arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.10881cs.CRcs.CYcs.SE

AspisAI:面向自动化多标准合规监控的规范化、机器可解释治理框架

AspisAI: A Canonical, Machine-Interpretable Governance Framework for Automated Multi-Standard Compliance Monitoring

Tsafac Nkombong Regine Cyrille, Hasan Dag, Reiner Creutzburg, Knut Haufe

首次发表
浏览论文内容

中文总结 AI 辅助

AspisAI提出一种标准无关的治理框架,将多标准要求转化为机器可解释控制模型,通过条件决策规则实现可解释、可追溯的自动化合规监控,并经外部验证证明其有效性。

中文摘要 AI 辅助

在受监管和关键基础设施领域运营的组织必须同时满足多种异构的网络安全和隐私保护文书要求,包括但不限于ISO/IEC 27001、NIST网络安全框架2.0、Cyber Essentials和GDPR。在实践中,这些义务通过人工映射、基于电子表格的跟踪和定期审计来管理,这些方式维护成本高昂、各标准之间不一致且可追溯性薄弱。本文提出了AspisAI,一个受限的、标准无关的治理框架,它将多个框架中的选定要求转换为规范化的、机器可解释的控制模型,并根据基于条件的决策规则评估提交的证据,以产生可解释、可追溯的合规性判定。在26项代表性要求的受限范围内,该框架在受控模拟中针对五项面向治理的标准进行了评估,并且关键的是,针对两个外部参考点进行了评估,以减轻单一作者评估的循环性:其跨标准映射针对NIST自身发布的参考信息进行了验证,精确一致率为57%,分歧仅限于同族控制;该框架还应用于OpenSSF Scorecard的真实第三方证据,在一个活跃的开源项目中揭示了真实的治理缺口。受控结果包括完整的要求编码、88.5%的映射覆盖率、完整的可追溯性以及对所有引入缺口的正确检测,确立了功能正确性,而外部验证提供了模拟之外适用性的证据。因此,其贡献在于证明了一种规范化的、保留来源的治理模型可以使多标准合规既自动化又可审计。

英文摘要

Organisations operating in regulated and critical-infrastructure sectors must satisfy multiple, heterogeneous cybersecurity and privacy instruments simultaneously, including but not limited to ISO/IEC~27001, the NIST Cybersecurity Framework~2.0, Cyber Essentials, and the GDPR. In practice, these obligations are managed through manual mappings, spreadsheet-based tracking, and periodic audits that are costly to maintain, inconsistent across standards, and weak in traceability. This paper presents \emph{AspisAI}, a bounded, standard-agnostic governance framework that translates selected requirements from several frameworks into a canonical, machine-interpretable control model, and evaluates submitted evidence against condition-based decision rules to produce explainable, traceable compliance determinations. Within a bounded scope of 26 representative requirements, the framework is evaluated in a controlled simulation against five governance-oriented criteria and, critically, against two external reference points that mitigate the circularity of single-author evaluation: its cross-standard mappings are validated against NIST's own published informative references, with 57\,\% exact agreement and divergences confined to same-family controls, and the framework is applied to real third-party evidence from the OpenSSF Scorecard, surfacing genuine governance gaps in a live open-source project. The controlled results, comprising full requirement encoding, 88.5\,\% mapping coverage, complete traceability, and correct detection of all introduced gaps, establish functional correctness, while the external validation provides evidence of applicability beyond the simulation. The contribution is therefore a demonstration that a canonical, provenance-preserving governance model can render multi-standard compliance both automatable and auditable.

发表机构

  • Kadir Has University(卡迪尔哈斯大学)
  • SRH University of Applied Sciences Heidelberg Campus Berlin(SRH海德堡应用科学大学柏林校区)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑