A Method for Effectively Managing AI Risks with ISO 27001 In the Context Of GIS

Jerzy STANIK and Maciej KIEDROWICZ

Military University of Technology, Warsaw, Poland

https://doi.org/10.5171/2025.4515425

Abstract

The increase in the use of artificial intelligence (AI) in geographic information systems (GIS) brings new challenges related to information security. The aim of this study is to develop a method for managing AI threats in the context of GIS, using the ISO 27001 standard to ensure data integrity, confidentiality, and availability. Despite the growing body of research on AI and GIS, there is a limited amount of work focusing on managing AI risks in the context of GIS using information security standards. This gap indicates the need to develop specific methods and tools that can be applied in practice.

The study uses a blended approach, combining literature analysis and thematic analysis with empirical research. Existing standards and guidelines were reviewed, followed by expert interviews and surveys among the organization’s employees using GIS and AI. These methods allow you to collect qualitative and quantitative data on experiences, challenges, and opinions on AI threat management. The results of the study indicate that the application of ISO 27001 in the context of GIS and AI is effective in managing information security risks. The implementation of the standard allows systematic risk identification, assessment, and management, leading to increased data security and trust in AI systems. The study also highlights the need for further research and adaptation of safety standards to the specific requirements of AI and GIS. The findings of the study can be used by organizations that want to effectively manage AI risks in their GIS systems while ensuring compliance with international information security standards.

Keywords: Information security, Incident management, Risk analysis, Security practices, AI threats.
Shares