arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

放大器效应:多框架GRC自评估中AI建议相关性与自动传播的人因风险

The Amplifier Effect: Human-Factor Risks of AI-Suggested Correlation and Auto-Propagation in Multi-Framework GRC Self-Assessment

Nikolaos Kekatos, Michael Ioannou, Marina Korgiala-Karyda, Alexios Lekidis, Tom Nianios

arXiv 2610.07866首次发表:更新:

发表机构

Clone Systems; Bolton Technologies; University of Thessaly(克隆系统; 博尔顿科技; 塞萨利大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究揭示多框架GRC平台中AI相关性与自动传播会放大单一人因偏差,提出六维评分框架及测量协议,并以十三工具比较验证。欧盟中小企业平台因设计权衡得分最低。

AI 中文摘要

多框架治理、风险与合规(GRC)平台日益自动化地将组织的自评估答案与该答案据称满足的合规义务之间的关联。跨框架控制映射、AI建议的问题相关性以及答案和证据在相关问题间的自动传播,都服务于在欧盟《网络弹性法案》、NIS2和GDPR下为中小企业减少重复工作的合法效率目标。然而,同样的机制会放大单个答案中任何人因偏差的后果:一个乐观评级的控制、一个橡皮图章式的证明,或一个AI起草的答案,可能被静默复制为跨多个框架的众多义务的合规证据。我们称之为放大器效应:一种平台设计属性(粗粒度证明和无门槛传播),而非个体用户的失误。以两个欧盟资助的面向中小企业的GRC平台CYBERFORT和CYBER-BRIDGE为例,我们(i)用具体的数据模型术语描述放大机制,(ii)提出一个六维评分框架,用于评估任何GRC工具对该效应的暴露程度,(iii)将该框架实例化于一个涵盖企业IRM、中端市场平台、合规自动化工具以及两个欧盟中小企业项目的十三工具比较中,以及(iv)概述一个可由拥有生产自评估数据访问权的联盟运行的测量协议。十三工具比较是一项结构化的设计评估,而非对用户行为的实证测量。欧盟中小企业平台在放大器维度上得分最低,因为其减负设计刻意以签署粒度换取吞吐量;我们将其报告为一种设计权衡,而非对这些平台的裁决。我们的贡献在于框架构建和测量协议。

英文摘要

Multi-framework Governance, Risk and Compliance (GRC) platforms increasingly automate the link between an organisation's self-assessment answer and the compliance obligations that answer is said to satisfy. Cross-framework control mapping, AI-suggested question correlation, and automatic propagation of answers and evidence across correlated questions all serve the legitimate efficiency goal of reducing duplicate work for small and medium-sized enterprises under the EU Cyber Resilience Act, NIS2 and GDPR. The same mechanisms, however, amplify the consequences of any human-factor bias in a single answer: one optimistically-graded control, one rubber-stamped attestation, or one AI-drafted answer can be silently replicated as evidence of compliance with many obligations across multiple frameworks. We call this the amplifier effect: a platform-design property (coarse-grained attestation and un-gated propagation) rather than a failing of individual users. Using two EU-funded SME-facing GRC platforms, CYBERFORT and CYBER-BRIDGE, as examples, we (i) describe the amplification mechanism in concrete data-model terms, (ii) propose a six-dimension scoring framework for evaluating any GRC tool's exposure to the effect, (iii) instantiate the framework on a thirteen-tool comparison covering enterprise IRM, mid-market platforms, compliance-automation tools, and the two EU SME projects, and (iv) outline a measurement protocol that a consortium with access to production self-assessment data can run. The thirteen-tool comparison is a structured design assessment, not an empirical measurement of user behaviour. The EU SME platforms score lowest on the amplifier dimensions because their burden-reduction design deliberately trades sign-off granularity for throughput; we report this as a design trade-off, not a verdict on the platforms. Our contribution is the framing and the measurement protocol.

Comments7 pages, 2 figures, 3 tables. Accepted at the 2026 IEEE International Conference on Cyber Security and Resilience (IEEE CSR 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑