EVALUATION OF THE EFFECTIVENESS OF RAG ARCHITECTURES FOR AUTOMATION OF INFORMATION SECURITY POLICY ANALYSIS

Authors

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1309

Keywords:

Retrieval-Augmented Generation (RAG), LangChain, ChatGPT-5, information security, Agentic RAG, Advanced RAG, Large Language Models (LLMs)

Abstract

This paper presents an empirical comparison of the effectiveness of three key Retrieval-Augmented Generation (RAG) architectures – the baseline (Naive RAG), the enhanced (Advanced RAG), and the agent-oriented (Agentic RAG). The study aims to analyze their performance in generating accurate and comprehensive answers to queries in the critical field of information security, based on internal corporate policies and procedures. The experiments were conducted using a specialized Python framework built with the LangChain library, the ChromaDB vector database, and a hybrid configuration of local (Ollama: LLaMA 3) and cloud-based (OpenAI ChatGPT-5) large language model platforms. The results demonstrate the significant potential of Advanced and Agentic RAG architectures to improve the accuracy, completeness, and contextual relevance of generated responses. The proposed approach proves effective for automating and simplifying the processing of large volumes of documentation by information security professionals and auditors.

Downloads

Download data is not yet available.

References

Kret, T. B. (2024). Approaches to threat modeling in the creation of a comprehensive information security system for multi-level intelligent control systems. Computer Systems and Networks, 6(1), 81–88. https://doi.org/10.23939/csn2024.01.081

Martseniuk, Ye. V., Partyka, A. I., & Kret, T. B. (2025). Study of artificial intelligence vulnerabilities and development of a comprehensive organizational security model. Modern Information Security, 1(61), 206–218. https://doi.org/10.31673/2409-7292.2025.018929

Oliinyk, B. V., & Chychkarov, Ye. O. (2025). Methods of implementing retrieval-augmented generation in combination with modern large language models. Scientific Notes of the State University of Telecommunications. Series: Information Technologies, (3), 56–65. https://doi.org/10.31673/2412-1034.2025.03.3267

Gao, Y., Xiong, Y., Gao, X., et al. (2023). Retrieval-augmented generation for large language models: A survey. arXiv. https://doi.org/10.48550/arXiv.2312.10997

International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection—Information security management systems—Requirements. ISO.

Jiang, Z., Xu, F. F., Gao, L., et al. (2023). Active retrieval augmented generation. arXiv. https://doi.org/10.48550/arXiv.2305.06983

Karpukhin, V., Oguz, B., Min, S., et al. (2020). Dense passage retrieval for open-domain question answering. In Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP 2020) (pp. 6769–6781). Association for Computational Linguistics. https://doi.org/10.18653/v1/2020.emnlp-main.550

LangChain. (2025). LangChain Python documentation. https://python.langchain.com/en/latest/

Lewis, P., Perez, E., Piktus, A., et al. (2020). Retrieval-augmented generation for knowledge-intensive NLP tasks. Advances in Neural Information Processing Systems, 33. https://proceedings.neurips.cc/paper/2020/hash/6b493230205f780e1bc26945df7481e5-Abstract.html

Li, Z., Wang, J., Jiang, Z., et al. (2024). DMQR-RAG: Diverse multi-query rewriting for RAG. arXiv. https://doi.org/10.48550/arXiv.2411.13154

Singh, A., Ehtesham, A., Kumar, S., et al. (2025). Agentic retrieval-augmented generation: A survey on agentic RAG. arXiv. https://doi.org/10.48550/arXiv.2501.09136

Yao, S., Zhao, J., Yu, D., et al. (2023). ReAct: Synergizing reasoning and acting in language models. In Proceedings of the 11th International Conference on Learning Representations (ICLR 2023). https://doi.org/10.48550/arXiv.2210.03629

Zhao, P., Zhang, H., Yu, Q., et al. (2024). Retrieval-augmented generation for AI-generated content: A survey. arXiv. https://doi.org/10.48550/arXiv.2402.19473

Downloads


Abstract views: 6

Published

2026-09-24

How to Cite

Vynar, A., Svedeniuk, O., & Medynskyi, O. (2026). EVALUATION OF THE EFFECTIVENESS OF RAG ARCHITECTURES FOR AUTOMATION OF INFORMATION SECURITY POLICY ANALYSIS. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 2(34), 560–567. https://doi.org/10.28925/2663-4023.2026.34.1309