Future research agenda
| Timeline | Description | Concrete examples across ISP levels |
|---|---|---|
| Short term (1–2 years) | Exploratory research aimed at mapping AI-related phenomena in ISP management, defining key concepts and identifying feasible AI applications while examining how stakeholders interpret and engage with AI-supported ISP activities | Strategic level: AI-assisted interpretation of regulations (e.g. NIS2) to support managerial sensemaking and prioritization of long-term security goals |
| Operational level: Using LLMs to restructure ISP documents into clearer and more readable formats, enabling employees to better understand ISP expectations | ||
| Technical level: Exploring the feasibility of translating operational ISP requirements into technical suggestions while maintaining human oversight in system configuration decisions | ||
| Mid-term (3–4 years) | Development and evaluation of AI software prototypes supporting ISP management activities, with emphasis on human–AI collaboration, decision support and organizational adoption rather than full automation | Strategic level: Prototyping AI software systems that assist information security managers in developing strategic ISP frameworks from regulatory inputs, supporting informed human decision-making |
| Operational level: AI-assisted generation of role-based ISPs and analysis of compliance deviations to support role-specific policy guidance and training strategies | ||
| Technical level: Testing AI-supported continuous alignment between ISP requirements and technical controls, while examining how administrators interact with and validate automated recommendations | ||
| Long-term (4+ years) | Longitudinal and comparative studies assessing the sustained organizational impact of AI-supported ISP management, including governance quality, policy adoption and system effectiveness over time | Strategic level: Evaluating whether AI-supported ISP frameworks influence governance practices, regulatory alignment and long-term security culture compared to human-designed strategies |
| Operational level: Longitudinal assessment of whether AI-assisted ISP documents improve continued policy engagement, adoption and compliance, across organizational contexts | ||
| Technical level: Benchmarking AI-generated technical ISPs against manually crafted controls in terms of system effectiveness, resilience and security outcomes |
| Timeline | Description | Concrete examples across |
|---|---|---|
| Short term (1–2 years) | Exploratory research aimed at mapping AI-related phenomena in | |
| Mid-term (3–4 years) | Development and evaluation of | |
| Long-term (4+ years) | Longitudinal and comparative studies assessing the sustained organizational impact of AI-supported | |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.