Overview of ISP management research that have addressed or used AI
| Study | ISP phase | ISP level | Addressing AI | Using AI | Empirical domain | Research method | Study aim |
|---|---|---|---|---|---|---|---|
| Kruger et al. (2020) | Monitoring | Operational | Uses deep learning to classify emotional sentiment from facial expressions | – | Not specified (general organizational setting) | Experiment | To acquire unbiased feedback on employees’ sentiment toward ISPs using affective computing |
| Jawhar et al. (2024) | Construction | Strategic | Uses GPT-4 via API to generate ISP documents tailored to standard frameworks | – | Private sector (small business – real estate) | Design science research | To automate the generation of ISPs using AI in compliance with standards like NIST and ISO |
| Cappellozza et al. (2022) | Compliance | Operational | – | Uses AI neural networks (alongside SEM) to analyze the data to predict intention to violate ISPs | Mixed organizational workers in São Paulo, Brazil | Survey | To investigate how individual factors (e.g. moral disengagement, penalties, turnover) affect intent to violate ISPs |
| Kang et al. (2022) | Construction | All Three levels | Uses machine learning (GP, VSS, DTW) for log-based benchmarking to inform ISP design | – | IT and communications industry | Experiment | To construct tailored ISPs by benchmarking organizations using AI-powered analysis of information security management systems logs |
| Frank and Ranft (2021) | Compliance | Operational | Supervised machine learning (e.g. C5.0, random forest) to classify employees based on likelihood to perform extra-role security behaviors | – | Large international pharmaceutical company | Experiment | To identify contextual factors (e.g. training, salary, helpdesk reliance) that predict which employees are likely to report phishing emails – actions that support ISP goals beyond formal compliance |
| Study | Addressing | Using | Empirical domain | Research method | Study aim | ||
|---|---|---|---|---|---|---|---|
| Monitoring | Operational | Uses deep learning to classify emotional sentiment from facial expressions | – | Not specified (general organizational setting) | Experiment | To acquire unbiased feedback on employees’ sentiment toward ISPs using affective computing | |
| Construction | Strategic | Uses GPT-4 via | – | Private sector (small business – real estate) | Design science research | To automate the generation of ISPs using | |
| Compliance | Operational | – | Uses | Mixed organizational workers in São Paulo, Brazil | Survey | To investigate how individual factors (e.g. moral disengagement, penalties, turnover) affect intent to violate ISPs | |
| Construction | All Three levels | Uses machine learning (GP, VSS, | – | Experiment | To construct tailored ISPs by benchmarking organizations using AI-powered analysis of information security management systems logs | ||
| Compliance | Operational | Supervised machine learning (e.g. C5.0, random forest) to classify employees based on likelihood to perform extra-role security behaviors | – | Large international pharmaceutical company | Experiment | To identify contextual factors (e.g. training, salary, helpdesk reliance) that predict which employees are likely to report phishing emails – actions that support |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.