Course Outline
AI and Security Fundamentals
- What distinguishes AI systems from a security standpoint.
- An overview of the AI lifecycle: data collection, training, inference, and deployment.
- A basic classification of AI risks: technical, ethical, legal, and organizational.
AI-Specific Threat Vectors
- Adversarial examples and techniques for model manipulation.
- Risks associated with model inversion and data leakage.
- Data poisoning vulnerabilities during the training phase.
- Security concerns in generative AI, such as LLM misuse and prompt injection.
Security Risk Management Frameworks
- The NIST AI Risk Management Framework (NIST AI RMF).
- ISO/IEC 42001 and other specialized AI standards.
- Integrating AI risks into existing enterprise GRC frameworks.
AI Governance and Compliance Principles
- Establishing AI accountability and ensuring auditability.
- The role of transparency, explainability, and fairness as security-critical attributes.
- Addressing bias, discrimination, and potential downstream harms.
Enterprise Readiness and AI Security Policies
- Defining clear roles and responsibilities within AI security programs.
- Key policy components: development, procurement, usage, and retirement.
- Managing third-party risks and the usage of supplier AI tools.
Regulatory Landscape and Global Trends
- An overview of the EU AI Act and other international regulations.
- The U.S. Executive Order on Safe, Secure, and Trustworthy AI.
- Emerging national frameworks and sector-specific guidance.
Optional Workshop: Risk Mapping and Self-Assessment
- Mapping real-world AI use cases to NIST AI RMF functions.
- Conducting a foundational AI risk self-assessment.
- Identifying internal gaps in AI security readiness.
Summary and Next Steps
Requirements
- Solid grasp of fundamental cybersecurity principles.
- Practical experience with IT governance or risk management frameworks.
- Basic familiarity with general AI concepts is advantageous but not mandatory.
Target Audience
- IT security teams.
- Risk managers.
- Compliance specialists.
Testimonials (3)
inventory and identifying the different risk exposures within AI
Gary Cook - Cybersecurity and Information Technology Risk Division
Course - Introduction to AI Trust, Risk, and Security Management (AI TRiSM)
I really enjoyed learning about AI attacks and the tools out there to begin practicing and actively using for security testing. I took a lot of knowledge away which I didn't have at the beginning and the course met what I hoped it would be. My favorite part shown from the training was Comet Browser and was amazed at what it could do. Definitely something will be looking into more. Overall it was a great course and enjoyed learning all OWASP GenAI Top 10.
Patrick Collins - Optum
Course - OWASP GenAI Security
The profesional knolage and the way how he presented it before us