Generate TOM content with AI
How to have the measure texts of a TOM document generated by AI: in the detail view you open the “AI actions” menu, choose between “Only supplement content” and “Completely revise content”, add optional notes and apply the result.
Last updated:
A TOM document describes the technical and organisational measures with which you secure the confidentiality, integrity, availability and resilience of your systems. Instead of filling in every category by hand, you let the AI generate the measure texts and simply review the result.
Prerequisites
- Your team has access to the AI integration — only then does the “AI actions” selection menu appear at the top right.
- You have access to the associated organization, or the TOM document is shared for “All organisations”.
- You hold the permission to edit the TOM document.
- You are in the detail view of the technical and organisational measure (“Contents” tab).
Step by step
- Open the overview of technical and organisational measures and click anywhere in the row of the table to open the detail view.
- Click “AI actions” at the top right and select one of the two options:
- “Only supplement content” — the existing contents are supplemented with AI-generated content; existing texts and text modules are retained.
- “Completely revise content” — the entire content is replaced with AI-generated content; all existing texts and text modules are overwritten.
- In the side input window, under “Additional notes”, enter optional notes that will be added to the request to the AI.
- Click “Next” and confirm the security prompt with “Yes, only supplement content with AI” or “Yes, completely revise content using AI”.
- While the AI provider processes the request, a status window is displayed. The generated contents are then applied to the detail view automatically.
Review the result
- Go through the sections protection objective by protection objective — from “Ensuring confidentiality” and “Ensuring integrity” to “Ensuring availability, resilience and recoverability”.
- Click “Preview” at the top right to see the formatted version. In the rendered form, empty categories, duplicate measures and outdated references to systems that no longer exist are much easier to spot than in the individual input fields. Close the preview using the X at the top right.
- Correct any deviations via “Edit” and only then publish the document.
Practical tips
- Use “Completely revise content” only for an empty or clearly outdated TOM version. For a TOM document used in production, “Only supplement content” is safer — this way manually maintained, organization-specific measures are not lost.
- Use the “Additional notes” field for industry- and environment-specific details, for example
Cloud provider with AWS FrankfurtorHospital with patient monitoring system, so that the AI generates more suitable suggestions. - The AI takes care of the preparatory work — the professional responsibility for the documented measures stays with you and your team.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.