RAG와 OCR 기술을 활용한 LLM 기반 정보보호 관리체계(ISMS) 인증관리 자동화 시스템

Vol. 35, No. 2, pp. 383-396, 4월. 2025
10.13089/JKIISC.2025.35.2.383, Full Text:
Keywords: ISMS, LLM, RAG, OCR, Automation
Abstract

This study proposes an LLM-based certification management automation system for efficient diagnosis and analysis of complex regulatory compliance requirements when preparing for an Information Security Management System(ISMS) certification. This system has the following two functions. The first is the document search function, which automatically analyzes and searches for content that meets the certification standards according to the company's policy. At this time, in order to solve the hallucination that occurs by simply introducing LLM, RAG was applied to refer only to the company's documents. The second is the evidence appropriateness check function, which automatically checks whether the evidence data and the certification criteria meet for some items. Considering that most of the necessary evidence data are in tables and texts, OCR was applied to the preprocessing process of data to be delivered to LLM. The performance evaluation of this system was conducted based on the Big-O notation and the consulting output used in the actual ISMS certification, and the reduced time required and high accuracy and detail of the analysis results were confirmed compared to the existing consulting process. This will not only reduce the burden on companies, but also improve the level of information security, and is expected to be reorganized into a more simplified screening process.

Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[IEEE Style]
진현준, 박후린, 최정원, 조용권, 홍영창, 이동수, 신우빈, "LLM-Based Information Security Management System(ISMS) Certification Management Automation System Using RAG and OCR," Journal of The Korea Institute of Information Security and Cryptology, vol. 35, no. 2, pp. 383-396, 2025. DOI: 10.13089/JKIISC.2025.35.2.383.

[ACM Style]
진현준, 박후린, 최정원, 조용권, 홍영창, 이동수, and 신우빈. 2025. LLM-Based Information Security Management System(ISMS) Certification Management Automation System Using RAG and OCR. Journal of The Korea Institute of Information Security and Cryptology, 35, 2, (2025), 383-396. DOI: 10.13089/JKIISC.2025.35.2.383.