Course Outline
Foundations of AI and Security
- What distinguishes AI systems from a security standpoint
- Overview of the AI lifecycle: data, training, inference, and deployment
- Basic classification of AI risks: technical, ethical, legal, and organizational
AI-Specific Threat Vectors
- Adversarial examples and techniques for model manipulation
- Risks of model inversion and data leakage
- Data poisoning vulnerabilities during training phases
- Security concerns in generative AI (e.g., LLM misuse, prompt injection)
Security Risk Management Frameworks
- The NIST AI Risk Management Framework (NIST AI RMF)
- ISO/IEC 42001 and other AI-specific standards
- Integrating AI risk into existing enterprise GRC frameworks
AI Governance and Compliance Principles
- AI accountability and auditability requirements
- Transparency, explainability, and fairness as security-critical attributes
- Addressing bias, discrimination, and downstream impacts
Enterprise Readiness and AI Security Policies
- Establishing roles and responsibilities within AI security programs
- Key policy components: development, procurement, usage, and retirement
- Managing third-party risks and the use of supplier AI tools
Regulatory Landscape and Global Trends
- Overview of the EU AI Act and international regulatory shifts
- U.S. Executive Order on Safe, Secure, and Trustworthy AI
- Emerging national frameworks and sector-specific recommendations
Optional Workshop: Risk Mapping and Self-Assessment
- Mapping practical AI use cases to NIST AI RMF functions
- Conducting a fundamental AI risk self-assessment
- Identifying internal gaps in AI security preparedness
Summary and Next Steps
Requirements
- Basic knowledge of cybersecurity principles
- Prior exposure to IT governance or risk management frameworks
- General familiarity with AI concepts is beneficial but not mandatory
Target Audience
- IT security teams
- Risk managers
- Compliance professionals
Testimonials (3)
inventory and identifying the different risk exposures within AI
Gary Cook - Cybersecurity and Information Technology Risk Division
Course - Introduction to AI Trust, Risk, and Security Management (AI TRiSM)
I really enjoyed learning about AI attacks and the tools out there to begin practicing and actively using for security testing. I took a lot of knowledge away which I didn't have at the beginning and the course met what I hoped it would be. My favorite part shown from the training was Comet Browser and was amazed at what it could do. Definitely something will be looking into more. Overall it was a great course and enjoyed learning all OWASP GenAI Top 10.
Patrick Collins - Optum
Course - OWASP GenAI Security
The profesional knolage and the way how he presented it before us