IDEAS home Printed from https://ideas.repec.org/a/jbi/ijsrhs/v1y2024i2id146.html

Large Language Models for Cybersecurity Policy Compliance and Risk Mitigation

Author

Listed:
  • Emmanuel Cadet
  • Edima David Etim
  • Iboro Akpan Essien
  • Eseoghene Daniel
  • igha
  • Lawal Abdulmutalib Babatunde
  • Joshua Oluwagbenga Ajayi
  • Ehimah Obuse

Abstract

The rapid digitization of critical business processes has heightened the importance of effective cybersecurity policy compliance and proactive risk mitigation. Large Language Models (LLMs), with their advanced natural language processing and reasoning capabilities, present a transformative opportunity to enhance compliance management, regulatory interpretation, and security decision-making. This study explores the application of LLMs in automating policy analysis, monitoring adherence to industry-specific standards, and facilitating real-time risk assessment. Leveraging extensive training on diverse text corpora, LLMs can interpret complex regulatory frameworks such as GDPR, HIPAA, NIST, and ISO 27001, translating them into actionable technical controls. By integrating with security information and event management (SIEM) systems, LLMs can contextualize alerts, identify potential policy violations, and recommend remediation steps aligned with organizational governance requirements. The research highlights key capabilities, including automated compliance audits, intelligent mapping of policies to operational procedures, and continuous control monitoring across heterogeneous IT and operational technology environments. Case studies illustrate how LLM-powered systems have improved response efficiency in identifying misconfigurations, insider threats, and third-party compliance risks, thereby reducing mean time to detect (MTTD) and mean time to respond (MTTR). The study also addresses challenges, including ensuring model interpretability, managing domain-specific fine-tuning, mitigating hallucinations, and securing sensitive data during inference. Proposed solutions include prompt engineering best practices, integration of explainable AI (XAI) techniques, reinforcement learning from human feedback (RLHF), and the application of privacy-preserving methods such as federated learning. Performance evaluation in simulated enterprise scenarios demonstrates that LLM-enabled compliance tools achieve higher accuracy in regulatory mapping and lower rates of false positives compared to traditional rule-based systems. The findings underscore the potential of LLMs to serve as dynamic compliance advisors, enabling organizations to proactively adapt to evolving cybersecurity regulations while minimizing operational and reputational risks. Future research will explore multimodal LLMs for integrating text, code, and network telemetry, as well as collaborative AI-human governance models to balance automation with oversight. This study positions LLMs as a pivotal technology in advancing cybersecurity policy compliance and risk mitigation in complex, regulated environments.

Suggested Citation

  • Emmanuel Cadet & Edima David Etim & Iboro Akpan Essien & Eseoghene Daniel & igha & Lawal Abdulmutalib Babatunde & Joshua Oluwagbenga Ajayi & Ehimah Obuse, 2024. "Large Language Models for Cybersecurity Policy Compliance and Risk Mitigation," International Journal of Scientific Research in Humanities and Social Sciences, International Journal of Scientific Research in Humanities and Social Sciences, vol. 1(2), pages 612-643, December.
  • Handle: RePEc:jbi:ijsrhs:v1:y2024:i2:id:146
    DOI: 10.32628/IJSRSSH242560
    Note: Article URL: https://ijsrhss.com/home/article/view/IJSRSSH242560
    as

    Download full text from publisher

    File URL: https://ijsrhss.com/home/article/view/IJSRSSH242560
    File Function: Article URL
    Download Restriction: no

    File URL: https://ijsrhss.com/home/article/download/IJSRSSH242560/IJSRSSH242560
    File Function: Full text
    Download Restriction: no

    File URL: https://libkey.io/10.32628/IJSRSSH242560?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    More about this item

    Keywords

    ;
    ;
    ;
    ;
    ;
    ;
    ;
    ;
    ;
    ;
    ;
    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:jbi:ijsrhs:v1:y2024:i2:id:146. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Pankaj Sharma (email available below). General contact details of provider: https://ijsrhss.com/home .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.