Compliance and Authorization
AVISSAAAvint ISSO Advisory Assistant
The ISSO's conversational guide to every control, every step, every piece of evidence.
Ask what a control requires, what it means at your baseline, what an assessor will expect as proof, and what the mandatory tasks are at each RMF step. Answers come from the NIST corpus and cite the publication. It runs on a local model inside your boundary, and it never reads your data.
What does AC-2(3) require at Moderate, and what will the SCA want to see?
Control knowledgeAC-2(3) requires that accounts be disabled within an organization defined period when they are expired, no longer associated with a user, in violation of policy, or inactive for [organization defined time period]. At Moderate the enhancement is in the baseline. An assessor will examine the account management policy for the period, the disable procedure, and records showing accounts actually disabled within it.
What the assessor will want
- Account review export. Shows inactive accounts identified within the period
- Disable log or ticket sample. Shows the disable action within the period
- Policy excerpt. States the organization defined period
Illustrative answer. Local model, NIST corpus, citations shown.
Built for the job
You know these days.
Your first month as an ISSO
Three hundred controls, a baseline you did not choose, and everyone assuming you already know what AU-6 means in practice. Ask, in your own words, and get the answer with the publication it came from.
The assessor asked for evidence you do not have
Ask what an assessor examines, interviews and tests for the control, what artifact would satisfy each, and whether what you have is sufficient, usable, relevant, reliable and effective.
The ISSE building the control
Ask what the control actually requires at your impact level, how two related controls differ, and which one applies, before you build the wrong thing.
Leadership keeps asking
The questions that used to interrupt your day get a cited answer in seconds, so the ISSO answers them once and the executive stops waiting.
How it answers
Three domains, one corpus, every answer cited
Each question is classified into a domain, the right NIST material is retrieved for it, and the answer is written from that material only. The assistant is instructed never to substitute its own training knowledge for the publication.
01
Route
The question is classified: an RMF process question, a control knowledge question, or an evidence question. The control and the RMF step are picked out of your words, or taken from the page you are on.
Domain, control, step
02
Retrieve
The control's own document, the RMF step's tasks, and the closest passages from the ingested NIST corpus: SP 800-53 Rev 5, SP 800-53A, SP 800-37 Rev 2 and OSCAL control content.
The NIST material
03
Answer
A local model writes the answer from the retrieved material and cites the publication. Evidence questions are answered against the SURRE criteria: sufficient, usable, relevant, reliable, effective.
Cited answer
Local modelThe three domains
RMF process
What the mandatory tasks are at Prepare, Categorize, Select, Implement, Assess, Authorize and Monitor, and what each produces.
Control knowledge
What a control and its enhancements require, what they mean at a baseline, how related controls differ, which applies.
Evidence advisory
What an assessor will examine, interview and test, which artifact satisfies each, and how the SURRE criteria apply to what you have.
Ask it anything about a control
What does CM-6 require, and what changes at High?
Control knowledgeHow is AC-6(9) different from AU-2? Which one covers privileged command logging?
Control knowledgeWhat evidence will the SCA expect for IR-4, and how would they test it?
Evidence advisoryIs a screenshot of the console enough for SC-8, or do I need the configuration export?
Evidence advisoryWhat are the mandatory tasks in the Assess step, and who owns them?
RMF processWe just had a significant change. What does Monitor require of us now?
RMF processWhere it lives
-
The AVISSAA page
A conversation, with the control and RMF step you are working on carried as context, and a docx export of the session for the package.
-
Beside the evidence upload
Inside the ATO workflow, one click asks what to collect for the control in front of you: a short list of artifacts, what each shows, and how it is assessed. The question changes once a verdict shows gaps.
See the evidence stage -
With PolicyForge
Evidence and technical gaps go to AVISSAA for what would close them; policy and procedure gaps go to PolicyForge for the language.
See PolicyForge
What it will not do
-
It does not read your data
Advisory by design. Your evidence, documents and system data stay out of it. It tells you what a control requires and what an assessor looks for; judging your artifact against that stays with you and your assessor.
-
It does not invent guidance
Answers are written from retrieved NIST material and cite it. Where the corpus has nothing, it says so rather than improvising.
-
It does not leave your boundary
A local model inside your own environment, no external inference calls. Ask about your most sensitive system without the question going anywhere.
Seen in the app
The real thing, on the public NIST corpus
Straight answers
Ask it the question you were about to ask a colleague.
Bring a control you are struggling with to the demo. We will ask AVISSAA in front of you and read the citations together.

