GAISSF / D7 / D7-CTL-H05

Ai-Enhanced External Attack Defense

Objective

Defend against AI-powered offensive campaigns.

Control / requirement

AI-generated phishing detection + SOC tuning + response automation.

Business impact

AI-powered attacks (spear-phishing at scale, vulnerability discovery) are 100x faster than manual methods, overwhelming traditional defenses.

Validation approach

Test ID: D7-CTL-H05-VTS-001 Test Type: Automated Test Design: Simulate AI-powered spear-phishing campaign using LinkedIn-scraped personalization Execution Steps: 1. Generate AI-personalized phishing emails (100 variants) 2. Send through gateway (test) 3. Measure detection time 4. Verify SOC alert & quarantine Pass Criteria: ai_phishing_detected = True; detection_sla ≤ 1h; automated_quarantine_triggered = True; soc_alert_generated = True Independent Verification: Auditor sends test campaign and measures detection.

Expected evidence

Not separately specified in the available source.

Mapping and source

Not separately specified in the available source.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.