A security team wants to deploy an AI tool to generate first-draft incident response reports from SIEM data and alert timelines. An auditor raises a concern about these AI-generated reports being filed as official incident documentation. What process control addresses this concern?
- A.AI-generated reports should only be used for training purposes and never filed as official documentation under any circumstances
- B.AI-generated reports are acceptable as official documentation if the AI model achieves greater than 95% accuracy on a validation set
- C.Include a disclaimer at the top of AI-generated reports stating they may contain errors, then file them without further review
- D.All AI-generated incident report drafts must be reviewed, edited, and explicitly signed off by a named human analyst before being filed as official documentation, with the review process logged - the filed document should clearly indicate that AI assistance was used in drafting
Why D is correct