错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Impact of Artificial Intelligence on Enterprise Information Security Management in the Context of ISO 27001 and 27002: A Tertiary Systematic Review and Comparative Analysis

  • Heiko Kreutz,
  • Hamid Jahankhani

摘要

The use of Artificial Intelligence (AI) by enterprises has dramatically increased over the last decade and is estimated to accelerate further. This research aimed to identify, which impact AI will have on enterprise information security and how to address this in the context of the widely used security standards ISO 27001 and 27002. Guided by AI security aspects relating to AI enhanced cyber attacks, AI enhanced cyber defences, attacks against AI systems, AI malfunctions and AI human and societal impact, combined with the context of governance and regulations and additional dimensions of risk management and quantum computing, a systematic literature review was conducted to find current AI security challenges and defences, which were then comparatively analysed with ISO 27001/27002 controls. The results of this analysis confirmed, that existing ISO 27001 ISMS and security controls were not sufficient to address the emerging AI security challenges. To improve this lack of adequate security controls, six new security controls and ten modified existing security controls were proposed.