- Overview
- Course Details
ISACA Advanced in AI Security Management (AAISM) validates security management professionals’ ability to demonstrate their expertise in AI. This credential builds upon existing security best practices to enhance expertise and adapt to the evolving AI-driven landscape, ensuring robust protection and a strategic edge.
ISACA Advanced in AI Security Management (AAISM) Certification
Must possess a CISM or CISSP to be eligible for Certification.
Course Overview
ISACA Advanced in AI Security Management (AAISM) validates security management professionals’ ability to demonstrate their expertise in AI. This credential builds upon existing security best practices to enhance expertise and adapt to the evolving AI-driven landscape, ensuring robust protection and a strategic edge.
Course Objectives
In this course you will learn skills which:
Establishes AI-Specific Security Expertise
Bridges the Gap Between AI and Cybersecurity
Aligns with Enterprise Governance and Risk Needs
Built on ISACA’s Trusted Frameworks.
Course Syllabus
Module 1: AI Governance and Program Management
Section A. Stakeholder Considerations, Industry Frameworks, and Regulatory Requirements
1.Organizational Structure and Overall Governance
2.Roles and Responsibilities
3.Charter and Steering Committee
4.Identifying Stakeholders
5.Risk Appetite and Tolerance
6.Frameworks, Standards, and Regulations
7.Selecting appropriate Frameworks
8.Business and Use Cases for AI
9.Privacy Considerations
Section B. AI-related Strategies, Policies, and Procedures
1.AI Strategy
2.Consumer v. Enterprise
3.Buy vs. Build
4.AI Policies
5.Responsible Use
6.Acceptable Use
7.AI Procedures
8.Implementation
9.Manuals
10.Ethics
Section C. AI Asset and Data Life Cycle Management
1.AI Asset and Data Inventory
2.Inventory management
3.Model cards
4.Data handling, classification, discovery
5.Data Augmentation and Cleaning
6.Data Storage
7.Data Protection
8.Destruction
Section D. AI Security Program Development and Management
1.Documented Program Plan
2.Security team, roles, responsibilities, and proficiencies
3.Alignment to existing info sec
4.Use of AI-enabled security tools in the program
5.Metrics and management
6.KRIs and KPIs for AI use with regard to the security
7.Management reporting
Section E. Business Continuity and Incident Response
1.Incident detection
2.Notification
3.Incident classification
4.Criticality and severity
5.Resiliency
6.Business Continuity Plan
7.Red-button requirements for compliance
8.Incident response playbooks specifically for AI
9.Break glass policies/ go no go • Authority
10.RTO RPO – AI perspective
11.Disaster recovery
12.Testing
Module 2. AI Risk Management
Section A. AI Risk Assessment, Thresholds, and Treatment
1.Impact assessment
2.Conformity assessment
3.PIAs
4.Risk documentation
5.Acceptable levels of risk
6.Treatment plans
7.KRIs and KPIs for AI us
Section B. AI-related Strategies, Policies, and Procedures
1.PEN test
2.Vulnerability tests
3.Red teaming
4.AI related vulnerabilities
5.Adversarial threats
6.Threat intelligence
7.AI-enabled threats/Attack chains
8.Anomalies
9.Threat landscape
10.Deep fakes
11.Insider threat
12.AI agents
Section C. AI Vendor and Supply Chain Management
1.Dependencies of software packages and libraries
2.Vendor due diligence and contracts
3.SLAs
4.Vendor usage
5.Accountability models
6.Provider vs. deployer
7.Third, fourth, and fifth parties
8.Ownership and intellectual property
9.Access controls
10.Liability
11.Vendor monitoring for risk and changes
Module 3. AI Technologies and Controls
Section A. AI Security Architecture and Design
1.Change management
2.SDL
3.Secure by design
4.Securing infrastructure as code
5.Data flows
6.Approved base models
7.Interconnectivity and interaction with architecture
Section B.AI Life Cycle (e.g., model selection, training, and validation)
1.Testing models interconnectivity
2.Linkages between models
3.Regression
4.Model testing
5.Progression
6.TEVV
7.Model accuracy testing and evaluation
Section C. Data Management Controls
1.Data collection
2.Data control
3.Data Poisoning
4.BIAS
5.Accuracy
6.Data position requirements
Section D. Privacy, Ethical, Trust and Safety Controls
1.Explainability
2.Privacy controls – like right to be forgotten, data subject rights
3.Consent
4.Transparency
5.Decision making
6.Fairness
7.Ethics
8.Automated decision making
9.Human in the loop
10.Trust and safety – content moderation
11.Potential harm
12.Environmental impacts
13.Data minimization and anonymization
Section E. Security Controls and Monitoring
1.Security monitoring metrics
2.Selecting the right controls
3.Implementing controls
4.Self-assessment of controls (CSA)
5.Control life cycle
6.Continuous monitoring
7.KPIs and KRIs for security controls and monitoring
8.Technical controls
9.Threat controls mapping
10.Security awareness training.
Who should attend
Ops/SRE/DevOps engineers, cloud administrators, solution architects, and security-minded developers who need to operate (not just prototype) in AWS across small to mid-sized production estates.
Certification
The Exam Format:
Domain 1 – AI Governance and Program Management (31%)
Domain 2 – AI Risk Management (31%)
Domain 3 – AI Technologies and Controls (38%)
The Exam Passing score:
You must receive a score of 450 or higher to pass the exam which represents the minimum standard of knowledge.
The Scoring range is between 200-800
2.5 hours (150 minutes),
90 multiple choice questions.
Exam duration: 150 minutes.