GenAI: Assessing Risk and Compliance
Frameworks upon which you can build amazing structures. Created by the Wonder AI app on iOS.

GenAI: Assessing Risk and Compliance

Welcome to the fourth installment in this series. ?Hopefully you have enjoyed reading this as much as I have enjoyed writing it.???

?

In the first article we covered what Artificial Intelligence (AI), Machine Learning (ML), and GenAI are and what some of the key capabilities GenAI brings to the table.?? The second article dove into the different ways that GenAI can enhance our capabilities in detecting threats in our environments.? As a reminder, those capabilities are large scale data analysis, pattern recognition, anomaly detection, contextual understanding, predictive capabilities, and continuous learning.?? Article three switched to incident response and how GenAI can enhance our capabilities there.? In this fourth article, we take on the role that GenAI can fill in how we manage and assess risk and maintain compliance.?

?

The capabilities we discussed as being beneficial to Threat Detection and Incident Response, again come into play as we take on the role of assessing and managing risk.? ?GenAI can analyze large datasets to detect patterns, trends, and any anomalies.? ?Each of these can be scored giving us a better perspective into the risk inherent in our environments.?? Couple this analysis with GenAI’s contextual understanding and predictive capabilities and we have the right data upon which we can have informed discussions on risk.? We can decide which risk is acceptable to carry and which risks need to be addressed and the priority for each.? ?

?

Beyond simply identifying and prioritizing risks, GenAI can go one step further and, if trained properly, can recommend appropriate mitigation strategies beyond the simple, patch the system recommendation.??

?

As GenAI can be trained to understand the context of the risk situation, it will know where each risk sits in the environment.? It can then examine the existence of compensating controls to determine if they are sufficient to mitigate individual risks.? If it finds that these compensating controls are not adequate, it can recommend changes or additions that will reduce one or more risks to acceptable levels.? ?It is a bit like having the high dollar consultants from the big firms on speed dial except you don’t have to pay them exorbitant fees.?

?

Additionally, GenAI can continuously analyze and monitor your environments to track remediation efforts and automatically generate detailed risk reports.?? These reports can also be at different levels of details with the most details being included in technical reports for technical individuals and executive level summaries for executives.?

?

These reports are a good segway into how GenAI can help us maintain regulatory compliance.? ?The ability of GenAI to actively monitor and report on our compliance support our responsibilities to maintain compliance with the various laws and regulations that impact our business and industry.?

?

I’m going to bring this to a quick close this week.? At this point we have covered all the different areas where GenAI can help support our cybersecurity programs.? The key word in that sentence was “support”.? ?GenAI can be a great tool to help support our programs, remember it is simply a tool and doesn’t replace human intuition and judgement.? Next week we will start to bring this series to a close with a quick review of what we have covered and a discussion about the challenges of implementing GenAI.??

要查看或添加评论,请登录

Graydon McKee - MSIA, CISSP的更多文章

  • Cybersecurity Threat Overview of the Paris Games

    Cybersecurity Threat Overview of the Paris Games

    Between July 26th and September 8th, the world will come together in Paris to conduct and celebrate the Olympics and…

  • Wrapping up the GenAI Conversation

    Wrapping up the GenAI Conversation

    We have finally come to the end of this particular series on GenAI. We started things off four articles ago where we…

  • GenAI and Incident Response

    GenAI and Incident Response

    This is part three of an article I wrote where I addressed the use of AI in Cybersecurity. I’m focusing on the newest…

    1 条评论
  • GenAI and Threat Detection

    GenAI and Threat Detection

    This is part two of an article I wrote for LinkedIn where I took on the topic of the use of AI in Cybersecurity. I’m…

  • Incorporating GenAI into Cybersecurity

    Incorporating GenAI into Cybersecurity

    Originally, I intended this to be a quick article but the more I delved into the top of GENAI and how we can use it in…

    1 条评论
  • My Thoughts on the Verizon 2021 Data Breach Investigations Report

    My Thoughts on the Verizon 2021 Data Breach Investigations Report

    Verizon has recently released their annual Data Breach Investigations Report (DBIR) and after reading it over, I…

    1 条评论
  • Taking the Wrong Trail

    Taking the Wrong Trail

    With the emergence of yet another widespread vulnerability, I’ve been spending some time reflecting on the ever…

  • Hunting Ostriches

    Hunting Ostriches

    I came across an interesting article at Forbes today entitled "Cyber Security and the Danger of Ostriches in the…

    2 条评论
  • The Road Goes Ever On and On...

    The Road Goes Ever On and On...

    It is a Journey What is security? How can I be secure? How will I know my systems are secure? I was compliant with the…

    3 条评论
  • Swimming with Caiman, Piranha and Arapaima

    Swimming with Caiman, Piranha and Arapaima

    About a year ago I had the opportunity to conduct some security assessments at a partner’s facility deep in the rain…

社区洞察

其他会员也浏览了