用大模型自动生成符合乌克兰法规的安全配置,降低人工出错风险。
Towards the Development of an LLM-Based Methodology for Automated Security Profiling in Compliance with Ukrainian Cybersecurity Regulations
- 用大模型+检索增强生成,自动匹配法规与组织策略
- 减少人工操作复杂度,确保技术措施与法律要求一致
- 适合面临高强度混合威胁的合规管理场景
近年来,各领域信息技术发展迅速,迫使网络安全专家不断审查现有流程以防止未经授权访问敏感信息。本文以乌克兰为典型案例,探讨将国际最佳实践(如ISO/IEC 27001和NIST网络安全框架)融入国家监管体系的过程。重点研究从传统合规模式向基于风险的方法转型,体现于乌克兰最新规范文件的采纳。此外,本文提出一种基于大语言模型(LLM)并结合检索增强生成(RAG)的自动化安全配置开发方法。通过集成国家法规与组织政策的向量数据库,该RAG驱动的顾问系统降低了人工复杂性,减少了人为错误,并确保技术控制与法律要求对齐。本研究为高强度混合威胁环境下的人工智能辅助网络安全管理提供了结构化工作流。
原文摘要 · Abstract (English)
In recent years, the pace of development of information technology in various areas has increased drastically, forcing cybersecurity specialists to constantly review existing processes in order to prevent unauthorized access to confidential information. Using Ukraine as a primary case study, this paper explores the integration of international best practices, specifically ISO/IEC 27001 and the NIST Cybersecurity Framework, into national regulatory systems. A focus is placed on the transition from traditional compliance models to risk-based approaches, exemplified by the recent adoption of the Ukrainian normative documents. Furthermore, we propose a methodology for automating the development of target security profiles using Large Language Models (LLMs) enhanced by RetrievalAugmented Generation (RAG). By integrating a vector database of national regulations and organizational policies, the proposed RAG-based advisor reduces manual complexity, minimizes human error, and ensures alignment between technical controls and legal requirements. This study contributes to the field by providing a structured workflow for AI-assisted cybersecurity management in environments characterized by high-intensity hybrid threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。