Artificial intelligence systems and methods for cybersecurity compliance
An AI-based system using LLMs and IaC automates cybersecurity compliance assessment and enforcement, addressing scalability and compliance challenges in IT systems, enhancing security and efficiency.
Patent Information
- Application Number
- PCT/US2025/044331
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-29
- Filing Date
- 2025-08-29
- Publication Date
- 2026-03-05
AI Technical Summary
Existing IT systems face challenges in diagnosing and addressing performance and security issues, particularly in live environments, due to inadequate documentation, human error, and the complexity of scaling and maintaining compliance with cybersecurity standards, which is burdensome for small-medium manufacturers (SMMs) lacking resources and expertise.
An AI-based system utilizing Large Language Models (LLMs) and Infrastructure as Code (IaC) to automatically assess and enforce cybersecurity compliance, providing real-time compliance insights, visualizations, and reports, while ensuring consistent and reproducible system configurations.
The system reduces the burden of manual compliance management, enhances security posture, and ensures ongoing adherence to regulatory standards by automating compliance tasks and reducing human error, making it scalable and adaptable to evolving frameworks.
Smart Images

Figure US2025044331_05032026_PF_FP_ABST
Abstract
Description
[0001]PCT Patent Application Attorney Docket Number: 61732-249613 Artificial Intelligence Systems and Methods for Cybersecurity Compliance Cross-Reference and Priority Claim to Related Patent Application: This patent application claims priority to U.S. provisional patent application serial no. 63 / 688,760, filed August 29, 2024, and entitled “Artificial Intelligence Systems and Methods for Cybersecurity Compliance”, the entire disclosure of which is incorporated herein by reference. Introduction: Demands, uses and needs for computing have skyrocketed over the last several decades. Along with this increase, demands for greater storage, speed, computing capability, applications, and accessibility have resulted in a rapidly changing field of computing, with tools being provided to entities of a variety of types and sizes. As a result, public virtual computing and cloud computing systems have been developed to provide greater computing resources for a multitude of users and types of users. This exponential growth is expected to continue. At the same time, greater failure and security risks have made infrastructure set-up, management, change management, and updating more complicated and costly. Scalability, or growing a system over the course of time, has become a major challenge in the field of information technology as well. Problems in most IT systems may be difficult to diagnose and address, particularly problems relating to performance and security. Constraints on time and resources required to set up, configure and deploy a system may lead to errors and result in future IT problems. Over time, a number of different administrators may be involved in changing, patching or updating IT systems. These changes can include users, applications, services, security, software and hardware. Often documentation and history of configuration and changes may be inadequate or get lost, making it difficult to understand at a later time how a particular system has been configured and works. This may make future changes or troubleshooting difficult. IT configurations and settings may be difficult to recover and reproduce when problems or failures arise. In addition, system administrators can easily make mistakes. Examples may include incorrect commands or other mistakes, which in turn may bring down computer and web databases and services. Furthermore, while increased risks of security breaches are commonplace, changes, updates, and patches to avoid the security breaches may cause undesirable downtime. Once the critical infrastructure is in place, working, and live, the cost or risk often may seem to outweigh the benefit of changing the system. The problems involved in making changes to live IT systems or environments can create substantial and at times catastrophic problems for users or entities that rely on these systems. At the very least, the amount of time it takes to troubleshoot and fix failures or problems occurring during change management may require substantial resources of time, personnel and money. The technical problems potentially created when changes are made to live environments can have cascading effects and may not be solved solely by undoing the changes made. Many of these issues contribute to the inability to expeditiously rebuild a system if there are failures during the change management. Furthermore, a bare metal cloud node or bare metal resource within an IT system may be vulnerable to security issues, compromised, or accessed by a rogue user. A hacker, attacker or rogue user may pivot off of that node or resource to access or hack into other portions of the IT system or networks coupled to the node. A bare metal cloud node or a controller of an IT system may also be vulnerable through a resource connected to an applications network that may expose the system to security threats or otherwise compromise the system. According to various examples disclosed herein, an IT system may be configured to improve security in bare metal cloud nodes or resources interfacing the internet or from application networks whether or not the nodes are connected to an external network. For example, large consortia, organizations, non-profits, and other firms or agencies including but not limited to local, state, federal, or other government entities or affiliates have enacted policies and frameworks designed to protect their digital footprint and data of various levels of sensitivity. This includes but is not limited to domestic design data, foreign design data, and other types of sensitive data shared between them and private entities. For example, the Defense Industrial Base (DIB) has struggled with declining Small-Medium Manufacturer (SMM) participation year over year. This is despite multiple external efforts in designing and releasing increasingly condensed Cybersecurity Frameworks (CSFs) which have simplified the requirements and processes needed to be put into place to protect sensitive data. A key issue with respect to the DIB, as well as Financial, Healthcare, and other regulated industries, is the need for a capability to maintain confidentiality. In the DIB, this may include schematics containing sensitive classified designs and information known as Controlled Unclassified Information (CUI). A significant fraction of the over 100,000 businesses in Defense Industrial Base (DIB) comprises SMMs, and as these types of businesses are the engines of job creation and innovation in such agencies has a vested interest in continuing to support and patronize these small businesses. However, the interagency concerns over sensitive data have led to regulations mandating all businesses implement a tiered, cumulative baseline of cybersecurity according to the sensitivity of the data they handle. For example, after the Cybersecurity Maturity Model Certification (CMMC) program is enacted, all contractors and subcontractors handling CUI, including any systems which interact with assets possessing, transmitting, or storing CUI, must first receive a Cybersecurity Maturity Model Certification 2.0 Level 2 passing score or certification from a 3rd party assessment organization before taking award of a contract. The requirement of CMMC certification places an undue burden on SMMs, particularly with respect to data security, and it is likely that other industries will begin adopting the same standard. Unlike large, global defense contractors, SMMs do not have the budgets or staff to implement specialized IT systems; compliant IT systems often have a significant fixed cost of implementation and maintenance that is far beyond even the revenues of most SMMs. Open- source solutions require specialized IT staff—if SMMs cannot afford commercial solutions, they almost certainly won’t have the expertise or budget to implement poorly-documented, user- unfriendly open-source solutions. In critical-CUI assets and system securing those critical assets, falling under the protection of CMMC 2.0 Level 3, several challenging cybersecurity rules are imposed, such as a 24 / 7 Security Operations Center. While large defense contractors may be able to afford implementation of specialized IT systems, many Defense Industrial Base firms are small-medium in size and these additional expenditures are only justifiable with large streams of revenue, immediately disqualifying many businesses. In an effort to address these daunting technical challenges in the art, the inventors disclose artificial intelligence (AI) technology that can assess whether an IT system complies with a cybersecurity compliance standard using a computer system that can process a representation of a compliance standard, query a system state for the IT system based on the processed compliance standard representation, and automatically produce a report about whether the IT system complies with the compliance standard. For example, disclosed herein is a method and system to make a model that acts as a vCISO (virtual Chief Information Security Officer) for a specific compliance framework, including modifying existing systems through autoconfiguration. Further disclosed herein is a method and system for a model to read compliance guides and / or National Institute of Standards and Technology (NIST) guides in order to perform an audit of IT systems, code, and other digital data. Further disclosed herein is a method and system to read the system state of an IT system and create a report of compliance based on the evidence required by that framework. Furthermore, systems and methods for employing hardened IT computer systems in accordance with digital cybersecurity controls are disclosed. According to example embodiments, the system may include a controller that provisions and manages inter-related services within the system using dependency graph resolution to automatically calculate Infrastructure as Code-based system configurations. Infrastructure as Code (IaC) refers to automated management and provisioning of IT infrastructure (e.g., servers, networking, storage, etc.) by writing and using code such as configuration files as opposed to manual configurations. An example embodiment can be bootstrapping a compute environment using a service template from an automatically configured and encrypted Storage Area Network (SAN). According to additional example embodiments, the system may include a controller that provisions storage to compute resources and / or provisions and connects resources to other IT environments, including to cloud instances. Additionally, according to example embodiments, those configurations and system components are commanded by novel cybersecurity techniques enhanced by Artificial Intelligence (AI) models with cybersecurity and compliance capabilities. Innovative techniques for automated IT deployment, administration, and compliance, performed in accordance to one of or a plurality of cybersecurity frameworks, are disclosed. As an example, the IT system to be evaluated for security compliance can be an IT system that comprises a hardware-based controller loaded with software. The controller is capable of automatically deploying a fully functioning IT system or connecting to an existing IT system, using IaC as a basis for consistently and reliably encoded automation needed to implement controls based on the requirements of a given cybersecurity framework, including metadata for versioning, provenance, and applicability scopes. The controller’s software capabilities include an Artificial Intelligence-based cybersecurity software leveraging Natural Language Processing (NLP) for ease of use, provided through Large Language Models (LLMs). This cybersecurity software is employed to automate multiple cybersecurity and compliance related tasks such as artifact and evidence gathering typically outlined in company policy, which are needed to attest that configuration and procedures are successfully within the parameters of compliance. The AI- and LLM-based cybersecurity software elements contain knowledge of cybersecurity maturity processes, controls, and best practices from a plurality of security standards and frameworks. As existing controls are modified and / or new controls are added, the LLM’s knowledge may be retrained or updated just-in-time through a retrieval augmented generation database that allows additional content to be provided ad hoc to the model(s) and incorporated into their responses. The AI and LLM models are provided access into the SAN by the controller, allowing the model to automatically evaluate and verify the IT system’s compliance using their pre-trained knowledge of cybersecurity standards, frameworks, best practices, and other references. A primary benefit of utilizing Infrastructure as Code for deterministic autoconfiguration is that it allows the controller to deploy and maintain consistent and reproducible environments. A subsequent benefit is that the consistency can be used as content that an AI is easily trained on; the AI is given consistent data and patterns reinforced by extensive pre-training on code. The controller’s knowledge of system state, global system rules, and configuration dependencies allows the AI systems to have a comprehensive view of the IT system. This AI capability is extensible to other use-cases. An example embodiment is that the system may be used to scan, evaluate, and even modify brownfield / pre-existing Infrastructure as Code-based IT systems and system configurations, simplifying a plurality of tasks associated with cybersecurity. Two popular Generative AI (GAI) modalities in which natural language understanding and natural language processing occurs are with either a single language model or a system of language models which together use a plurality of methods and algorithms during intercommunication to generate novel output based on the user’s prompt(s). Language models come in varying levels of general aptitude and roles / identities based on the intended use case. For example, small language models are generally beneficial as they are small enough in memory size to be easily portable between hardware platforms, and have become popular for their ability to be used on edge devices where specialized hardware such as advanced graphical processing units (GPUs) are not typical. Large language models and / or foundational models, which are trained on enormous amounts of data to drive multiple use cases and typically require specialized hardware in order to accommodate the additional performance demands, are not easily portable to small consumer devices and instead require advanced GPUs with enough memory to accommodate the model’s size. For enterprise use cases, a system of models that can intercommunicate provides greater fidelity by taking user input and intuitively delegating tasks to smaller specialized models fine-tuned to be experts in certain tasks and / or domains, and then report back to the foundational model. As hardware advances, users will benefit from increasingly powerful models hosted on their own devices. Training models to be accurate when responding to compliance inquiries, such as report generation requests, requires more than simply training a model on NIST standards as such training would only result in a model that responds like NIST. However by having a system of models trained on synthetic datasets showing how they should respond based on compliance rules, then the model will respond as an auditor. This approach involves using a model that can read NIST standards and guides, as well as providing the model(s) with a plurality of real-world pass and fail compliance reports from PCI and CMMC audits, which the model(s) can synthesize to create examples of systems that pass and fail. Those examples can be used to tune a model to respond to data about the system state, and as another model that can make examples and can theorize about whether the system is compliant or not. In order to avoid hallucinations, the model must also explain its reasoning, and optionally have it call a separate model (a gorilla) that will make API calls to controller logic in order to examine the system state and system rules to verify that the model is talking about the system in question and not a system in the training data. The process and methodology of building a new model for a new compliance type, in order to address the evolving compliance landscape, may be through an initial model which will bootstrap and create an initial dataset based on examples of compliance reports, frameworks, control sets, etc., that it is provided. The next step may be having the model respond with samples / examples of the new compliance type. The dataset will look like (INPUT: Compliance Type OUTPUT: examples of passes and fails and compliant systems). The next step is having the model create synthetic examples of passes and fails, which will allow us to tune a model just in time to respond like an auditor for each compliance type. In today's complex IT environments, maintaining compliance with various regulatory standards is a daunting and resource-intensive task. The advent of artificial intelligence (AI) and large language models (LLMs) offers promising solutions for automating compliance, including visualization and management. This patent pertains to a system designed to leverage AI and LLMs for generating comprehensively compliant IT systems, as well as visualizations and crosswalks of brownfield IT systems, enhancing both physical and logical network transparency, and automating compliance reporting for different regulatory frameworks. The disclosed system can utilize AI and LLMs to parse IaC configurations and dynamically generate compliance and risk matrix visualizations. Brownfield systems, characterized by their legacy components and diverse configurations, pose significant challenges for compliance management. This system automates the process of locating, associating, and presenting evidence for each control through a user interface (UI), providing real-time compliance insights. By continuously analyzing IaC-based IT systems, the AI models can map out existing configurations and generate visual crosswalks that illustrate how various components align with compliance controls. This ensures that compliance evidence is always up-to-date and readily available for audit purposes. The system may use system state data to extend its capabilities to verify and generate both physical and logical network diagrams. Utilizing the AI / LLM's comprehensive understanding of the system state, rules, and configurations, the system can produce accurate representations of the network infrastructure. This includes both physical layouts (e.g., hardware components and their interconnections) and logical structures (e.g., data flow and access controls). These automatically generated diagrams can aid staff in identifying potential compliance gaps and ensuring that the network adheres to the prescribed standards. The system's ability to dynamically update these diagrams in response to changes in the network state is crucial for maintaining ongoing compliance. An integral feature of this compliance system is its capability to generate a fully comprehensive inventory of system components. By scanning the Storage Area Network (SAN) and other system repositories, the AI models can identify all hardware and software components present within the IT environment. This inventory is then cross-referenced with the system's state, rules, and configurations to ensure accuracy. The comprehensive inventory not only aids in compliance reporting but also provides visibility into the physical and logical configurations of the system components. The system can also be designed to implement cybersecurity controls from a plurality of compliance frameworks, including but not limited to PCI-DSS, CMMC 2.0, NIST-CSF, and HIPAA. Each type of compliance framework has a corresponding audit, and the system may address those corresponding requirements through a series of compliance focused inquiries which can be emulated through LLMs, where each CSF may require and utilize its own distinct model. The plurality of AI models within the system perform cybersecurity tasks such as providing a visualization or to generate reports based on the particular standards of a CSF with which the organization must comply. A key set of features are those which leverage the system’s automation abilities to gather evidence automatically and generate reports based on those findings. Depending on the type of compliance audit, the system can produce documents such as System Security Plans (SSP) and Plans of Action and Milestones (POA&M). According to an example embodiment, reports are generated based on the real-time analysis of the entire system for compliance evidence, ensuring automated, accurate, and on-demand visibility for staff. This innovative approach to automated compliance harnesses a plurality of AI techniques and tools to automate the visualization, verification, and reporting of compliance in complex IT environments. According to example embodiments, generating real-time compliance insights, network diagrams, and comprehensive inventories using AI techniques and tools significantly reduces the burden of manual compliance task management. Its adaptability to different regulatory frameworks ensures that organizations can maintain robust compliance across various standards, ultimately enhancing their security posture and operational efficiency. These and other features and advantages of the present invention are explained in greater detail below. Brief Description of the Drawings: Figure 1 shows an example system in which AI-based cybersecurity compliance evaluations can be carried out. Figure 2 shows an example process flow for an AI-based cybersecurity compliance evaluation of an IT system. Figure 3 shows additional aspects of an example process flow for an AI-based cybersecurity compliance evaluation of an IT system. Figure 4 shows an example workflow for collecting and validating compliance evidence in response to system state queries from a compliance model. Figures 5A-5B provide a high-level overview of a CMMC compliance infrastructure. Figure 6 shows an example workflow for automatically identifying and fixing CMMC compliance gaps using remediation components. Figure 7 shows an example of how AI models from can be trained using CMMC framework data and real audit reports. Figures 8A-8B show an example of mapping a CMMC assessment process from initiation to report generation. Figures 9A-9C show an example of construction of the RAG Database from CMMC 2.0 Framework data by an educator model. Figures 10A-10C show an example of how a compliance model can process assessment process requests using a RAG Database. Detailed Description of Example Embodiments: FIG.1 shows an example system in which AI-based cybersecurity compliance evaluations can be carried out. The system comprises one or more processors 10 that cooperate with one or more memories 12 to perform an AI-based cybersecurity evaluation of IT system 20. These system components can be linked together via networking or other suitable connections for the processor(s) to gain access to information used for carrying out the operations described herein. The processor(s) 10 may take the form of one or more CPUs and / or other compute resources (e.g., field programmable gate arrays (FPGAs), graphics processing units (GPUs), application- specific integrated circuits (ASICs), etc.) that are suitable for performing the operations described herein. Moreover, memory 12 may comprise one or more physical memory devices that are capable of storing data, code, and other information that are to be accessed by the processor(s) 10 for carrying out the operations described herein. Moreover, it should be understood that multiple processors 10 and memories 12 may be employed in a distributed computing environment to perform the operations described herein. Further still, it should be understood that the processor(s) 10 and memory 12 may be part of the IT system 20 if desired by a practitioner. For example, the processor(s) 10 and memory 12 may be implemented by existing resources within the IT system 20 if desired by a practitioner. According to an example embodiment, the AI-based cybersecurity evaluation of the IT system 20 can be employ a plurality of different models that facilitate the evaluation. For example, as discussed in greater detail below, the system may employ en educator model and a compliance model. The educator model can focus on learning aspect of a specified CSF to translate that CSF for actionable understanding by the system. The compliance model can focus on comparing the translated CSF with pertinent aspects of the IT system 20 under evaluation so determinations can be made regarding whether the IT system 20 is compliant with the CSF and details regarding such compliance (where these details would include details about non-compliance if applicable). Further still, the system may also employ a system state model that translates a system state for the IT system into a set of pertinent data elements for use with the compliance model to carry out an evaluation. With this modular approach to AI-based cybersecurity evaluations, a number of technical benefits can be achieved relative to conventional systems in the art. Conventional systems for evaluating cybersecurity compliance are highly reliant on human expert intervention and custom code for dealing with specific compliance standards and / or different IT systems. These conventional systems are highly rigid and are not scalable for adapting to the changing nature of IT systems and cybersecurity standards. However, through the modular approach to cybersecurity evaluation described herein, the different models can be adapted and updated independently without necessitating widespread changes to the entire system. Moreover, through training and learning aspects of these AI models, the system can naturally adapt to changes in IT systems and different cybersecurity specifications without requiring massive system overhauls. This modular approach solves a significant scalability problem that exists with respect to conventional systems in the art. Even with IaC platforms and software-defined infrastructure, conventional systems still need an expert auditor to verify that no unauthorized changes or manual “monkey patch” changes are done to a system. This takes many hours for an auditor to verify, and therefore contributes to how conventional systems cannot efficiently audit IT systems for a large number of small businesses. When an IaC platform has a system state and ways to verify that there have not been changes, an AI model can enhance the amount of time to automatically read the configurations using the techniques described herein. When the system state is in a database, code can be employed to programmatically read the system state, system rules, and / or other information about the system. However, this approach would still not be friendly for humans to verify that information against compliance frameworks. One could write queries and a guide to verify these frameworks, but such custom code writing is not practically scalable because compliance frameworks change regularly. However with proper AI modeling and the ability for the AI modeling to adapt or for easier retraining, the techniques disclosed herein a scalable to readily adapt to changes to compliance frameworks Another technical problem that arises from AI solutions are the risk that the AI will hallucinate parts of a compliance playbook or aspects of the IT system to be evaluated. To address these risks, the AI modeling described herein can provide a database query that allows for querying and tracing an audit trail to verify that the model is being accurate. Furthermore, with the fine- tuning regimes discussed herein or ability to read a RAG as described herein, the inventive systems and methods described herein can quickly add in new compliance frameworks. IT System 20: The IT system 20 may comprise a computer system that includes a collection of resources (e.g., compute resources, storage resources, networking resources, etc.) that are arranged for cooperation with each other. The IT system can maintain a system state which comprises data that represents the collection of resources that comprise the IT system, and this data can include configuration information and operational information about this collection of resources. While the IT system 20 can take the form of other computer systems to be evaluated for cybersecurity compliance, an example of an IT system 20 that can be evaluated for cybersecurity compliance is disclosed by published PCT patent application WO 2020 / 252088, the entire disclosure of which is incorporated herein by reference. As explained in the WO 2020 / 252088 publication, the IT system 20 may include a controller that automatically manages the IT system 20. For example, the controller can use system rules, a system state, and templates to automatically manage the IT system’s physical infrastructure. This automated management can include adding resources to the IT system such as bare metal compute resources, bare metal storage resources, and bare metal networking resources while coupling these resources together to implement a desired system configuration. Accordingly, the IT system 20 may comprise a bare metal cloud node or physical resource. When the bare metal cloud node or physical resource is turned on, set up, managed or used, if it may be connected to a network with nodes that other people or customers may be using, the in- band management may be omitted, switchable, disconnectable or filtered from the controller. In addition, an application or applications network within a system may be disconnected, disconnectable, switchable, or filtered from the controller by way of resource(s) to which the application network is coupled to a controller. A physical resource that comprises a virtual machine or hypervisor may also be vulnerable to security issues, compromised or accessed by a rogue user where the hypervisor may be used to pivot to another hypervisor that is a shared resource. An attacker may break out of the virtual machine and may have network access to management and or administration systems by way of the controller. According to various example embodiments, the IT system may be configured to improve security where one or more physical resources that comprise a virtual resource on a cloud platform may disconnected, disconnectable, filtered, filterable or not connected to a controller by way of in-band management connection. According to example embodiments, a physical resource of an IT system may comprise one or more virtual machines or hypervisors where the in band management connection between the controller and the physical resource may be omitted, disconnected, disconnectable or filtered / filterable from the resource. According to example embodiments, the system may include a controller that provisions and manages inter-related services within the system using techniques described herein. As an example, clean up rules can be created and maintained to manage how modifications can be unwound in the event of a deletion of a service that has inter-dependencies with other services. According to example embodiments, the system may include a controller that provisions storage to compute resources and / or provisions and connects resources to cloud instances using techniques described in the above-referenced and incorporated WO 2020 / 252088 publication. Further still, according to example embodiments, the system can use the architecture described in the above-referenced and incorporated WO 2020 / 252088 publication to support efficient back up operations, including back ups involving multiple, interdependent services. In an effort to provide technical solutions to needs in the art as discussed above, the above- referenced and incorporated WO 2020 / 252088 publication discloses a variety of embodiments relating to systems and methods for information technology that provide automated IT system set up, configuration, maintenance, testing, change management and / or upgrade. For example, a controller can automatically manage a computer system based on a plurality of system rules, a system state for the computer system, and a plurality of templates. As another example, the controller can automatically manage physical infrastructure for a computer system based on a plurality of system rules, a system state for the computer system, and a plurality of templates. Examples of automated management that can be performed by the controller may include remotely or locally accessing and changing settings or other information on computers that may run an application or service, building an IT system, changing an IT system, building an individual stack in an IT system, creating a service or application, loading a service or application, configuring a service or application, migrating a service or application, changing a service or application, removing a service or application, cloning a stack onto another stack on a different network, creating, adding, removing, setting up, configuring, reconfiguring and / or changing a resource or system component, automatically adding, removing, and / or reverting a resource, service, application, IT system, and / or IT stack, configuring the interaction between applications, services, stacks, and / or other IT systems, and / or monitoring the health of IT system components. In example embodiments, the controller can be embodied as a physical or virtual computing resource that can be remote or local. Additional examples of controllers that can be employed include but are not limited to one of or any of a combination of processes, virtual machines, containers, remote computing resources, applications deployed by other controller, and / or services. The controller may be distributed across multiple nodes and / or resources, and may be in other locations or networks. IT infrastructure is most often constructed from discrete hardware and software components. Hardware components used generally comprise servers, racks, power supply equipment, interconnection, display monitors, and other communication equipment. The methods and techniques of selecting and then interconnecting these discrete components are highly complex with extremely large numbers of optional configurations that will function with varying degrees of efficiency, cost effectiveness, performance, and security. Individual technicians / engineers that are skilled at connecting these infrastructure components are expensive to hire and train. In addition, the extremely large number of possible iterations of hardware and software create complexity in maintaining and updating the hardware and software. This has created additional challenges when the individuals and / or engineering companies that originally installed the IT Infrastructure are not available to perform the updating. Software components such as operating systems are designed either generically to work on a broad scope of hardware or are very specialized to specific components. In most cases a complex plan, or blueprint, is drawn up and executed. Changes, growth, scaling, and other challenges require that the complex plan be updated. While some IT users purchase cloud computing services from a growing number of suppliers, this does not resolve the problems and challenges of setting up infrastructure, but rather shifts them from the IT user to the cloud service provider. Furthermore, large cloud service providers have addressed the challenges and problems of setting up infrastructure in a manner that may reduce flexibility, customization, scalability and rapid adoption of new hardware and software technologies. In addition cloud computing services do not provide out of the box bare-metal set up, configuration deployment and updating or allow for transition to, from or between bare-metal and virtual IT infrastructure components. These and other limitations of cloud computing services may lead to a number of computing, storage and networking inefficiencies. For example, speed or latency inefficiencies in computing and networking may be presented by cloud services or in applications or services utilizing cloud services. The system and method of an example embodiment provide IT infrastructure deployment, use and management. According to an example embodiment, the complexity of resource choice, installation, interconnections, management and updates are rooted within the core controller system and its parameter files, templates, rules, and IT system state. The system comprises a set of self-assembly rules and operating rules configured so that components self-assemble rather than requiring a technician to assemble, connect, and manage. Further the system and methods of an example embodiment allow greater customization, scalability, and flexibility using rules of self-assembly without requiring a currently typical external planning document. They also allow for efficient resource usage and repurposing. The IT system described in the above-referenced and incorporated WO 2020 / 252088 publication can ameliorate many of the issues and problems in current IT systems whether physical or virtual in whole or in part. The system and method of an example embodiment allow flexibility, reduce variability and human error, and provide a structure with potential for increased system security. While some solutions may exist individually for one or more of the problems in current IT systems, such solutions do not comprehensively address a multitude of the problems as are solved by example embodiments described herein. Furthermore such existing solutions may address a particular problem while compounding the others. Some of the current challenges for IT systems include, but are not limited to, issues related to the set-up, configuring, infrastructure deployment, asset tracking, security, application deployment, service deployment, documentation for maintenance and compliance, maintenance, scaling, resource allocation, resource management, load balancing, software failures, updating / patching software and security, testing, recovering IT systems, change management, and hardware updates. IT systems as used herein may include but are not limited to: servers, virtual and physical hosts, databases and database applications including but not limited to IT services, business computing services, computer applications, customer facing applications, web applications, mobile applications, back-ends, case number management, customer tracking, ticketing, business tools, desk top management tools, accounting, e-mail, documentation, compliance, data storage, back- ups, and / or network management. One problem users may face prior to setting up IT systems is predicting infrastructure needs. The user might not know how much storage, compute power, or other requirements will be needed either initially or over time during growth or change. According to an example embodiment an IT system and infrastructure allow flexibility in that if a system needs change, the self-deploying infrastructure (both physical and / or virtual) of an example embodiment may be used to automatically add, remove, or reallocate from within the infrastructure at a later time. Thus, the challenge of predicting future needs presented when setting up a system is addressed by providing the ability to add on to the system using its global rules, templates, and system state and by tracking the changes of such rules, templates and the system state. Other challenges may also relate to correct configuration, uniformity of configuration, interoperability, and / or interdependency, which may include, for example, future incompatibilities due to changes to configured system elements or configurations thereof over time. For example when the IT system is initially set up, there may be missing elements or a failure to configure some elements. And, for example when iterations of elements or infrastructure components are set up there may be a lack of uniformity between the iterations. Configuration may need to be revamped when changes to a system are made. A difficult choice has been presented between optimal configuration versus flexibility with future infrastructure changes. According to an example embodiment when first deploying a system, configuration is self-deployed using global system rules from templates to the infrastructure components so the configuration is uniform, repeatable or predictable allowing for optimal configuration. Such initial system deployment may be done on physical components while subsequent components may be added or modified and which may or may not be physical. Further, such initial system deployment may be done on physical components while subsequent environments may be cloned from the physical structure and may or may not be physical. This allows the system configuration to be optimal while permitting minimally disruptive future changes. In the deployment phase, there are typically challenges of interoperability of bare-metal and / or software defined infrastructure. There may also be challenges of interoperability of software with other applications, tools or infrastructure. These may include but are not limited to challenges due to deployed products originating from different vendors. Inventors disclose an IT system that may provide interoperability of infrastructure regardless of whether bare-metal, virtual or any combination thereof. Accordingly, the interoperability, the ability of the parts to work together, may be built into the disclosed infrastructure deployment where the infrastructure is automatically configured and deployed. For example, different applications may depend on each other, and they may exist on separate hosts. To allow for such applications to interact with each other, the controller logic, templates, system state, and system rules as discussed herein contain the information and configuration instructions to be used for configuring the applications' interdependencies and track the interdependencies. Thus, the infrastructural features discussed herein provide a way to manage how each application or service talks to one another. Some examples, making sure that email services communicate properly with authentication services; and / or making sure groupware services communicate properly with email services. Further still, such management can go down to the infrastructure level to permit tracking of how compute resources are communicating with storage resources, for example. Otherwise, complexity in IT systems can rise with O(nn). According as disclosed, automatic deployment of resources does not necessitate preconfiguring the operating system software due to the controller's ability to deploy based on global system rules, templates, and IT system state / system self-knowledge. According to an example embodiment, a user or IT professional may not need to know if the addition, allocation or reallocation of the resources will work together in order to ensure interoperability. Additional resources according to an example embodiment may be added to a network automatically. Using applications requires many different resources typically including compute, storage and networking. It also requires interoperability of the resources and system components, including knowledge of what is in place and running and interoperability with other applications. Applications may need to connect to other services and get configuration files and make sure every component works together properly. Application configuring can therefore be time and resource intensive. Application configuring can lead to cascading effects with the rest of the infrastructure if there are problems of interoperability with other applications. This can lead to outages or breaches. The inventors disclose automated application deployment to address these issues. Accordingly, as disclosed by the inventors, applications may be made self-deploying by reading from the IT system state, global system rules and templates, using knowledge of what is going on the system and intelligently configuring. Furthermore, according to an example embodiment pre-deployment testing of configuration may be performed using change management features as described herein. Another issue addressed by an example embodiment concerns problems that may arise relating to intermediary configurations where it is desired to switch to a different vendor or to other tools. According to an aspect of an example embodiment, template translation is provided between rules and templates of the controller and an application template from a particular vendor. This allows the system to change vendors of software or other tools automatically. Many security issues arise from misconfigurations, failure to patch, and inability to test patching prior to deployment. Often security issues may be created at the configuration stage of set-up. For example misconfigurations may leave sensitive applications exposed to the internet or allow forged emails from an email server The inventors disclose a system set up that is automatically configured thereby protecting against attackers avoiding unnecessary exposure to attackers and providing greater knowledge of the system to security engineers and application security architects. The automation reduces security flaws due to human error or misconfigurations. In addition, the disclosed infrastructure provides introspection between services and may allow rule based access and limit communications between services to only those that actually need to have it. The inventors disclose a system and method with the ability to safely test patches prior to deployment for example as discussed with respect to change management. Documentation frequently is a problematic area of IT management. During set up and configuration, a primary goal may typically be to get the components working together. Typically this involves troubleshooting and a trial and error process where at times, it is difficult to know what actually made a system work. While the exact commands as executed are typically documented, the troubleshooting or trial and error process that may have achieved a working system often is not well documented or even documented at all. Problems or inadequacies in documentation may create problems with audit trails and auditing. The documentation problems that arise may create problems in showing compliance. Often compliance issues may not be well known when building a system or its components. Applicable compliance determinations may only become known after a set up and configuration of an IT system. Thus documentation is crucial for auditing and compliance. The inventors disclose a system comprising global system rules database, templates, and an IT system state database, which provide an automatically documented set up and configuration. Any configuration that occurs is a recorded in a database. According to an example embodiment, automatically documented configuration provides audit trails and can be used to show compliance. Inventory management may use the automatically documented and tracked information. Another challenge that arises from IT system set-up, configuration, and operation involves inventory management of hardware and software. For example, it is typically important to know how many servers there are, whether they are up and still functioning, what are their capabilities, in which rack each server is, which power supplies are connected to which servers, what network cards and what network ports each server is using, which IT system the components are operated in and many other important notes. In addition to inventory information, passwords used for inventory management and other sensitive information should be managed effectively. Particularly in larger IT systems, data centers or data centers where equipment changes frequently, the gathering and retention of this information is a time consuming task that is often managed manually or using a variety of software tools. Compliant protection of the secure passwords is a large risk factor that can be an important issue in assuring secure computing environments. Inventors disclose and IT system where the gathering and maintaining of the inventory and operational status of all servers and other components is automatically updated, stored and secured as part of the IT system state, global system rules, templates, and controller logic of the controller. In addition to addressing problems with set-up and configuration of an IT system, the IT system 20 may also be designed to address problems and issues that appear in the maintenance of IT systems. A number of problems arise with the continuous functioning of data centers with hardware failures, for example, power supply failure, memory failure, network failure, network card failure, and / or CPU failures among other things. Additional failures emerge when migrating a host during hardware failures. Accordingly, the IT system may employ dynamic resource migration, e.g., migrating resource from one resource provider to another resource provider when a host goes down. In such situation according to an example embodiment, the IT system can migrate to other servers, nodes or resources, or to other IT systems. A controller may report the system's status. A duplicate of the data is on another host having a known and automatically set up configuration. If a hardware failure is detected, then any resource that the hardware may have been providing may be migrated automatically after automatically detecting the failure. A significant issue with many IT systems is scalability. Growing businesses or other organizations typically add on or reconfigure their IT systems as they grow and their needs change. Problems arise when more resources are needed for an existing IT system, for example adding hard drive space, storage space, CPU processing, more network infrastructure; more end points, more clients and / or more security. Problems also arise in configuration, set up and deployment when different services and applications or changes to infrastructure are needed. According to an example embodiment, a data center may be scaled automatically. Nodes or resources may be added to or removed from the pools of resources dynamically and automatically. Resources added and removed from the resource pool may be automatically allocated or reallocated. Services may be provisioned and moved over to new hosts rapidly. The controller may detect and add more resources to the resource pools dynamically and know where to allocate / reallocate resources. A system according to an example embodiment may scale from a single node IT system to a scaled system needing numerous physical and / or virtual nodes or resources across multiple datacenters or IT systems. The IT system 20 may also be configured to enable flexible resource allocation and management. The system comprises compute, storage and networking resources that may be in resource pools and may be dynamically allocated. The controller may recognize new nodes or hosts on a network and then configure them so that they can be part of the resource pools. For example, whenever a new server is plugged in, the controller configures that as part of the resource pool and can add it to the resources and can begin using it dynamically. The nodes or resources may be detected by the controller and added to the different pools. Resource requests may be made, e.g., through an API request to a controller. The controller may then deploy or allocate the needed resources from the pools according to the rules. This allows the controller and / or an application through the controller, to load balance and dynamically distribute the resources based on needs of the request. Examples of load balancing include but are not limited to: deploying new resources when hardware or software failures occur; deploying one or more instances of the same application in response to an increased user load; and deploying one or more instances of the same application in response to an imbalance in storage, computing or networking requirements. The problems involved in making changes to live IT systems or environments may create substantial, and at times, catastrophic problems for users or entities that rely on these systems to be consistently up and running Not only do these outages represent potential losses in use of the system, but losses of data, economic losses due to substantial resources of time, personnel and money required to fix the problems. The problems can be exacerbated by difficulties rebuilding a system where there are errors in documentation of configuration or lack understanding of the system. Because of this problem many IT system users are reluctant to patch IT resources to eliminate known security risks. They thus remain more vulnerable to security breaches. A host of problems arising in maintenance of IT systems are related to software failures due to change management or control where configuration may be required. Situations in which such failures may occur include but are not limited to upgrading to new software versions, migrating to a different piece of software; password or authentication management changes; switches between services or between different providers of a service. Manually configured and maintained infrastructure is typically difficult to recreate. Recreating infrastructure may be important for several reasons including, but not limited to, rolling back problematic changes, power outages or for other disaster recovery. Problems in manually configured systems are difficult to diagnose. Manually configured and maintained infrastructure is difficult to remake. In addition, system administrators can easily make mistakes for instance an incorrect command which in turn have been known to have brought down computer systems. Making changes to live IT systems or environments can create substantial and at times catastrophic problems for users or entities that rely on these systems to be consistently up and running Not only do these outages represent potential losses in use of the system, but such outages can also cause losses of data as well as economic losses due to substantial resources of time, personnel and money required to fix the problems. The problems can be exacerbated by difficulties rebuilding a system where there are errors in documentation of configuration or lack understanding of the system. And, in many cases, it is very difficult to restore a system to a previous state after a significant or major change. Furthermore the technical problems potentially created when changes are made to live environments may have cascading effects. These cascading effects may make it challenging and sometimes not possible to going back to the pre-change state. Thus, even if changes need to be reverted back due to problems with implemented changes, the state of the system has already changed. It has been recently stated that it is an unsolved problem to undo infrastructure and system administration errors as well as faulty changes to a production environment. Additionally, it has been known to be problematic to test changes to a system before deployment to a live environment. Accordingly, a number of example embodiments for the IT system 20 can be configured to revert a change to a live system back to a pre-change state. Further, inventors disclose a system and method are provided that is configured to enable a substantial reversion of a state of system or environment undergoing live changes that may prevent or ameliorate one or more of the problems described above. According to a variation of an example embodiment, the IT system has full system knowledge with the global system rules, templates, and IT system state. The infrastructure may be cloned using the full system knowledge. The system or a system environment may be cloned as a software defined infrastructure or environment. A system environment including a volatile database that is in use, referred to as the production environment, may be written into a non- volatile read only database to be used as development environment in a development and testing process. Desired changes may be made to and tested in the development environment. A user or controller logic may make changes the global rules to create a new version. The versions of the rules may be tracked. According to another aspect of an example embodiment a newly developed environment may be then implemented automatically. The previous production environment may also be maintained or fully functional so the revision to the earlier state production environment is possible without losing data. The development environment may then be booted with the new specification, rules, and templates and the databases or the system are synced with the production database and may be switched to a writeable database. The original production database may then be switched to a read only database to which the system may revert if recovery is necessary. With respect to upgrading or patching software, a new host may be deployed if a service is detected that needs an upgrade or patch. The new service may be deployed while change reversion is possible as described above, in the event there is a failure due to the upgrade or patch. Hardware upgrades are significant in many situations particularly where up-to-date hardware is essential. An example of this type of situation occurs in the high frequency trading industry where an IT system with milliseconds of speed advantage may enable a user to achieve superior trading results and profits. In particular, problems arise in ensuring interoperability with current infrastructure so that the new hardware will know how to communicate with protocols and work with existing infrastructure. In addition to ensuring interoperability of components, the components would require integration with an existing set up. Modular AI Approach to Evaluating Cybersecurity Compliance for an IT System: FIG.2 illustrates a system of AI models 100 that work together to analyze, configure, verify, and report to a user on the state of compliance. The system of AI models 100 includes an educator model 110, a compliance model 111, and a system state model 112, and the processor(s) 10 in cooperation with these models can fetch and return system state data 112.1 by querying system state to answer questions from the compliance model 111. System state model 112 queries dataset 120 containing audit reports and dataset with queries of the database 121 in the process 201 for determining compliance. The process 201 for determining compliance is shown by Figure 1 as a flowchart which first describes how the educator model 110 teaches compliance specifications to a retrieval augmented generation 300 that processes the compliance specifications and prompts the compliance officer model 111. The compliance model 111, which can also be referred to as a compliance officer model, fetches compliance specification from retrieval augmented generation 300 and asks questions about system state data 112.1 from the system state model 112. System state model 112 responds to compliance officer model 111 by querying system state data 112.1 and returning answers. Finally, the compliance officer model 111 responds with findings and offers remediation advice which can include instructions to give to the controller 200 to execute automatically or with user permission. Compliance officer model 111 can also respond to user inquiry with a compliance report or offer the information to another helper model 113 which can also offer a compliance report. Compliance officer model 111 can cite sources and show methods which can be tested and verified by a human to check against hallucinations. FIG.3 discloses an additional embodiment where the system 100 may use a dataset 120 that contains audit reports. This dataset 120 can be used for the compliance officer model 111 to respond like a compliance officer, furthermore in some examples a compliance standard and a set of audit reports with information about the real or fictitious companies may be included. In this embodiment the dataset 120 can contain audit reports for a specific compliance to direct tune a compliance officer model 111 or it can be used for tuning an educator model 110 that takes in compliance standards. The training material can include a single or plurality of compliance standards. For the compliance officer model 111 the training set can include example systems and audit reports. These audit reports can be coupled to example systems. The audit report can have citations that match to the compliance standards. The dataset 120 can also have a plurality of compliance standards coupled to example systems audit reports (that are coupled together). In an additional embodiment the compliance officer model 111 can have a vector database or a lookup table of a compliance standard that matches to audit reports that are coupled. This can also be used for making training sets of these vector diagrams coupled with compliance standards for the educator model 110 to make these compliance standard files. The educator model 110 can also provide proper technical information and examples of how they might be used an an audit. The educator model 110 can also be used for making microchanges to standards that the compliance officer model already knows from his original training. Educator model 110 to compliance officer model 111 can be in the form of a generated RAG that the compliance model officer 111 can know how to use from his training or it can be done through prompting the compliance officer model 111. The compliance officer model 111 can be trained so that the prompts include a system coupled to a compliance standard. The outputs of the compliance officer model 111 could then be the audit report. Another model 113 can be used to query the system state 112.1 and couple a system state 112.1 to that prompt for the compliance officer model 111 or use the system state 112.1 as an input and the prompt will have the compliance standard included in the prompt. The dataset for training with any of these models 110-113 can include queries of the system state 112.1. These queries can optionally be coupled to parts of example compliance reports and optionally be coupled to compliance standards that can be written in a specific prompt method (or prompt language) or natural language. The educator model 110 can condense down a compliance standard and then using a compliance officer model 111, either directly or to create synthetic data can match queries to a system state 112.1. This method will allow for a system that can take a compliance standard and query the system state and write a report of compliance automatically. The system state queries can be done an a specific model and the compliance officer model 111 can be trained to talk to the system state query model 112. The educator model 110 is a model trained and / or fine tuned to turn compliance specifications into a lookup table or fine tuning material for a compliance officer model 111. The educator model 110 can give information to the compliance officer model 111 based on the compliance standard. The compliance officer model 111 can be trained on compliance audits however standards may change and the compliance officer model 111 might need to be updated. The compliance offer model 111 can be trained or fine tuned on a synthetic dataset from the educator model 110 and the compliance officer model 111 can also be trained based on an educator model 110 sending compliance specifications so that the compliance officer model 111 is able to know how to take compliance standards. The educator model 110 can also be trained using a compliance officer model 111 to write prompts to feed to the compliance officer model 111. The compliance officer model 111 can be trained directly as a compliance officer but it can also be trained by the educator model 110. The compliance offer model 111 can be trained in multiple or a singular compliance standard based on reports of compliance. An educator model can take audit reports from dataset 120 and turn them into training materials. The compliance officer can then talk to another model 113 or directly get information based on the system state 112.1 and audit the configurations of the system and provide a report that can be used for compliance. The compliance officer model 111, or an alternate model 113 can converse with the compliance officer model 111, to make it so that a human auditor can talk with the compliance model 111 as an AI-based compliance auditor. The educator model 110 can provide source citations for the information and that info can be trained into the compliance officer model 111. This may reduce hallucinations. Evidence Collection Diagram (Process 420): Fig.4 illustrates the complete workflow for collecting and validating compliance evidence in response to system state queries from the Compliance Officer Model (111). With reference to FIG.4, at step 1.01, the System State Model (112) receives a natural language query from the Compliance Officer Model (111), such as "Are CUI systems encrypted?" At step 1.02, the System State Model (112) parses the intent of the query and maps it to specific CMMC controls from the 700 Series, such as 760 - SC.L2-3.13.16 for system communications protection, and structures the query into a database query. At step 1.03, the System State Model (112) accesses multiple data sources from the 300 Series, including the IT System State Database (310), SAN Storage Configurations (320), Audit Logs Database (330), and Network Configurations Database (340), to gather various evidence types, such as configuration files with encryption settings, security certificates and PKI status, access control lists with user permissions, audit trail logs of security events, network topology with segmentation rules, and the CUI Systems asset inventory (540). At step 1.04, all gathered evidence undergoes rigorous validation through the Validation & Verification Process (450), which includes completeness verification, cross-referencing multiple sources, timestamp currency checks, and data integrity validation. At step 1.05, the validated evidence is structured for compliance review with proper citations, source references, control mapping context, and formatted responses for the Compliance Officer Model (111). System Architecture Diagram (200-600 Series Overview): FIGs.5A and 5B provide a high-level overview of the complete CMMC compliance infrastructure spanning all numbered component series. With reference to FIGs.5A-5B, at step 2.01, the Physical Infrastructure (200 Series) consisting of Bare Metal Servers (211), Network Equipment (212), and Storage Systems (213) connects to the Controller System (220). At step 2.02, the Controller System (220) manages the Global System Rules Database (350), Templates Database (360), and IT System State Database (310). At step 2.03, the SAN Storage Configurations (320) store system configurations, audit logs, and compliance evidence. At step 2.04, the AI Models (100 Series) including the Educator Model (110), Compliance Officer Model (111), and System State Model (112) work together with the RAG Database (300) to process the CMMC 2.0 Framework components (500 Series) comprising the 17 Control Domains (520) and 110 Individual Controls (530). At step 2.05, the system outputs deliverables from the 600 Series, including Compliance Reports (610), System Security Plans (620), POA&M Documents (630), and Executive Dashboard (640). Automated Remediation Diagram (Process 430): FIG.6 details the workflow for automatically identifying and fixing CMMC compliance gaps using the remediation components from the 800 Series. With reference to FIG.6, at step 3.01, compliance findings from the Gap Analysis Process (440) are automatically categorized by criticality (Critical / Medium / Low) and remediation type (810 - Automated Fixes, 820 - Semi- Automated Actions, 830 - Manual Actions). At step 3.02, the system generates specific Controller Commands (840) for common fixes, such as enabling encryption (referencing 760 - SC.L2-3.13.16), updating access control lists (referencing 710 - AC.L2-3.1.1), and enabling audit logging (referencing 720 - AU.L2-3.3.1). At step 3.03, each remediation follows the Execution Pipeline (850) including validation through the Verification Process (450), staging, testing, and deployment via the Controller System (220), with built-in rollback capabilities. At step 3.04, the process concludes with verification through re-running the Compliance Assessment Process (410) and comprehensive Audit Trail Documentation (650) including updated System Security Plans (620). Model Training Diagram (100 Series Development): FIG.7 illustrates how the AI models from the 100 Series are trained using CMMC framework data and real audit reports. With reference to FIG.7, at step 4.01, the Educator Model (110) is trained by parsing controls from the CMMC 2.0 Framework (510) and generating synthetic pass / fail scenarios to build the RAG Database (300) with vector embeddings. At step 4.02, the Compliance Officer Model (111) learns from real CMMC audit reports (Dataset 120) and synthetic training data from the Educator Model (110) to develop the Assessment Process (410) patterns. At step 4.03, the System State Model (112) learns query translation to map natural language questions to 300 Series database queries and proper response formatting for the Evidence Collection Process (420). At step 4.04, all models undergo validation through the Verification Process (450) against known CMMC outcomes with hallucination checks and iterative training refinement. Compliance Assessment Diagram (Process 410): FIGs.8A and 8B map the complete CMMC assessment process from initiation to 600 Series report generation. With reference to FIGs.8A-8B, at step 5.01, the Assessment Process (410) is triggered by either a scheduled or user-requested event. At step 5.02, the CUI Systems Scope (540) is defined, the CMMC level is determined, and the 17 Control Domains (520) are identified. At step 5.03, the Compliance Officer Model (111) queries the RAG Database (300) to generate control checklists. At step 5.04, the System State Model (112) translates these into Evidence Collection Process (420) queries to gather system evidence from the 300 Series databases. At step 5.05, the assessment evaluates all 700 Series CMMC domains, producing PASS / PARTIAL / FAIL results with supporting evidence citations. At step 5.06, final outputs include the Compliance Assessment Reports (610), System Security Plans updates (620), Plan of Action & Milestones (630), and Executive Summaries (640). Educator Model RAG Diagram (Component 300 Creation): FIGs.9A, 9B, and 9C detail the construction of the RAG Database (300) from CMMC 2.0 Framework (510) data by the Educator Model (110). With reference to FIGs.9A-9C, at step 6.01, the system parses the 17 Control Domains (520) to extract the 110 Individual Controls (530), processing each domain from the 700 Series to extract requirement text. At step 6.02, the Educator Model (110) generates implementation examples, creates pass / fail scenarios, and maps controls to specific system queries for the System State Model (112). At step 6.03, the vector database creation process for the RAG Database (300) includes text embeddings, control vectors indexed by domain and level, and implementation context storage. At step 6.04, each RAG entry contains the control ID, requirement text, implementation examples, system queries for the System State Model (112), and pass / fail criteria for the Compliance Officer Model (111), creating a comprehensive compliance specification ready for the Assessment Process (410). Compliance Officer Operation Diagram (Component 111 Workflow): FIGs.10A, 10B, and 10C demonstrate how the Compliance Officer Model (111) processes Assessment Process (410) requests using the RAG Database (300). With reference to FIGs.10A- 10C, at step 7.01, the Compliance Officer Model (111) starts with a compliance assessment request, determines the required CMMC level, and identifies the CUI Systems in scope (540). At step 7.02, the Compliance Officer Model (111) queries the RAG Database (300) to retrieve relevant 700 Series controls, then parses requirements to generate specific system state questions. At step 7.03, these queries are sent through the Evidence Collection Process (420) to the System State Model (112), which returns evidence responses from the 300 Series databases. At step 7.04, the Compliance Officer Model (111) evaluates this evidence against CMMC control requirements, determining PASS / PARTIAL / FAIL status and generating detailed findings with the Gap Analysis (440) and non-compliance identification. At step 7.05, the process culminates in comprehensive Assessment Reports (610) returned to users or integrated systems, with potential triggering of the Automated Remediation Process (430) for identified gaps. Component Series Overview 100 Series - AI Models & Core Intelligence ^ 110 - Educator Model: Processes CMMC framework into structured knowledge. ^ 111 - Compliance Officer Model: Conducts automated compliance assessments. ^ 112 - System State Model: Translates queries into evidence collection. 200 Series - Infrastructure & Hardware ^ 211 - Bare Metal Servers: Primary compute resources for AI models. ^ 212 - Network Equipment: Secure networking for compliance system. ^ 213 - Storage Systems: High-availability storage for compliance data. ^ 220 - Controller System: Central orchestration hub. 300 Series - Data Storage & Databases ^ 300 - RAG Database: Vector database with CMMC compliance knowledge. ^ 310 - IT System State Database: Real-time system configurations. ^ 320 - SAN Storage Configurations: Encrypted configuration storage. ^ 330 - Audit Logs Database: Comprehensive audit trail storage. ^ 340 - Network Configurations Database: Network topology and security. ^ 350 - Global System Rules Database: Centralized policy management. ^ 360 - Templates Database: Standardized documentation templates. 400 Series - Assessment & Compliance Processes ^ 410 - Compliance Assessment Process: End-to-end CMMC assessment workflow. ^ 420 - Evidence Collection Process: Systematic compliance evidence gathering. ^ 430 - Automated Remediation Process: Automated gap correction. ^ 440 - Gap Analysis Process: Systematic compliance deficiency identification. ^ 450 - Validation & Verification Process: Accuracy and completeness assurance. 500 Series - CMMC Framework Components ^ 510 - CMMC 2.0 Framework: Official DoD cybersecurity framework. ^ 520 - 17 Control Domains: Organized cybersecurity control categories. ^ 530 - 110 Individual Controls: Specific CMMC security requirements. ^ 540 - CUI Systems Scope: Identification of systems requiring compliance. 600 Series - Outputs & Reports ^ 610 - Compliance Assessment Reports: Comprehensive compliance documentation. ^ 620 - System Security Plans: Formal security control implementation docs. ^ 630 - Plan of Action & Milestones: Remediation tracking documents. ^ 640 - Executive Dashboard: High-level compliance status visualization. ^ 650 - Audit Trail Documentation: Comprehensive activity logging. 700 Series - Security Control Domains ^ 710 - Access Control Domain: User access management (AC.L2-3.1.1-22). ^ 720 - Audit & Accountability Domain: Security event logging (AU.L2-3.3.1-9). ^ 730 - Awareness & Training Domain: Security training (AT.L2-3.2.1-3). ^ 740 - Configuration Management Domain: Security configurations (CM.L2-3.4.1-9). ^ 750 - Identification & Authentication Domain: Identity verification (IA.L2-3.5.1-12). ^ 760 - System & Communications Protection Domain: Information protection (SC.L2- 3.13.1-16). 800 Series - Remediation Components ^ 810 - Automated Fixes: Fully automated remediation actions. ^ 820 - Semi-Automated Actions: Human-approved remediation. ^ 830 - Manual Actions: Human-implemented remediation. ^ 840 - Controller Commands: Standardized remediation command set. ^ 850 - Execution Pipeline: Systematic remediation implementation process. Integration Flow Summary Assessment Workflow: 410 → 111 → 300 → 112 → 420 → 300 Series DBs → 450 → 610 / 620 / 630 / 640 Remediation Workflow: 440 → 800 Series → 850 → 220 → 450 → 410 (verification) Training Workflow: 510 → 110 → 300 → 111 / 112 → 450 (validation) Evidence Workflow: 420 → 112 → 300 Series DBs → 450 → 111 → 610 While the invention has been described above in relation to its example embodiments, various modifications may be made thereto that still fall within the invention’s scope. Such modifica- tions to the invention will be recognizable upon review of the teachings herein.
Claims
WHAT IS CLAIMED IS:
1. A computer system for scalably assessing cybersecurity compliance with respect to a cybersecurity compliance framework, the system comprising: one or more processors; one or more memories configured to store an educator model, a compliance model, and a system state; wherein the system state comprises data that represents a collection of resources that comprise an IT system, wherein the data includes configuration information and operational information about the collection of resources; wherein the educator model comprises data structures that support translation of a cybersecurity compliance specification into a retrieval augmented generation (RAG) database; wherein the compliance model comprises data structures that support translation of elements from the RAG database into queries for the system state; wherein the one or more processors are configured to employ the educator model to analyze the cybersecurity compliance specification and translate the cybersecurity compliance specification into the RAG database; wherein the one or more processors are configured to employ the compliance model to translate the RAG database into queries for the system state; wherein the one or more processors are configured to query a representation of the system state based on the queries; and wherein the one or more processors are further configured to generate data indicative of whether the IT system complies with the compliance specification based on responses to the queries.
2. The system of claim 1 wherein the computer system is part of the IT system.
3. The system of any of claims 1-2 wherein the educator model supports translating a plurality of different compliance specifications into a RAG.
4. The system of claim 3 wherein the educator model comprises a plurality of educator models that correspond to the different compliance specifications, and wherein the one or more processors are further configured to select an educator model from among the educator models based on which of the educator models corresponds to a specified compliance specification.
5. The system of any of claims 1-4 wherein the one or more processors are further configured to train the educator model based on a plurality of training samples corresponding to different compliance specifications.
6. The system of any of claims 1-5 wherein the cybersecurity compliance specification comprises a natural language cybersecurity compliance specification, and wherein the one or more processor are further configured to use natural language processing (NLP) and one or more large language models (LLM) to interpret the natural language cybersecurity compliance specification.
7. The system of claim 6 wherein the one or more processors are further configured to generate the educator model based on the interpreted natural language cybersecurity compliance specification.
8. The system of claim 7 wherein the one or more processors are further configured to translate the interpreted natural language cybersecurity compliance specification into a plurality of controls.
9. The system of claim 8 wherein the one or more processors are further configured to employ the educator model to create vector embeddings for the controls with associated implementation guidance derived from the interpreted natural language cybersecurity compliance specification.
10. The system of claim 9 wherein the RAG database links the controls to a plurality of system configuration requirements.
11. The system of any of claims 1-10 wherein the one or more processors are further configured to train the compliance model based on a plurality of training samples.
12. The system of claim 11 wherein the training samples comprise a plurality of CMMC assessment reports.
13. The system of any of claims 1-12 wherein the one or more processors are further configured to receive a CMMC compliance query for evaluating the IT system and employ the compliance model to fetch a plurality of CMMC controls from the RAG database in response to the CMMC compliance query.
14. The system of claim 13 wherein the one or more processors are further configured to employ the compliance model to formulate queries for the system state that verify a control implementation based on the fetched CMMC controls.
15. The system of any of claims 1-14 wherein the one or more processors are further configured to generate a system state model based on the system state, wherein the system state model comprises a representation of the system state that is interpretable as evidence with respect to the cybersecurity compliance specification; and wherein the one or more processors are further configured to query the system state model based on the queries in order to generate the data indicative of whether the IT system complies with the compliance specification.
16. The system of any of claims 1-15 wherein the IT system comprises a controller, the system state, a plurality of system rules, and a plurality of templates; and wherein the controller is configured to perform automated management of infrastructure for the IT system including the resources based on the system state, the system rules, and the templates; and wherein the controller is further configured to update the system state based on the automated management.
17. The system of any of claims 1-16 wherein the one or more memories include a first memory configured to store the system state and a second memory configured to store the educator model and / or the compliance model.
18. The system of any of claims 1-17 wherein the one or more processors comprise (1) a first processor configured to employ the educator model to analyze the cybersecurity compliance specification and translate the cybersecurity compliance specification into the RAG database and (2) a second processor configured to employ the compliance model to translate the RAG database into queries for the system state.
19. A scalable computerized method for evaluating cybersecurity compliance with respect to a cybersecurity compliance framework, the method comprising: one accessing an educator model, a compliance model, and a system state, wherein the system state comprises data that represents a collection of resources that comprise an IT system,wherein the data includes configuration information and operational information about the collection of resources, wherein the educator model comprises data structures that support translation of a cybersecurity compliance specification into a retrieval augmented generation (RAG) database, and wherein the compliance model comprises data structures that support translation of elements from the RAG database into queries for the system state; employing the educator model to analyze the cybersecurity compliance specification and translate the cybersecurity compliance specification into the RAG database; employing the compliance model to translate the RAG database into queries for the system state; querying a representation of the system state based on the queries; and generating data indicative of whether the IT system complies with the compliance specification based on responses to the queries; and wherein the method steps are performed by one or more processors.
20. The method of claim 19 further comprising any feature or combination of features set forth by any of claims 1-18.
21. A computer system for scalably translating a natural language cybersecurity compliance specification into an actionable data structure for automating a cybersecurity compliance evaluation, the system comprising: one or more processors; one or more memories configured to store an educator model; wherein the one or more processors are configured to (1) use natural language processing (NLP) and one or more large language models (LLM) to interpret the natural language cybersecurity compliance specification and (2) generate the educator model based on the interpreted natural language cybersecurity compliance specification, wherein the educator model comprises data structures that support translation of a cybersecurity compliance specification into a retrieval augmented generation (RAG) database.
22. The system of claim 21 further comprising any feature or combination of features recited by any of claims 1-20.
23. A computer system comprising: one or more processors; one or more memories configured to store a compliance model;wherein the one or more processors are configured to create the compliance model based on a plurality of training samples, wherein the compliance model comprises data structures that support translation of elements from a RAG database derived from a cybersecurity compliance specification into queries for a representation of a system state of an IT system to generate data indicative of whether the IT system is compliant with the cybersecurity compliance specification.
24. The system of claim 23 further comprising any feature or combination of features recited by any of claims 1-22.
25. A computer system comprising: one or more processors; one or more memories configured to store a system state model that models a system state for an IT system; wherein the one or more processors are configured to create the system state model based on the system state, wherein the system state model comprises a representation of the system state that is interpretable as evidence with respect to a cybersecurity compliance specification.
26. The system of claim 25 further comprising any feature or combination of features recited by any of claims 1-24
Citation Information
Patent Citations
Contextual security behavior management and change execution
US20200021620A1
Determination of Compliance with Security Technical Implementation Guide Standards
US20210194929A1
Systems and methods for intelligent segmentatioin and rendering of computer environment data
US20210232593A1
Policy-driven management of security and compliance controls for multi-cloud workloads
US20220210194A1
Systems and methods for protection modeling
US20240256678A1