Impact of Artificial Intelligence on Enterprise Information Security Management in the Context of ISO 27001 and 27002: A Tertiary Systematic Review and Comparative Analysis
摘要
The use of Artificial Intelligence (AI) by enterprises has dramatically increased over the last decade and is estimated to accelerate further. This research aimed to identify, which impact AI will have on enterprise information security and how to address this in the context of the widely used security standards ISO 27001 and 27002. Guided by AI security aspects relating to AI enhanced cyber attacks, AI enhanced cyber defences, attacks against AI systems, AI malfunctions and AI human and societal impact, combined with the context of governance and regulations and additional dimensions of risk management and quantum computing, a systematic literature review was conducted to find current AI security challenges and defences, which were then comparatively analysed with ISO 27001/27002 controls. The results of this analysis confirmed, that existing ISO 27001 ISMS and security controls were not sufficient to address the emerging AI security challenges. To improve this lack of adequate security controls, six new security controls and ten modified existing security controls were proposed.