuous risk and compliance analysis, including "what-if" modeling that evaluates a proposed change's security impact before it's made. Users pose these scenarios as plain-language questions through a retrieval-augmented natural-language interface. A built-in Compliance Assistant, pre-loaded with CMMC, NIST, and other frameworks, assesses an environment against a chosen framework's requirements, while a complementary AI checks policy and system documentation against individual controls, citing the passage that satisfies each or flagging a gap. Additional capabilities support vulnerability analysis and POA&M impact writing. Because RMF and NIST 800-53-based requirements span federal and critical infrastructure domains, the approach applies well beyond military systems.