Compliance with information security frameworks, such as the Cloud Control Matrix (CCM), is increasingly essential for many companies. Depending on an organization’s specific context, multiple frameworks may be relevant, requiring the identification and harmonization of similar requirements across standards. As frameworks evolve over time, continuous efforts from domain experts or the use of automated solutions are necessary. However, automatically identifying and matching information security requirements remains a complex task in the field of natural language processing. To support this claim, we evaluate the performance of state-of-the-art large language models on cloud security requirements. We also conduct a qualitative analysis of the specific challenges that arise when identifying similar requirements, providing a deeper, data-centric understanding of the matching difficulties. With this dual perspective, we contribute to the field of matching similar information security requirements and discuss implications for both AI systems and human analysts.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Efficacy of Large Language Models in Mapping Cloud Security Requirements: A Data-Centric View

  • Stefan Hirschmeier,
  • Markus Hirschmeier,
  • Andreas Giersch

摘要

Compliance with information security frameworks, such as the Cloud Control Matrix (CCM), is increasingly essential for many companies. Depending on an organization’s specific context, multiple frameworks may be relevant, requiring the identification and harmonization of similar requirements across standards. As frameworks evolve over time, continuous efforts from domain experts or the use of automated solutions are necessary. However, automatically identifying and matching information security requirements remains a complex task in the field of natural language processing. To support this claim, we evaluate the performance of state-of-the-art large language models on cloud security requirements. We also conduct a qualitative analysis of the specific challenges that arise when identifying similar requirements, providing a deeper, data-centric understanding of the matching difficulties. With this dual perspective, we contribute to the field of matching similar information security requirements and discuss implications for both AI systems and human analysts.