LLM-Driven PCI 4 Compliance Artifact Generation and Gap Analysis
Keywords:
PCI DSS, large language models, compliance automation, audit readiness, control evidence, runtime telemetryAbstract
Payment systems need to follow PCI DSS v4.0 to make sure a lot of documentation and constant inspections are needed to be done. The objective of this research is to introduce a large language model for the automated creation of compliance artefacts and real-time gap analysis, which includes architectural diagrams, version-controlled code commits, and operational data to show that we are PCI 4-compliant.
Downloads
References
P. Mell, K. Scarfone, and S. Romanosky, "A Complete Guide to the Common Vulnerability Scoring System Version 2.0," IEEE Security & Privacy, vol. 10, no. 6, pp. 63–71, Nov.-Dec. 2012.
PCI Security Standards Council, "PCI DSS v3.2: Payment Card Industry Data Security Standard," Apr. 2016. [Online]. Available: https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2.pdf
S. R. Madden, S. Rajagopalan, and A. K. Jones, "Automated Compliance Verification in Cloud Environments," IEEE Cloud Computing, vol. 3, no. 1, pp. 22–30, Jan.-Mar. 2016.
M. V. Wilkerson and J. R. McHugh, "Formal Methods for Security Compliance Auditing," IEEE Transactions on Dependable and Secure Computing, vol. 10, no. 4, pp. 221–235, July-Aug. 2013.
A. K. Jain and M. Kumar, "Natural Language Processing Techniques for Regulatory Document Analysis," in Proc. IEEE Int. Conf. on Data Mining Workshops, 2015, pp. 902–908.
B. Schneier, "The Uses and Abuses of Risk Assessment," IEEE Security & Privacy, vol. 10, no. 1, pp. 38–43, Jan.-Feb. 2012.
C. Dwork and J. Naor, "Pricing via Processing or Combatting Junk Mail," in Proc. Advances in Cryptology — CRYPTO ’92, 1992, pp. 139–147.
S. J. Stolfo, M. L. Wong, W. Fan, et al., "Detecting Computer System Intrusions by Mining Audit Data," in Proc. IEEE Security and Privacy Symposium, 2000, pp. 51–62.
D. R. Kuhn, E. J. Coyne, and T. R. Weil, "Adding Attributes to Access Control," IEEE Computer, vol. 43, no. 6, pp. 79–81, June 2010.
M. E. Locasto, S. J. Stolfo, and A. D. Keromytis, "Towards Collaborative Security and P2P Intrusion Detection," IEEE Security & Privacy, vol. 3, no. 1, pp. 22–31, Jan.-Feb. 2005.
J. R. Quinlan, "Induction of Decision Trees," Machine Learning, vol. 1, no. 1, pp. 81–106, 1986.
K. B. Kent and J. C. Millett, "Who Goes There? Authentication Through the Lens of Privacy," IEEE Security & Privacy, vol. 5, no. 6, pp. 12–15, Nov.-Dec. 2007.
T. Mikolov, K. Chen, G. Corrado, and J. Dean, "Efficient Estimation of Word Representations in Vector Space," in Proc. Int. Conf. Learning Representations (ICLR), 2013.
J. Pennington, R. Socher, and C. D. Manning, "GloVe: Global Vectors for Word Representation," in Proc. Conf. Empirical Methods in Natural Language Processing (EMNLP), 2014, pp. 1532–1543.
K. Cho, B. van Merrienboer, C. Gulcehre, et al., "Learning Phrase Representations using RNN Encoder–Decoder for Statistical Machine Translation," in Proc. Conf. Empirical Methods in Natural Language Processing (EMNLP), 2014, pp. 1724–1734.
A. Vaswani, N. Shazeer, N. Parmar, et al., "Attention is All You Need," in Proc. Advances in Neural Information Processing Systems (NeurIPS), 2017, pp. 5998–6008.
S. Bird, E. Klein, and E. Loper, Natural Language Processing with Python, O'Reilly Media, 2009.
R. B. King, "Challenges of Large-Scale Regulatory Compliance in Payment Systems," Journal of Financial Regulation and Compliance, vol. 24, no. 3, pp. 280–293, 2016.
M. K. Rogers, "Automating Compliance Through Metadata Tagging and Ontologies," in Proc. IEEE Int. Conf. on Services Computing, 2014, pp. 623–630.
F. Chollet, Deep Learning with Python, Manning Publications, 2017.
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.