Cookies on this website

We use cookies to ensure that we give you the best experience on our website. If you click 'Accept all cookies' we'll assume that you are happy to receive all cookies and you won't see this message again. If you click 'Reject all non-essential cookies' only necessary cookies providing core functionality such as security, network management, and accessibility will be enabled. Click 'Find out more' for information on how to change your cookie settings.

This position paper proposes the use of Large Language Models (LLMs) to evaluate the compliance of cybersecurity controls with organisational policies. We high-light the challenges related to efficiency, accuracy, and coverage associated with conventional compliance approaches and discuss how LLMs can address these issues. Additionally, we emphasise that organisational events and data can provide insightful evidence to measure true cybersecurity compliance value, rather than relying solely on documentary evidence. We develop our position by exploring current research directions in the use of LLMs within cybersecurity and demonstrating how their capability to assimilate and analyse unstructured data can be leveraged to provide a comprehensive compliance assessment for organisations. We present our research agenda to investigate this hypothesis and outline a comprehensive roadmap for studying the utility of LLMs in cybersecurity compliance.

Original publication

DOI

10.1109/EuroSPW61312.2024.00061

Type

Publication Date

01/01/2024

Pages

496 - 503