Table 7.

Future research agenda

TimelineDescriptionConcrete examples across ISP levels
Short term (1–2 years)Exploratory research aimed at mapping AI-related phenomena in ISP management, defining key concepts and identifying feasible AI applications while examining how stakeholders interpret and engage with AI-supported ISP activitiesStrategic level: AI-assisted interpretation of regulations (e.g. NIS2) to support managerial sensemaking and prioritization of long-term security goals
Operational level: Using LLMs to restructure ISP documents into clearer and more readable formats, enabling employees to better understand ISP expectations
Technical level: Exploring the feasibility of translating operational ISP requirements into technical suggestions while maintaining human oversight in system configuration decisions
Mid-term (3–4 years)Development and evaluation of AI software prototypes supporting ISP management activities, with emphasis on human–AI collaboration, decision support and organizational adoption rather than full automationStrategic level: Prototyping AI software systems that assist information security managers in developing strategic ISP frameworks from regulatory inputs, supporting informed human decision-making
Operational level: AI-assisted generation of role-based ISPs and analysis of compliance deviations to support role-specific policy guidance and training strategies
Technical level: Testing AI-supported continuous alignment between ISP requirements and technical controls, while examining how administrators interact with and validate automated recommendations
Long-term (4+ years)Longitudinal and comparative studies assessing the sustained organizational impact of AI-supported ISP management, including governance quality, policy adoption and system effectiveness over timeStrategic level: Evaluating whether AI-supported ISP frameworks influence governance practices, regulatory alignment and long-term security culture compared to human-designed strategies
Operational level: Longitudinal assessment of whether AI-assisted ISP documents improve continued policy engagement, adoption and compliance, across organizational contexts
Technical level: Benchmarking AI-generated technical ISPs against manually crafted controls in terms of system effectiveness, resilience and security outcomes
Source(s): Created by authors

or Create an Account

Close subscription notice
Close access options