Solutions

AI in the ISMS

AI in SecBoard is attached to a record that already exists: a risk, a standard, a PDF, a report, or an alert. It is not a separate product that replaces the modules.

Where it already runs

AI is used in risk assessment and threat analysis, in parsing regulatory PDFs, in translations, in report summaries, and in an assistant that sees the user’s role. The standards catalog has AI-powered search over PCI DSS and ISO/IEC 27002. SOC/FIM can run AI analysis on an alert next to hash lookups. The risk score itself is still calculated by the risk module.

What is not shipped as AI

The about page lists further scenarios as potential, including automatic generation of a full policy set. Those are not described here as current functions. GoPhish campaigns, the access matrix, and the incident registry work without being AI features.

Questions

No. The risk module calculates the level. AI assists with analysis, summaries, and the assistant.

The assistant is role-aware. It answers in the context of the signed-in role, not as an unrestricted view of the database.

In the standards catalog, over PCI DSS requirements and ISO/IEC 27002 controls.

No. Wazuh, or another monitor, sends the alert. SecBoard can analyze that alert.

Related