Context: For the protection of information assets and following laws and agreements, information security risk management is very important for the organization. Considering the existing ways of dealing with it are mainly dependent on human analysis and professionals experience. Security-related data that is mostly unstructured data, such as reports on incidents, audit results, policy papers, and system logs, is created because of digital infrastructures, and using traditional risk assessment methods makes it very difficult to meet the requirements of quality and complexity. It has now become very easy to get structured information from unstructured text because of the new developments in AI, especially in natural language processing and large language models (LLMs).
Still, there are additional issues that need to be thought about when using AI based LLMs in information security risk management. These include bad data, model bias, being able to explain things, integrating with current governance, risk, and compliance (GRC) frameworks, and keeping private corporate data safe.
Method: This report is a systematic literature review based on PRISMA 2020 guideline of peer-reviewed studies that look into how AI based methods mainly focusing on LLM-based methods are used to turn unstructured data about security into structured data that can be used for assessing information security risk, as well as how problems with integrating these methods with GRC processes are dealt with.
In the report, academic libraries such as Scopus, IEEE Xplore, ScienceDirect, and AMC DL to find, screen, and put together relevant work on how AI can be used to find risks, analyze and rate them, choose controls, and keep checks on them. Many studies indicate that AI based methods specifically LLMs approaches can help with different parts of the risk management lifecycle, such as finding weaknesses and threats, ranking the incidents on the basis of severity, linking data to the risk registers, and making comments about risk, but there is still limitations when trying to integrate into frameworks like ISO/IEC 27005 and NIST SP 800-30.
Moreover, for enhancing the explainability, decreasing the bias, and increasing the privacy of AI outputs, there are researches which provide different methods. But for maintaining accountability and transparency, it lacks developed methods to embed these into formal Governance, Risk, and Compliance (GRC) workflows.
This report identifies major research gaps and proposes future research areas for the utilization of AI-based solutions in corporate information security risk management, assuring safety, rationality, and legal compliance.