Artificial intelligence in information security policy management research: a scoping review

Fredrik Karlsson et al.

Information and Computer Security2026https://doi.org/10.1108/ics-09-2025-0357article
AJG 1ABDC B
Weight
0.50

Abstract

Purpose Although existing literature has advanced the understanding of information security policy (ISP) management, it has not examined how artificial intelligence (AI) can support ISP activities across management phases. Moreover, no study has yet mapped the empirical domains studied. The purpose of this paper is to systematically map existing ISP management research to assess to what extent AI has been addressed or used. Design/methodology/approach This study follows the five-step scoping review framework proposed by Arksey and O’Malley (2005): identifying the research questions, finding relevant studies, selecting studies, charting the data and reporting the results. Findings The review reveals that very few ISP management papers address or use AI. These few papers focused mostly on operational ISPs and addressed different ISP phases and empirical domains. Most existing work focuses on construction or compliance, while no studies have addressed the technical level. Research methods dominated by experiments, with a notable absence of organizational fieldwork. Research on ethical aspects such as fairness, transparency, accountability and data sensitivity is rare in this area. Research limitations/implications Given the limited research in this area, there are significant opportunities to explore AI in ISP management and to use AI in studying ISP management. The authors suggest a research agenda divided into three-time horizons: short, medium and long term. Originality/value This paper provides the first scoping review of AI in ISP management research, offering a systematic mapping of ISP management phases, ISP levels, research methods and empirical domains. It identifies research gaps, thereby guiding future research.

Open via your library →

Cite this paper

https://doi.org/https://doi.org/10.1108/ics-09-2025-0357

Or copy a formatted citation

@article{fredrik2026,
  title        = {{Artificial intelligence in information security policy management research: a scoping review}},
  author       = {Fredrik Karlsson et al.},
  journal      = {Information and Computer Security},
  year         = {2026},
  doi          = {https://doi.org/https://doi.org/10.1108/ics-09-2025-0357},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

Artificial intelligence in information security policy management research: a scoping review

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.50

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.50 × 0.4 = 0.20
M · momentum0.50 × 0.15 = 0.07
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.