Course Outline
Fundamentals of AI and Security
- The unique security characteristics of AI systems
- A comprehensive view of the AI lifecycle: data processing, training, inference, and deployment
- Basic classification of AI risks: technical, ethical, legal, and organizational
AI-Specific Threat Vectors
- Adversarial examples and techniques for model manipulation
- Risks associated with model inversion and data leakage
- Data poisoning vulnerabilities during the training phase
- Specific risks in generative AI, such as LLM misuse and prompt injection
Security Risk Management Frameworks
- The NIST AI Risk Management Framework (NIST AI RMF)
- ISO/IEC 42001 and other AI-specific standards
- Integrating AI risk into existing enterprise GRC frameworks
AI Governance and Compliance Principles
- Ensuring AI accountability and auditability
- Transparency, explainability, and fairness as critical security properties
- Addressing bias, discrimination, and downstream harms
Enterprise Readiness and AI Security Policies
- Defining roles and responsibilities within AI security programs
- Key policy components: development, procurement, usage, and retirement
- Managing third-party risks and the use of supplier AI tools
Regulatory Landscape and Global Trends
- An overview of the EU AI Act and international regulatory frameworks
- The U.S. Executive Order on Safe, Secure, and Trustworthy AI
- Emerging national frameworks and sector-specific guidance
Optional Workshop: Risk Mapping and Self-Assessment
- Mapping real-world AI use cases to NIST AI RMF functions
- Conducting a basic AI risk self-assessment
- Identifying internal gaps in AI security readiness
Summary and Next Steps
Requirements
- A solid grasp of basic cybersecurity principles
- Practical experience with IT governance or risk management frameworks
- While not mandatory, familiarity with general AI concepts is beneficial
Target Audience
- IT security teams
- Risk managers
- Compliance professionals
Testimonials (3)
inventory and identifying the different risk exposures within AI
Gary Cook - Cybersecurity and Information Technology Risk Division
Course - Introduction to AI Trust, Risk, and Security Management (AI TRiSM)
I really enjoyed learning about AI attacks and the tools out there to begin practicing and actively using for security testing. I took a lot of knowledge away which I didn't have at the beginning and the course met what I hoped it would be. My favorite part shown from the training was Comet Browser and was amazed at what it could do. Definitely something will be looking into more. Overall it was a great course and enjoyed learning all OWASP GenAI Top 10.
Patrick Collins - Optum
Course - OWASP GenAI Security
The profesional knolage and the way how he presented it before us