Skip to main content
Home
Main navigation
  • CAPABILITIES
  • SOLUTIONS
    • ArgusGA
    • AthenaGA
    • ComplySyncATO
    • ComplySyncATO (ServiceNow)
    • HephaestusGA
    • PhoenixGA
  • CUSTOMERS
  • CONTRACT VEHICLES
  • ONPOINT
Responsive Hamburger Menu
  • CAPABILITIES
  • SOLUTIONS
    • ArgusGA
    • AthenaGA
    • ComplySyncATO
    • ComplySyncATO (ServiceNow)
    • HephaestusGA
    • PhoenixGA
  • CUSTOMERS
  • CONTRACT VEHICLES
  • ONPOINT
  • GREEN ACCELERATOR
  • PARTNERS
  • CAREERS
  • ABOUT US
primary menu
GREEN ACCELERATOR
PARTNERS
CAREERS
ABOUT US
alt

FILTER BY

Type
Tags
Sectors
Capabilities
Sort by
APPLY
RESET
From Manual Compliance to Machine Readable Trust with OSCAL

KHALIL ZEBDI

KHALIL ZEBDI
EVP – Business Development
2025-07-21

With over a decade of experience in cybersecurity program management, I've gained deep insights into effective and ineffective strategies. My oversight of cybersecurity programs for healthcare government agencies, such as CMS, provides me with opportunities to identify and implement innovative technologies and processes for problem-solving. 

A notable challenge, for example, arises when files are received in OSCAL for GRC but cannot be seamlessly transmitted to disparate systems. This gap presents ASSYST with an opportunity to develop a proof of concept for standardizing security artifacts in machine-readable formats, including XML, JSON, and YAML. Ultimately, embracing OSCAL is pivotal for transforming compliance from a hindrance into a strategic advantage.

OSCAL: A Schema for Cybersecurity Consistency and Automation

Developed by NIST, this introduces a structured, machine-readable format (JSON, XML, YAML) for expressing security and privacy control documentation. It applies across the entire Risk Management Framework (RMF), including:

  • System Security Plans (SSPs)
  • Security Assessment Plans (SAPs)
  • Assessment Results (SARs)
  • POA&Ms
  • Control Catalogs and Implementation Profiles
  • Component and Service Definitions

The technical value of OSCAL is clear: it enables automated systems to interpret, validate, and integrate compliance artifacts across heterogeneous environments, eliminating the need for manual formatting, subjective interpretation, and repetitive control rewriting.

Before and After OSCAL: What Changes Technically?
Data Standardization as Strategy 

OSCAL represents a fundamental shift in how cybersecurity compliance is approached—moving from static documentation to machine-readable, structured data.

At its core, OSCAL is not just a format; it is a framework for automation, validation, and scalability. By expressing security artifacts, such as System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms), in standardized formats, OSCAL enables consistent interpretation, seamless integration, and faster processing across tools, teams, and systems.

Operationalizing OSCAL means adopting a data-first mindset—where compliance is not a manual output but a continuously validated state. This shift enables agencies and organizations to enhance audit readiness, minimize human error, and expedite the authorization process.

Operationalizing OSCAL Across the RMF Lifecycle

To help federal agencies practically implement OSCAL, forward-leaning compliance programs are embracing full-lifecycle automation strategies that align with evolving cybersecurity mandates and digital transformation goals.

Key technical enablers include:

Schema-Validated OSCAL Artifact Conversion

Transforms legacy System Security Plans (SSPs), Security Assessment Plans (SAPs), and Security Assessment Reports (SARs) into OSCAL-compliant formats while preserving control mappings and implementation metadata. This ensures continuity and consistency across traditional and machine-readable documentation.

Cross-Framework Harmonization

Enables alignment across frameworks such as FedRAMP, NIST 800-53, CMMC, and agency-specific overlays using OSCAL control profiles, tailoring capabilities, and inheritance mappings. This simplifies multi-standard compliance while supporting reuse and reciprocity.

AI-Enabled Evidence Ingestion

Integrates real-time inputs from vulnerability scanners, ticketing systems, and system logs. Natural Language Processing (NLP) models automatically map evidence artifacts to corresponding control identifiers, reducing manual effort and increasing traceability.

Automated SAR and POA&M Generation

Uses test assertions and validation logic to assess control effectiveness and generate machine-readable SARs. Open risks and remediation plans are automatically tracked via dynamically generated Plans of Action and Milestones (POA&Ms), improving oversight and continuous monitoring.

Extensible APIs and Integration Hooks

Supports seamless integration with existing DevSecOps pipelines, security tools, GRC platforms, and incident response systems. This ensures compliance becomes a continuous, embedded process—not a disconnected, episodic activity.

SaaS Security Posture Management (SSPM) + OSCAL = Real-Time Assurance

With the proliferation of SaaS in federal environments, SaaS Security Posture Management (SSPM) has become a critical component of modern risk governance. SSPM tools monitor configuration drift, access policies, encryption settings, and compliance violations across applications like Microsoft 365, Salesforce, and ServiceNow.

But their output is often siloed and disconnected from RMF workflows. By integrating SSPM telemetry with OSCAL artifacts, we enable:

  • Real-time mapping of SSPM alerts to RMF controls
  • Evidence ingestion into SARs using validated control assertions
  • Dynamic POA&M generation when SSPM detects a misconfiguration
  • SaaS-specific OSCAL profiles that reduce redundancy in ATO packages

This fusion creates an architecture where SaaS posture data feeds directly into structured compliance reporting, reducing ATO maintenance time and improving control visibility.

The Future: AI-Augmented Compliance Pipelines

As OSCAL adoption grows, its potential goes beyond static reporting. It becomes the foundation for:

  • Policy-as-code enforcement using OSCAL profiles as executable control rules
  • Continuous ATO (cATO) through integrated SAR/SAP validation against live telemetry
  • Predictive compliance drift detection using AI trained on OSCAL-linked artifacts
  • LLM-assisted control authoring and assessment planning
     

ASSYST ComplySyncATO’s roadmap reflects this direction—leveraging AI to reduce workload, flag non-conformance, promote data standardization, and foster interoperability, all while keeping compliance synchronized. Comply.Sync.Now.

 

ASSYST Expands National Security Practice to Align with Evolving DHS Priorities

RAM PRASAD

RAM PRASAD
EVP – Business Solutions
2025-07-18

ASSYST has expanded its Homeland & National Security Practice with integrated capabilities designed to meet the complex and evolving needs of federal agencies responsible for national resilience, cybersecurity, border protection, and emergency response. This strategic growth supports key priorities for the US Department of Homeland Security (DHS) and its mission partners.

"As agencies prepare for an increasingly dynamic threat environment, there's a growing demand for secure, modular, and compliant technology that adapts to new mandates and integrates easily into mission systems. As a former law enforcement officer, I want to help agencies not just procure this technology, but fully utilize it to assist the boots on the ground," said Eugene Goldlust, Senior Account Executive at ASSYST.

Read More

Strengthening Digital Services for Military Families and the People Who Support Them

JOSEPH A. ANDERSON

JOSEPH A. ANDERSON
Chief Operating Officer
2025-07-14

We’ve spent decades supporting federal agencies as they work to improve the delivery of public services. We’ve learned that for military families, veterans, and the people who support them, technology should do one thing above all: make it easier to get the help they need.

That might mean finding the right information quickly, completing a process without frustration, or accessing support while balancing the many realities of military life. Behind every request is a person—often a spouse, a parent, or someone in transition—looking for stability and clarity.

We believe it’s time to make that experience better. Not by adding more systems or interfaces—but by making what already exists more connected, more dependable, and more thoughtful.

The Real Need

Military families move often. They navigate complex benefits, changing school systems, healthcare decisions, and job transitions. Veterans and caregivers face unique challenges. The programs that support them—from readiness and resilience to education and outreach—operate across various systems, policies, and timelines.

Technology can either help or hinder.

Our vision is to help agencies deliver digital tools and services that:

  • Reduce duplication and confusion
  • Respect the user’s time and circumstances
  • Support staff with the right data and context
  • Stay reliable during key life moments—deployment, relocation, transition

This isn't about innovation for its own sake. It’s about building systems that do their job, consistently and securely.

How We Support That Vision

ASSYST collaborates closely with federal agencies to modernize systems, enhance security, and improve service delivery. For programs focused on military communities, we focus on four priorities:

1. Design for Real Life

We take a human-centered approach—utilizing our knowledge of military family life to design experiences that are clear, inclusive, and accessible. That includes global integrated services design, mobile-first design, and interfaces that reduce cognitive burden rather than add to it.

2. Keep Data Protected, Always

We build and operate systems with a security-first mindset. From access controls to monitoring and compliance with federal frameworks, our goal is to help programs protect personal information while still allowing users to move forward with confidence.

3. Make Information Work Harder

As the First Place Winner of the GSA Federal AI Hackathon, we are continually seeking ways to make AI More Human-Friendly. We utilize AI and automation thoughtfully, focusing on helping people find answers, complete tasks, or receive guidance. Our Green Accelerator Platform supports workflows that surface useful insights and reduce manual processing, all while maintaining human oversight.

4. Support Program Agility

Policy and program requirements change. Our teams develop modular systems that can be updated without disruption, giving agencies flexibility without high rework or long lead times.

5. Bringing People and Programs Closer Together

We understand that successful service delivery doesn’t just support individuals—it strengthens the relationship between programs and the communities they serve.

We aim to close the gap between:

  • Military families and the services built for them
  • Program managers and the tools they rely on
  • Providers and the systems they access
  • CIOs and CISOs who must balance progress with protection

By enhancing the everyday experience of using and managing public systems, we enable agency teams to stay focused on their mission, rather than the technology.

We recognize that the responsibility of supporting military families extends beyond any single system. It requires listening, adjusting, and staying accountable.

ASSYST is ready to be a steady partner in that effort by building services that work, platforms that last, and relationships that reflect a shared commitment to the public good.

Insightful, Intentional, and Intelligent Cybersecurity

VINAY V. SHIRKE

VINAY V. SHIRKE
Chief Information Officer
2025-07-08
Security Data Lake

A Data-Driven, Design-Led, and Intelligence-Infused Approach for the Security Data Lake at HHS CMS

The Centers for Medicare & Medicaid Services (CMS) manages one of the largest digital infrastructures in the federal government—spanning hundreds of FISMA systems, cloud workloads, hybrid networks, and compliance environments. To safeguard this complex ecosystem, CMS partnered with ASSYST to implement a forward-thinking solution, a Security Data Lake (SDL). A Platform designed to unify Continuous Diagnostic and Mitigation (CDM) detailed cybersecurity telemetry from across the IT environment, enhancing threat intelligence and empowering real-time decision-making to improve the security posture of mission-critical applications. 

It was a transformation driven by data engineering, human-centered design (HCD), and the power of AI infused user experiences.

Challenge: Siloed Data, Slower Response

CMS’s security teams were overwhelmed by volumes of data generated by disparate sources—cloud configurations, vulnerability scans, firewall logs, compliance assessments, and more. Each team operated in silos, using their ingestion tools, dashboards, and data schemas. This fragmentation slowed collaboration, increased storage costs, and made cross-domain analysis nearly impossible.

During zero-day events like Log4J, what should have been a rapid response became a manual process of stitching together insights from different systems—costing critical time and adding risk to operations. CMS needed a unified, governed, and accessible data platform that could provide a view of CDM data to support multiple teams, roles, and missions—without compromising agility or security.

Solution: A Federated, AI-Ready Security Data Lake

ASSYST collaborated with CMS’s Information Security and Privacy Group (ISPG) to architect and operationalize a federated Security Data Lake platform built on Snowflake’s secure, FedRAMP-authorized Data Cloud. The platform centralized the ingestion of telemetry from AWS Config, Tenable, Snyk, Panther, Archer, and more, from both the cloud and the premise data center. Applying schema-on-read techniques to retain raw fidelity while enabling flexible, on-demand analytics.

We designed the SDL to support a multi-tenant access model featuring row-level security and role-based controls that enable different security units to collaborate securely from a shared source of truth. To support CMS’s modernization and automation goals, we integrated data services for metadata enrichment and cross-domain telemetry linking.

The AI-enabled platform is integrated with large language models (LLMs), predictive analytics, and multi-agent systems, which enhance context-driven decision-making, streamline investigations, and scale compliance readiness.

Human-Centered Design: Making Cyber Data Work for People

Recognizing that technology is only as valuable as it is usable, ASSYST adopted a Human-Centered Design (HCD) approach for data visualization of the CDM data. We developed detailed user personas to represent the diverse range of CMS stakeholders—from SOC analysts and vulnerability engineers to executive leadership and audit teams—each persona guided decisions regarding data access, dashboard views, chatbot behavior, and analytics priorities.

To unlock the full value of the SDL, we designed and deployed the Agentic AI App. This conversational, LLM-powered tool enables users to search and retrieve data catalog metadata using natural language queries. The Agentic AI app is capable of leveraging multiple UI patterns (linear, card-based, threaded) and selecting the threaded mode based on feedback from metadata users who require structured exploration paths and layered conversations. The UI integrates interactive components, such as buttons, forms, and menus, providing users with an intuitive, action-driven interface for discovering and utilizing cyber telemetry without requiring SQL knowledge to formulate queries.

Usability at Scale: Dashboards That Drive Action

Beyond search and metadata exploration, ASSYST focused on making data-driven decisions easier across CMS. Working closely with CMS stakeholders, we redesigned Tableau dashboards with HCD principles—streamlining visual layouts, reducing cognitive load, and improving data navigation across key views such as:

  • Vulnerability Monitoring Dashboard
  • Known Exploited Vulnerabilities (KEV)
  • Vulnerability-Related Asset Details

We facilitated user discovery sessions, journey mapping, and dashboard testing to ensure these dashboards not only reflected real-time SDL data but also aligned with user goals, workflows, and remediation processes. Special attention was given to login and landing page usability, with validated UX enhancements enabling faster access to alerts, insights, and reports.

These improvements have directly contributed to higher dashboard adoption across CMS, increased stakeholder satisfaction, and faster time-to-action in response to evolving cyber threats.

Value Delivered: From Insights to Outcomes

The results have been transformative. CMS now operates from a single pane of glass for security telemetry, with unified data access across departments, improved team collaboration, and sharply reduced response times. During major cyber events, queries that previously took days now return results in minutes. Compliance and audit preparation have become more efficient through the use of live telemetry overlays and the contextual mapping of NIST controls via AI Tools.

The Security Data Lake—once envisioned as a data warehouse—is now a living, AI-ready platform where data, design, and intelligence converge to drive mission success.

What’s Next: Agentic AI, Continuous Compliance, and Beyond

With the SDL in place, ASSYST is helping CMS prepare for its next leap forward: integrating Agentic AI. Using the Model Context Protocol (MCP), CMS will enable autonomous agents to interact with live data, perform security checks, validate configurations, and generate evidence for audits in real-time.

Through ASSYST’s Green Accelerator Framework, ASSYST is advancing toward a future where security operations are not only data-driven but context-aware, automated, and intelligently designed around the people who rely on them.

Supporting the Earth from the Cloud: Modernizing Digital Infrastructure for DoD's Outdoor Recreation Management

LOREN GRAY

Loren Gray
Program Manager
2025-07-08

Background 

In a rapidly advancing digital world, keeping your systems up to date with the latest technology has become essential for maintaining operational efficiency. If your digital infrastructure is currently behind the curve, keeping up with modern advancements will only become increasingly challenging. This was the challenge that three DoD customers faced before ASSYST partnered with a specialized Software-as-a-Service (SaaS) Solution Offering provider to offer them a modern solution to their organizational challenges.

Challenge

The National Guard units stationed at Fort Chaffee, Arkansas, and Fort McLellan, Alabama, as well as the Army Contracting Command – Rock Island (ACC-RI) at Pine Bluff Arsenal, Arkansas, were operating on an outdated and overly complex infrastructure that was needlessly relying on physical documentation. This significantly increased the time spent acquiring permits for outdoor recreational activities, such as hunting or fishing, and presented unnecessary challenges regarding the organization of these documents. These customers all requested the implementation of a web-based outdoor recreation management tool to minimize these issues and introduce a more modernized operation that utilizes current technologies.

Solution and Features

ASSYST partnered with RecAccess to support the implementation of their Cloud-based outdoor recreation management software, also called RecAccess, as a service to these three customers. The RecAccess SaaS is an online platform designed to support customers performing field work, such as the National Guard and ACC-RI. The platform is compliant with relevant standards, including FedRAMP and the Sikes Act, ensuring it operates in alignment with Federal initiatives that promote sustainability and wildlife conservation.

A central feature of the RecAccess SaaS is the issuance of permits and licenses for various recreational outdoor activities, enabling users to navigate to a single platform for all permit acquisition needs rather than requesting each permit separately. This is invaluable for streamlining and vastly accelerating the permit application process, as well as for enhancing organizational capabilities. While the primary function of RecAccess is issuing permits, multiple supporting services and features are available for implementation, such as a check-in/out system enabling users to report their attendance in designated recreation zones, an interactive mapping service, mobile phone and tablet compatibility, a variety of data management support services, and many others.

Value/Impact

ASSYST’s partnership with RecAccess and support in implementing the RecAccess SaaS has been transformative for the National Guard units in Fort Chaffee and Fort McLellan, as well as the ACC-RI at Pine Bluff Arsenal. The application modernization services we provided to these three DoD customers’ unit infrastructures showcase a simplified and robust method for permit management and storage. These highly successful implementations highlight the unique value of Cloud-based Software-as-a-Service offerings in providing support tailored to a customer’s specific needs and circumstances.

Qik Bits with Vijay Narasimhan, journey from the days of Mainframes to the advent of Agentic AI

TAYLOR RUSSELL

Taylor Russell
Media Specialist
2025-07-02

 

On today's Qik Bits, ASSYST's Vijay Narasimhan shares insights on shaping the journey from the days of Mainframes to the advent of Agentic AI

Watch on LinkedIn - https://www.linkedin.com/feed/update/urn:li:activity:7346175344942481408 

Promoting Digital Health Excellence: The eRx Conformance Program

TARUN SHRIVASTAVA

Tarun Shrivastava
Business Development Analyst
2025-06-25

The reliable and timely exchange of electronic prescription information is foundational to modern healthcare delivery, yet national consistency in implementing the NCPDP SCRIPT standard has remained a challenge. Variations in vendor interpretation, limited validation resources, and evolving regulatory requirements have created barriers to the uniform adoption of these standards. Recognizing this, the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology (ASTP/ONC - https://www.healthit.gov) launched the eRx Conformance Initiative, a targeted effort to operationalize and sustain a centralized testing platform that enables developers, implementers, and certifiers to assess conformance against SCRIPT specifications with precision and confidence. As a critical enabler of interoperability and medication safety, this initiative aligns with ONC’s broader mission to advance trustworthy, standards-based health IT infrastructure at scale.

Fragmentation in Standards Implementation

Despite the widespread adoption of electronic prescribing, consistent adherence to the NCPDP SCRIPT standard across the health IT ecosystem has proven difficult. Vendors often interpret implementation guides differently, resulting in variations in how transactions are structured and exchanged. This lack of uniformity complicates testing and certification, introduces inefficiencies, and increases the risk of communication errors between prescribers, pharmacies, and payers. Additionally, updates to the standard, such as changes to data elements, workflows, or schema, require careful coordination across technical teams and certification bodies. Before the eRx Conformance Initiative, there was no single, authoritative platform for systematically validating SCRIPT-based transactions in a repeatable, policy-aligned way. This gap presented a risk not only to program integrity but also to ONC’s long-term goal of enabling interoperable, standards-driven care coordination.

Establishing a Standards-Aligned Testing Platform

To close the gap between standards development and real-world implementation, ONC initiated a multi-year contract to design, build, and operate a conformance testing system dedicated to electronic prescribing. The goal was to provide a reliable and scalable platform that enables health IT developers, certifiers, and federal stakeholders to assess and validate the structure and behavior of transactions against the NCPDP SCRIPT standard. The platform would serve as a central point of reference, supporting iterative updates to the standard, promoting national alignment, and ultimately accelerating vendor readiness for certification and production deployment. In selecting ASSYST to lead this effort, ONC prioritized proven capability in standards-based development, agile delivery, and secure system design, all essential for building a sustainable, production-grade solution that could evolve alongside regulatory and industry needs. CMS adopted the NCPDP SCRIPT standard for e-prescribing and electronic prior authorization (ePA). Under the CMS‑4205‑F2 rule (published July 17, 2024), Upgrades from SCRIPT version 2017071 to 2023011 are required by January 1, 2028. SCRIPT covers prescription orders, history, and ePA messaging.

Scalable, Agile-Driven Conformance System

ASSYST approached the eRx Conformance Initiative with a structured, agile delivery model tailored to federal health IT standards and policy oversight. At the core of the effort was the development and maintenance of a modular testing environment capable of validating electronic prescribing transactions by the NCPDP SCRIPT standard, version 2023. The system architecture supports iterative testing workflows across development, staging, and production environments, enabling controlled release cycles and rapid integration of feedback.

Over the course of the engagement, ASSYST developed and upgraded more than three dozen XML-based test scripts, covering a comprehensive range of eRx use cases, including new prescriptions, prior authorizations, renewals, cancellations, and clinical messaging. Each script was supported by a fully documented test case set, including test stories, data specifications, example messages, and expected results. These assets were mapped to acceptance criteria and tracked using integrated tools, such as JIRA and Confluence, providing transparency and traceability across all sprints.

The team also implemented continuous engagement with ONC’s technical leadership, reviewed and responded to user inquiries from the broader implementation community, and maintained rigorous compliance with federal IT quality standards by drawing practices from CMMI Level 3 and ISO 9001, 20000, and 27001 certifications.

Enabling Futureproof Standards-Based ePrescribing

The eRx Conformance Testing Platform has become a key asset in ONC’s broader strategy to drive interoperability and improve safety across the prescription drug ecosystem. By providing a centralized, standards-aligned environment for SCRIPT validation, the initiative enables health IT developers to test and refine their systems with greater speed, accuracy, and assurance long before they reach the certification or production stage.

This has led to measurable improvements in implementation consistency, reduced testing burden, and stronger alignment between policy goals and real-world technology behavior. The platform also provides federal stakeholders, including certification bodies and standards organizations, with a reliable tool to support compliance monitoring and future policy enforcement.

For the end user, whether a prescriber, pharmacy, or patient, the downstream impact is clearer communication, fewer transaction errors, and faster access to medication. By strengthening the technical foundation of e-prescribing, this initiative supports a safer and more coordinated healthcare experience for millions of Americans.

Empowering Financial Agility: AI-Driven Debt Management Modernization for the US Federal Agency

JOHN KIMBERL

E10
Business Development Specialist
2025-06-25
Background 

The U.S. Department of Health and Human Services (HHS) Program Support Center (PSC) provides centralized financial management services to multiple federal agencies, including the Administration for Children and Families (ACF), Centers for Disease Control and Prevention (CDC), Food and Drug Administration (FDA), and National Institutes of Health (NIH). A critical component of this support is the Debt Management System (DMS), which enables PSC to track, manage, and collect debts tied to federal grant programs and financial obligations.

Originally developed on legacy infrastructure, DMS had become inflexible, relying on paper-based workflows that introduced inefficiencies, limited visibility, and increased compliance risks. PSC partnered with ASSYST to reimagine DMS as a cloud-native, AI-enabled, secure shared services platform capable of meeting the evolving needs of multiple agencies while delivering consistent, high-quality user experiences.

Challenges 

PSC’s modernization goals were shaped by the following challenges common to legacy federal financial systems:

  • Legacy Technical Debt: Outdated codebases and unsupported components hindered improvements and introduced security risks.
  • Manual Processes: Labor-intensive workflows caused data errors and slowed down processing.
  • Siloed Systems: Limited interoperability, restricted real-time visibility, and accurate cross-agency reporting.
  • Lack of Predictive Intelligence: The system was unable to support risk scoring, delinquency tracking, or automated payment plans.
  • Scalability and Mobility Gaps: The platform was unable to scale with demand or support remote and mobile users.
  • Rising Cybersecurity Mandates: DMS needed to comply with stringent requirements such as FedRAMP, FISMA, and NIST.

These multifaceted issues underscore the need for a scalable, secure, and intelligent platform.

Solution

ASSYST implemented a comprehensive modernization strategy centered on agile delivery, cloud-native infrastructure, and AI-powered automation:

  • Agile and Human-Centered Design: A Dedicated Scrum team collaborated with PSC stakeholders through iterative sprints. Using user personas and journey maps, ASSYST designed a responsive and accessible UI tailored to debtors, auditors, program staff, and financial portfolio managers. Features were prioritized based on value and complexity, ensuring the timely delivery of mission-critical capabilities within a 12-month timeframe.
  • Cloud and Infrastructure Modernization: The legacy DMS was migrated to a secure AWS environment. Dedicated cloud environments were provisioned for development, staging, and validation, with the application deployed using Angular for the frontend and Node.js for the backend. Built on a microservices architecture and containerized using Docker, the solution leveraged custom Kubernetes clusters on Amazon EC2 instances, utilizing kOps for orchestration. This enabled rapid scalability and modular enhancements. RESTful APIs facilitated integration with payment processors and mission-critical systems. A fail-safe, automated cutover plan ensured zero downtime during the transition.
  • DevSecOps and CI/CD: A comprehensive DevSecOps pipeline was implemented using Jenkins, AWS CodeCommit, and SonarQube, integrating static code analysis, security scans (OWASP), and compliance checks into each sprint cycle. The CI/CD process automates build, test, and deployment across Kubernetes clusters running on EC2 instances in the DEV, STAGING, and VALIDATION environments, all managed via kOps. Docker images were built and stored in Amazon ECR, then deployed as pods within the Kubernetes clusters. Access control was using AWS IAM, with secure VPC peering connecting all isolated environments. Secrets and credentials were managed through AWS Secrets Manager, while centralized monitoring and alerting ensured operational visibility and system health across all stages of the deployment pipeline.
  • AI and Intelligent Automation: AI/ML models were integrated to make predictions and extract text from debt documents, and the Automation of the new debt creation process was achieved through an integrated, trained language model. Automated services handled repetitive tasks such as debt record imports and workflow initiation, reducing manual errors and increasing processing speed.
  • Advanced Analytics: Developed interactive, high-performance reports in AG-Grid and MySQL, designed to handle large datasets efficiently, and offered a wide range of features to visualize and manage tabular data that were accessible via role-based dashboards.
     
Results 

The modernized DMS platform has delivered a measurable impact:

  • Scalable Shared Services: Supports onboarding of new agencies and increasing data volumes without degradation.
  • Real-Time Financial Visibility: Live dashboards allow agencies to optimize strategies based on current conditions.
  • User-Centric Access: Mobile-ready self-service portals streamline workflows and improve stakeholder satisfaction.
  • Strengthened Security and Compliance: Automated controls and continuous monitoring ensure adherence to federal mandates.
  • Resource Optimization: Automation of routine tasks reduces operational overhead and boosts productivity.
  • Enhanced Interoperability: Secure, role-based multi-agency access fosters collaboration while maintaining data separation.

Sustaining Growth and Innovation

The platform modernization delivered by ASSYST provides PSC with the agility to evolve with future demands. With cloud-native flexibility, AI-enabled automation, and continuous delivery pipelines, PSC is equipped to onboard new debt programs, meet changing regulatory mandates, and deliver greater transparency in debt management.

ASSYST’s solution has empowered PSC with the tools, architecture, and operational model to sustain and scale the DMS platform as a strategic shared service, enabling data-driven decision-making and long-term mission success.

Designing for Global Impact: Human-Centered Innovation Supporting Diplomacy and Security

DIEGO WHITE

Diego white
Business Development Analyst
2025-06-22

Background

The Congressional Office for International Leadership (COIL) leads a vital international exchange program that builds meaningful civic and political relationships with global leaders. These person-to-person connections enhance U.S. national security by fostering mutual understanding, promoting democratic values, and cultivating long-term cooperation with foreign counterparts. COIL’s mission hinges on encouraging global engagement through dialogue, diplomacy, and shared civic experiences.

However, the organization's ability to scale its international outreach and fulfill its national security-oriented mandate was constrained by a legacy public-facing website. Built on an outdated content management system, the platform lacked responsiveness, accessibility, and ease of maintenance, ultimately hindering COIL’s ability to engage effectively with delegates, hosts, and stakeholders worldwide.

Challenge

To maintain its leadership in international exchange and support its strategic role in advancing American national security interests, COIL needed a modernized digital platform. The legacy website was not only visually outdated but structurally inflexible, limiting the team’s ability to update content, share program impact, and expand its global network of participants and partners. The new platform had to be secure, accessible across devices, intuitively designed, and aligned with federal digital and public diplomacy goals.

Solution

ASSYST partnered with COIL to lead a full-scale redesign and migration of OpenWorld.gov. The goal was to deliver a responsive, accessible, secure, and user-centered web platform that supported seamless global outreach and streamlined internal workflows. We began with a comprehensive assessment of the legacy system and conducted a structured migration of content and media assets to a secure and scalable Drupal environment. The new platform was developed using mobile-first, accessible design principles and validated through rigorous integration and user acceptance testing. Notably, the project was delivered two months ahead of schedule, allowing COIL to accelerate its public engagement efforts.

Security and content governance were core pillars of the redesign. The solution incorporated HTTPS enforcement, secure authentication, and role-based access control to safeguard site content and user data. Editorial workflows were implemented to support draft-review-publish cycles, ensuring only authorized users could publish content. ASSYST also provided tailored training to COIL staff, equipping them to manage content updates, monitor analytics, and maintain platform integrity without external support.

The new OpenWorld.gov reflects a Human-Centered Design (HCD) methodology, featuring a user-first interface optimized for seamless experiences across mobile, tablet, and desktop devices. The homepage highlights upcoming programs, stories of impact, and key updates. Content sections, such as “For Delegates” and “Host an Event,” were reorganized to prioritize ease of access. Enhanced search and filter tools now enable users to locate events, grant opportunities, and country-specific information with greater ease and intuitiveness.

Features

  • Human-Centered Design (HCD):
    The site was designed around user journeys and audience personas, ensuring an intuitive layout, visual clarity, and accessibility. Strategic spacing, scalable typography, and prominent navigation elements guide users naturally through the site, providing a seamless user experience. SEO-friendly URLs, implemented via Drupal’s URL Alias, improve content discoverability, while embedded feedback tools encourage interaction.
  • Interactive Global Maps:
    The site features dynamic, data-rich maps that display COIL’s international footprint, including participants by country, years of engagement, and thematic areas, visually communicating its global impact and transparency.
  • Accessibility & Responsive Design:
    Fully responsive across devices and tested for Section 508 compliance, the site includes a COIL Resource Center offering downloadable, open-source materials in various formats (articles, videos, voice recordings) to serve diverse user needs.
  • Engagement & Social Tools:
    Content libraries, video embeds, and commenting and rating features enhance user interaction. Social media integration (LinkedIn, Instagram, Facebook, YouTube, Twitter) ensures COIL’s mission is continuously shared across platforms.
  • Security & Access Control:
    The platform enforces HTTPS protocols and includes role-based permissions to manage access for contributors, editors, and administrators, ensuring a secure environment for publishing and platform management.
  • Content Workflow & Editorial Management:
    Integrated workflows allow content to progress through drafting, review, and approval stages before publication. Revision history, version control, and content scheduling further support transparency and accountability.
  • Performance & Scalability:
    Leveraging Drupal Cache API and Memcached, the site delivers high-speed performance, even under heavy traffic. These tools reduce load times, improve reliability, and ensure scalability for future growth.
  • Streamlined Content Management & Training Support:
    A role-based publisher dashboard empowers non-technical users to manage content, update pages, and perform administrative tasks, including archiving, user management, and uploading media. ASSYST delivered tailored training sessions and support documentation to help COIL staff confidently maintain and evolve the site independently.

Value

The solution delivered by ASSYST offers long-term value in three key areas:

  1. Enhanced Outreach Capabilities – The platform empowers COIL to reach international audiences more effectively with targeted content, timely updates, and intuitive tools.
  2. Operational Efficiency & Security – Administrative burden was reduced through streamlined publishing tools and editorial workflows, while secure access controls ensure platform integrity.
  3. Strategic Alignment – The new platform complies with federal digital, accessibility, and security mandates, while also future-proofing COIL’s digital infrastructure.

These capabilities position COIL to continually amplify its global mission with agility, consistency, and confidence.

Impact

Since launch, COIL’s new website has seen measurable improvements in user engagement, including increased session duration, return visits, and page views. These indicators demonstrate the effectiveness of intuitive design and accessible content in fostering deeper user interaction. The responsive design and enhanced workflows now ensure broader inclusivity and streamlined content management. Most importantly, the platform now serves as a digital ambassador, extending COIL’s diplomatic voice and storytelling capabilities to a global audience. Through this modernization effort, COIL has enhanced its capacity to establish and maintain positive relationships with civic and political leaders, thereby advancing the real-world outcomes of its mission.

Enabling Army Aviation’s Future Force Through Agile and Integrated System Modernization

LOREN GRAY

Loren Gray
Program Manager
2025-06-17

Background

The US Army Aviation Center of Excellence’s (USAACE) Mission Command Arts and Sciences Program (MCASP) initiative at Fort Novosel, Alabama, supports the Army’s Mission Command Training Strategy (MCTS) and Mission Command Training Strategy Implementation Plan (MCTSIP). MCASP supports Mission Command training for Professional Military Education (PME) and Initial Military Training (IMT) classes in various Officer, Warrant Officer, and Noncommissioned Officer Courses, in the interest of fostering a highly skilled professional military body. 

The USAACE required overarching support for their advanced Army Mission Command System (AMCS) simulation and stimulation training systems. These systems were critical exercises for ensuring MCASP students were fully capable of operating effectively in a combat environment. The ASSYST team provided highly multifaceted IT support services to USAACE’s MCASP at Fort Novosel for almost 11 years, supporting the program’s mission to conduct simulation training and practical exercises, develop advanced Mission Command simulation training systems, and create products for IMT and PME. 

Solution

ASSYST deployed a team to support the configuration, integration, design, delivery, execution, and maintenance of Army Mission Command System (AMCS) simulation training for IMT and PME. We expertly managed and delivered network support, maintenance, and upgrades for digital Tactical Operations Centers (TOC) Mission Command systems, servers, components, and other simulation and stimulation assets as required to ensure operational AMCS training network support.  

Additionally, ASSYST provided comprehensive support for AMCS components tied to the MCASP instruction. We managed the integration, configuration, cybersecurity, and maintenance of various AMCS simulation and stimulation hardware and software platforms. We supported the virtualization of synthetic battlefield environments at designated USAACE Enterprise Classroom Programs (ECPs). Updates to training curriculum, lesson plans, and Programs of Instruction were also regularly reviewed, updated, and certified as needed.

Additional Support

Hands-On Mentoring: In addition to providing support through software and system engineering, ASSYST delivered direct ECP instruction and over-the-shoulder mentor training support to personnel for operations, user maintenance, and training network configuration, which included, but was not limited to, various systems. ASSYST’s MCASP instructors provided the expertise needed to guide students to success.

Ensuring Regulatory Compliance: Upon ASSYST’s contract award of the MCASP program, the Tactical Training Network (TTN) was an unaccredited standalone network. Government regulations required that the TTN undergo formal accreditation. During the 11 years we held the contract, we transformed the TTN from being unaccredited to achieving one DOD Information Assurance Certification and Accreditation Process (DIACAP) accreditation and two DoD Risk Management Framework (RMF) accreditations. ASSYST implemented Host-Based SQL Server (HBSS) and applied the necessary Security Technical Implementation Guides (STIGs) associated with it to achieve compliance. After DIACAP was formally discontinued in May 2015 and replaced by the DoD Risk Management Framework (RMF), we transitioned seamlessly to RMF, maintaining full compliance throughout the TTN with updated assessments, documentation, and control implementation.

Our team also designed and implemented the necessary documentation and Standard Operating Procedures (SOPs) to obtain and maintain the network's Authority to Operate (ATO). ASSYST’s team performed testing, system audits, and remediation efforts to ensure that we met Army Portfolio Management System (APMS) and Enterprise Mission Assurance Support Services (eMASS) requirements.

Value/Impact

Through a combination of system enhancement and hands-on training support, we empowered MCASP to achieve its desired outcomes more efficiently. ASSYST’s services were crucial to ensuring MCASP students understood how the AMCS supported Army Aviation in decision-making, especially in combat environments, utilizing the Military Decision-Making Process (MDMP) and the Rapid Decision-Making Process (RDMP). 

 

 

Pagination

  • First page « First
  • Previous page ‹ Previous
  • …
  • Page 6
  • Page 7
  • …
  • Next page Next ›
  • Last page Last »

CORPORATE

22866 Shaw Road
Sterling, VA 20166
Phone: 703-230-3100
Fax: 703-230-3100
e-mail: info@assyst.net

OTHER OFFICES

7000 Security Boulevard, Suite 120
Baltimore MD 21244
Phone: 443-200-5387

FOLLOW US

facebook linkedin twitter

TALK TO US

Image CAPTCHA
Get new captcha!
Enter the characters shown in the image.
Clicky
Footer menu
  • Terms of Use
  • Accessibility
  • Privacy Statement
CMMC 2.0 CMMI Level 3 ISO 9001 ISO 20000 ISO 27001 © All Rights Reserved.