ASD ISM 2119Utilise AI Models in Vulnerability Assessments and Penetration Tests
Suitable AI models are used to augment both vulnerability assessments and penetration tests.
Plain language
This control is about putting suitable AI models to work alongside your security testers so they augment, not replace, the human effort in both vulnerability assessments and penetration tests. AI can scan larger code and infrastructure footprints faster, triage findings, and surface novel or complex attack paths a human might miss, while a tester decides what to chase and exploit. The word "suitable" matters: the model has to fit the target, the test type, and your data handling rules. Without it, testing is slower to cover everything and more likely to miss the harder, chained attack paths.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
05 Sept 2026
E8 maturity levels
N/A
Guideline
Guidelines for security assuranceSection
Security assessmentsTopic
Vulnerability assessments and penetration tests
Official control statement
Suitable AI models are used to augment vulnerability assessments and penetration tests.
Why it matters
If suitable AI models are not used to augment this work, vulnerability assessments and penetration tests cover ground more slowly, struggle to scale across large or fast-changing systems, and are more likely to miss novel or complex multi-step attack paths that automated reasoning could have surfaced; weaknesses that AI-augmented testing would have found stay open and exploitable.
Operational notes
Treat AI as an augmentation layer over both vulnerability assessments and penetration tests, never an unsupervised actor: validate AI-generated findings against false positives before they reach a remediation queue, and keep a human tester in control of any AI-driven penetration testing actions such as exploitation, lateral movement, or payload delivery. Scope the AI tooling strictly to authorised in-scope targets so it cannot scan or attack systems outside the rules of engagement, and govern the model and tool versions you use (pinning versions, recording prompts and configurations) so results are repeatable across tests. Periodically compare AI-augmented runs against unaided baselines to confirm the model is genuinely improving coverage and detecting novel paths rather than adding noise.
Implementation tips
- Select AI models suitable for each test type and record the choice in a model register: pick models that augment vulnerability scanning and triage for assessments, and models or agents that assist reconnaissance, attack-path reasoning and exploit suggestion for penetration tests, noting the suitability rationale for each.
- Wire the chosen AI tooling into your existing vulnerability assessment and penetration test workflow so it augments human testers, for example having it pre-triage scanner output, cluster duplicate findings, and propose chained attack paths for the tester to confirm and pursue.
- Constrain the AI tooling to the authorised target list before each engagement by loading the rules-of-engagement scope (IP ranges, hosts, applications) into its configuration and blocking it from acting on anything outside that scope.
- Keep a human tester in control of AI-driven penetration testing actions: require explicit human approval before the model runs any exploit, lateral movement, credential use, or payload, and log who approved each action.
- Validate every AI-generated finding against false positives before it reaches the remediation queue: have a tester confirm exploitability or reproduce the issue, and mark dismissed findings with the reason.
- Govern model and tool versions by pinning the model/tool version per engagement and saving the prompts and run configuration, so each AI-augmented vulnerability assessment and penetration test is repeatable and changes are tracked.
Audit / evidence tips
- AskAsk for the AI model register that lists the models used to augment vulnerability assessments and penetration tests.Look atCheck that each model has a documented justification for being suitable for the specific test type it augments, and that models are mapped to both vulnerability assessment and penetration test activities rather than only one.GoodEvery model in the register is justified as suitable for its use, and the register shows AI augmentation covers both vulnerability assessments and penetration tests.
- AskAsk for the engagement log or tester notes from a recent penetration test where AI assistance was used.Look atTrace a sample of AI-assisted exploitation or lateral-movement actions back to the named human tester who authorised each one.GoodEach sampled AI-driven action is linked to a named tester who approved it, and no action was executed without human oversight.
- AskAsk for the AI tooling configuration and the rules of engagement for a recent engagement.Look atConfirm the tooling was scoped only to the authorised targets and could not scan or attack out-of-scope systems.GoodThe configuration and rules of engagement restrict AI tooling to authorised targets, with out-of-scope systems excluded.
- AskAsk for a vulnerability assessment report that includes AI-augmented findings.Look atReview whether each AI-augmented finding was validated for false positives by a human before it entered remediation, rather than being accepted automatically.GoodEach finding carries evidence of human validation before remediation, and no AI-generated findings were accepted without review.
- AskAsk for the test records for a given AI-augmented run, including model and tool version details and any comparison against an unaided baseline.Look atCheck that model and tool versions are recorded and pinned so the run is repeatable, that version changes are tracked in the register, and that the comparison shows the AI improved coverage or surfaced novel or complex attack paths.GoodVersions are pinned and tracked, and the baseline comparison demonstrates the AI genuinely augmented the assessment rather than duplicating unaided results.
Cross-framework mappings
How ISM-2119 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(2)expand_less | ||
| Annex A 8.8 | ISM-2119 requires organisations to use suitable AI models to augment vulnerability assessments and penetration tests | |
| Annex A 8.29 | ISM-2119 requires suitable AI models to be used to augment vulnerability assessments and penetration tests | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Security assurance
See all Guidelines for security assurance controls, or browse the full ASD ISM library.