This work addresses the growing demand for efficient solutions in the information security and data protection compliance process, particularly in medium-sized companies that face significant challenges related to the shortage of specialized professionals. This paper implements a solution based on the use of Generative Artificial Intelligence to automate the generation of compliance reports, customized according to the needs of different stakeholders within the organization, such as managers, technical teams, and compliance officers. The main objective is to optimize the efficiency, scalability, and reliability of compliance processes, reducing the time and resources required to produce these documents, in addition to improving the clarity of the presented information. The study's rationale lies in the need to mitigate two main problems faced by companies: the lack of qualified professionals in the cybersecurity field and the workload associated with the manual production of complex reports. These factors limit organizations' ability to implement robust compliance programs and hinder meeting current regulatory requirements. The adopted methodology included a systematic literature review to identify existing applications of Generative AI technologies in the field of information security and data protection, as well as an analysis of best practices in compliance. To validate the proposal, modular architecture was developed, consisting of three main modules: integration of data from security information and event management systems; processing of this data to extract relevant information; and report generation using advanced Generative AI techniques. The results indicate that automating report creation can free up experts to focus on more strategic activities, while improving the accuracy and consistency of the information provided. Furthermore, the results demonstrated that the solution enables the generation of consistent reports, allowing companies to adapt more easily to changes in legal and normative requirements, ensuring greater regulatory compliance and reducing operational risks. Through this approach, implementation represents a significant contribution to the use of artificial intelligence in the business context, promoting a more accessible and sustainable security culture in line with the spirit of Sustainable Development Goal 11 (Sustainable Cities and Communities).
O Computer on the Beach é um evento técnico-científico que visa reunir profissionais, pesquisadores e acadêmicos da área de Computação, a fim de discutir as tendências de pesquisa e mercado da computação em suas mais diversas áreas.