ARIA — RMF Automation
Sentinel AI  /  Solutions & Products / ARIA
Solutions & Products // Module

ARIA RMF Automation

Automated RMF Intelligence Architecture — the Sentinel AI module that automates the DoD Risk Management Framework end to end, from categorization to continuous monitoring, so Authorizing Officials decide faster, on better evidence, with every decision still in human hands.

Results

Measured on Real Authorizations

87 → 27
Avg. days for Step 4 assessment
312 → 64
SCAR analyst hours per system
~89%
Less eMASS data entry
26 → 1
Avg. days to collect artifacts

Source: Puyenpa operational records, n=14 systems across DoD and Federal engagements, 2021–2025. Manual baseline vs. full automation. Results vary by system and environment.

Built on Sentinel’s Nine Hardened LayersDecision Authority
On the Control Plane

Built on Sentinel’s Nine Hardened Layers

ARIA runs as a governed workload on the Sentinel AI Control Plane. Every model is registered and versioned, every artifact carries lineage, and every AI recommendation — and every human override — is logged for audit.

Overview

Authorize at the Speed of the Mission

Authorization boundaries are growing faster than assessment teams can absorb. ARIA takes on the highest-volume RMF work — evidence collection, checklist reconciliation, eMASS entry, POA&M upkeep — and returns assessor time to judgment.

01

Control Template Engine

720 baseline controls pre-mapped to implementation statements, test objectives and expected artifacts, with inheritance, overlays and Rev 4 → Rev 5 migration.

02

Multi-Scanner Intelligence

One normalized view across Evaluate-STIG, OpenSCAP / Red Hat Satellite and DISA SCC, with AI-maintained Answer Files that shrink the manual-check backlog every quarter.

03

AI Assessment Engine

IBM watsonx-powered artifact analysis, control satisfaction scoring with cited evidence, CAT I/II/III classification and SCAR-ready narratives.

04

Human Decision Authority

Decision support, never decision making. Assessors validate every score and the AO alone accepts risk — enforced in the platform and logged for audit.

Lifecycle

Every RMF Step, Automated

  1. Step 0PrepareRole mapping, inventory sync, pre-populated SSP templates
  2. Step 1CategorizeFIPS 199 / CNSSI 1253 impact suggestions, boundary diagrams
  3. Step 2SelectBaseline selection, tailoring, overlays, inheritance mapping
  4. Step 3ImplementSSP generation, STIG evidence collection, CI/CD security gates
  5. Step 4AssessParallel AI artifact analysis, finding classification, SCAR output
  6. Step 5AuthorizeRisk posture dashboard, draft risk narrative, AO decision package
  7. Step 6MonitorContinuous scan feeds, drift alerts, live POA&M tracking
STIG & Vulnerability Automation

Scan. Harden. Prove.

ARIA works with the scanners and automation already on your network — no forklift replacement — and turns every remediation into authorization evidence.

01

Ingest

Evaluate-STIG checklists, OpenSCAP results from Red Hat Satellite, DISA SCC XCCDF and Nessus output, linked to one system record.

02

Resolve

Normalization across tools, format bridging for STIG Viewer and STIG Manager, and Answer File intelligence for recurring manual checks.

03

Remediate

DISA Cyber.mil Ansible and Chef playbooks matched to each finding, executed through Satellite, Ansible or device APIs behind approval gates.

04

Prove

Remediation evidence attached automatically, POA&M closure queued for ISSO confirmation, and eMASS-ready packages.

Roadmap

ACAS / Tenable Security Center connector and IAVA lifecycle tracking under DoDI 8531.01; STIG Manager and C-PAT API integration.

Decision Authority

The AI Recommends. People Decide.

DecisionARIAHuman Authority
Control satisfactionScores Pass / Partial / Fail with confidence and cited evidenceSCA validates or overrides
Finding severityProposes CAT I / II / III classificationSCA confirms; CAT I requires written sign-off
RemediationMatches playbooks and stages executionApproval gate before any change; ISSO confirms POA&M closure
AuthorizationAssembles the decision package and draft risk narrativeAO decides and signs — non-delegable
Review Console

Built-In ISSO/ISSM Approval

Every AI-drafted POA&M is reviewed and approved by a named person before it reaches C-PAT or eMASS — never auto-published. Locked scanner data sits beside editable narrative fields, and approval seals a cryptographic fingerprint of the exact content that was approved.

Sentinel AI POA&M review console showing the review queue, locked ACAS fields, and reviewer-editable narrative
Review queue — locked scanner data beside reviewer-editable fields
Approval dialog showing the content fingerprint and attestation before publishing to C-PAT and eMASS
Approval seal — content fingerprint, attestation, and full history
Standards & Status

Where ARIA Stands

Standards We Hold
DoDI 8510.01 — DoD Risk Management Framework
NIST SP 800-53 Rev 5 and SP 800-53A
CNSSI 1253 categorization and overlays
FIPS 140-3 validated cryptography
DoDI 5200.44 supply chain risk management, CycloneDX SBOM
Authorization Status
DoD IL4 — IATT active
IL5 — on-premises deployment, authorized by customer AO
SIPRNet — deployment subject to customer IATT
Government data remains Government property; models trained on it are Government-owned
Technology Partners

Built With

01

IBM

watsonx and watsonx Orchestrate for AI analysis, search and agent orchestration; QRadar for continuous monitoring telemetry.

02

Dragos

ICS/OT asset visibility and NIST SP 800-82 mapping, so OT and kinetic systems move through the same RMF workflow as IT.