🤖 AI Summary
This study addresses the challenges of dynamically managing compliance risks under Ukraine’s cybersecurity regulations and the complexity and error-proneness of manually constructing security profiles. To overcome these issues, the authors propose a novel approach that integrates Retrieval-Augmented Generation (RAG) with large language models (LLMs), harmonizing the ISO/IEC 27001 and NIST cybersecurity frameworks to automatically generate jurisdiction-specific target security profiles. By incorporating a vector database linked to a knowledge base of Ukrainian legal requirements and organizational policies, the method enables precise alignment between regulatory mandates and technical controls. This framework significantly reduces the need for manual intervention and associated error rates, offering a structured, AI-assisted workflow that effectively supports risk-driven cybersecurity compliance management.
📝 Abstract
In recent years, the pace of development of information technology in various areas has increased drastically, forcing cybersecurity specialists to constantly review existing processes in order to prevent unauthorized access to confidential information. Using Ukraine as a primary case study, this paper explores the integration of international best practices, specifically ISO/IEC 27001 and the NIST Cybersecurity Framework, into national regulatory systems. A focus is placed on the transition from traditional compliance models to risk-based approaches, exemplified by the recent adoption of the Ukrainian normative documents. Furthermore, we propose a methodology for automating the development of target security profiles using Large Language Models (LLMs) enhanced by RetrievalAugmented Generation (RAG). By integrating a vector database of national regulations and organizational policies, the proposed RAG-based advisor reduces manual complexity, minimizes human error, and ensures alignment between technical controls and legal requirements. This study contributes to the field by providing a structured workflow for AI-assisted cybersecurity management in environments characterized by high-intensity hybrid threats.