Table 5.

Overview of ISP management research that have addressed or used AI

StudyISP phaseISP levelAddressing AIUsing AIEmpirical domainResearch methodStudy aim
Kruger et al. (2020) MonitoringOperationalUses deep learning to classify emotional sentiment from facial expressionsNot specified (general organizational setting)ExperimentTo acquire unbiased feedback on employees’ sentiment toward ISPs using affective computing
Jawhar et al. (2024) ConstructionStrategicUses GPT-4 via API to generate ISP documents tailored to standard frameworksPrivate sector (small business – real estate)Design science researchTo automate the generation of ISPs using AI in compliance with standards like NIST and ISO
Cappellozza et al. (2022) ComplianceOperationalUses AI neural networks (alongside SEM) to analyze the data to predict intention to violate ISPsMixed organizational workers in São Paulo, BrazilSurveyTo investigate how individual factors (e.g. moral disengagement, penalties, turnover) affect intent to violate ISPs
Kang et al. (2022) ConstructionAll Three levelsUses machine learning (GP, VSS, DTW) for log-based benchmarking to inform ISP designIT and communications industryExperimentTo construct tailored ISPs by benchmarking organizations using AI-powered analysis of information security management systems logs
Frank and Ranft (2021) ComplianceOperationalSupervised machine learning (e.g. C5.0, random forest) to classify employees based on likelihood to perform extra-role security behaviorsLarge international pharmaceutical companyExperimentTo identify contextual factors (e.g. training, salary, helpdesk reliance) that predict which employees are likely to report phishing emails – actions that support ISP goals beyond formal compliance
Source(s): Created by authors

or Create an Account

Close subscription notice
Close access options