# SP-049 AI in Security Operations

Status: draft. Release 26.02. Modified 2026-02-22. Licence: CC BY-SA 4.0.

Scope: Security architecture for the use of AI in defensive security operations — AI-augmented threat detection, AI-assisted incident triage and response, AI-generated threat intelligence, and automated security analysis. Addresses the specific risks this introduces: detection model evasion, hallucination in security-critical decisions, training data poisoning, analyst skill atrophy, and over-automation.
Use when: Organisation uses SIEM with ML-based anomaly detection or AI-based alert prioritisation. XDR or EDR products with AI detection are in production.
Not when: Organisation has no security operations function and no security monitoring tooling.

## Controls (26, NIST SP 800-53 ids)
- Critical (7): AU-02, AU-03, CA-07, CM-02, IR-04, SA-11, SI-04
- Important (18): AC-05, AT-02, AT-03, AU-06, CM-03, CM-04, CM-08, IR-06, PM-14, PM-16, PT-02, RA-03, SA-03, SA-04, SA-09, SC-28, SI-10, SR-02
- Standard (1): PS-06

## What each critical control mitigates (7)
- AU-02 Event Logging: T-AISO-003, T-AISO-007, T-AISO-010
- AU-03 Content of Audit Records: T-AISO-004, T-AISO-008
- CA-07 Continuous Monitoring: T-AISO-001, T-AISO-004, T-AISO-005, T-AISO-007
- CM-02 Baseline Configuration: T-AISO-001, T-AISO-005, T-AISO-007
- IR-04 Incident Handling: T-AISO-003, T-AISO-008
- SA-11 Developer Testing and Evaluation: T-AISO-001, T-AISO-003, T-AISO-004, T-AISO-005
- SI-04 System Monitoring: T-AISO-001, T-AISO-007

## Threats and the controls that mitigate them (10)
- T-AISO-001 Detection model evasion — adversary crafts activity patterns to stay below ML anomaly detection thresholds: CA-07, SI-04, CM-02, SA-11
- T-AISO-002 Training data poisoning — adversary manipulates security telemetry to degrade detection model accuracy over time: SI-10, CM-08, SA-03, SC-28
- T-AISO-003 AI triage hallucination — AI incorrectly classifies a critical incident as low priority, causing delayed or absent response: IR-04, AU-02, AC-05, SA-11
- T-AISO-004 AI threat intelligence fabrication — hallucinated IOCs, CVE references, or threat actor attributions misdirecting investigation: AU-03, SI-10, SA-11, CA-07
- T-AISO-005 Detection model concept drift — model trained on historical traffic fails to detect novel attack patterns without refresh: CA-07, CM-02, SA-11, CM-03
- T-AISO-006 Analyst skill atrophy — SOC loses manual investigation capability after sustained AI dependency: AT-02, AT-03, PM-14, PS-06
- T-AISO-007 Security AI system compromise — adversary targets the detection model or AI triage tool to suppress alerting: SI-04, CA-07, AU-02, CM-02
- T-AISO-008 Over-automation — AI-triggered response actions causing disproportionate business disruption without human review: AC-05, IR-04, CM-03, AU-03
- T-AISO-009 Third-party detection model supply chain risk — vendor model updates silently reducing detection coverage or introducing regression: SR-02, SA-04, CM-08, SA-09
- T-AISO-010 Security telemetry data exposure — sensitive log and alert data processed by vendor AI with insufficient residency or access controls: SA-09, SC-28, PT-02, AU-02

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-049/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-049/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 37 KB: /api/v1/patterns/SP-049
- Page for people: /patterns/sp-049/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-025 Advanced Monitoring and Detection; SP-027 Secure LLM Usage; SP-031 Security Monitoring and Response; SP-036 Incident Response; SP-045 AI Governance and Responsible AI

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
