As organizations rush to deploy AI, the gap between security leadership and AI-specific risk expertise keeps widening. This program bridges that gap by teaching experienced security managers how AI governance frameworks, risk assessments, and technical controls work in production environments. You will examine model-level threats, vendor and supply-chain exposure, and regulatory pressure such as the EU AI Act, then apply that knowledge through scenario-based labs mirroring the AAISM exam format.
Prerequisites
- Active CISM (Certified Information Security Manager) or CISSP (Certified Information Systems Security Professional) credential in good standing – this is ISACA’s mandatory gate for AAISM exam eligibility
- 2–3 years of hands-on experience in information security, IT risk, or security program management
- Working familiarity with AI/ML concepts (model training, inference, data pipelines) and governance frameworks such as NIST or ISO/IEC 27001
- Comfort with scenario-based, judgment-driven exam questions rather than pure recall
Course Objectives
- Understand the three AAISM domains: AI governance and program management, AI risk management, and AI technologies and controls
- Build and defend an AI security policy and program that stakeholders and boards can act
- Identify AI-specific threats – model poisoning, prompt injection, data leakage, adversarial inputs – and translate them into measurable risk
- Design security controls that fit machine learning pipelines, not just traditional IT infrastructure
- Map AI risk management to compliance obligations, including the EU AI Act, NIST AI RMF, and ISO/IEC 42001
- Prepare confidently for the scenario-based ISACA AAISM exam
What You Will Learn
- How to set up AI governance structures, ownership models, and escalation paths inside an existing security program
- How to inventory AI assets, data flows, and third-party models so nothing sits outside your risk register
- Techniques for assessing AI-specific threats: data poisoning, model inversion, adversarial manipulation, and shadow AI usage
- How to manage AI vendor and supply-chain risk, including foundation model providers and API-based tools
- Practical approaches to embedding privacy, ethics, and human oversight into AI systems without slowing delivery
- How to build and test an AI incident response plan, from detection through post-incident review
- Where AI security controls intersect with existing frameworks you already know from CISM or CISSP
Who Should Enroll in This Aaism Course?
This course is built for experienced security professionals who already hold a CISM or CISSP and are now being asked to own AI risk. It suits:
- Information security managers and CISOs extending their remit to cover AI systems
- IT risk and compliance officers responsible for AI governance frameworks
- Security architects and engineers designing controls for ML and generative AI deployments
- GRC (governance, risk, and compliance) leads preparing their organization for AI-specific regulation
- CISM or CISSP holders looking to differentiate their profile with an AI-focused credential
Skills You Will Gain
By the end of this training, you’ll be able to:
- Draft AI governance policies and secure executive buy-in
- Run structured AI risk assessments across the model lifecycle
- Select and justify technical controls for AI environments
- Evaluate AI vendors and third-party models for security exposure
- Respond to AI-related security incidents with a documented playbook
- Speak fluently about AI regulation, ethics, and enterprise risk appetite
Tools and Frameworks Covered
- NIST AI Risk Management Framework (AI RMF)
- ISO/IEC 42001 AI management system standard
- MITRE ATLAS (Adversarial Threat Landscape for AI Systems)
- OWASP Top 10 for LLM Applications
- Model governance and MLOps monitoring concepts (tool-agnostic)
- Cloud AI security posture, referenced through AWS, Azure, and GCP case studies
Career Outcomes
Completing this training positions you for senior roles where AI risk ownership is now expected. Typical roles include:
- AI Security Manager
- AI Governance Lead / AI Risk Officer
- CISO with AI Portfolio Oversight
- Enterprise Risk and Compliance Manager
- AI Security Consultant
- Security Program Manager, AI Systems
Why Choose kodestree?
kodestree brings together practical training design and real-world security experience to help you prepare with confidence. Here’s what you get:
- Instructor-led live sessions plus self-paced access
- Small batch sizes for direct instructor interaction
- Scenario-based labs mapped to the AAISM domains
- Flexible weekday, weekend, and fast-track batches
- 24×7 lifetime learner support
- 100% money-back guarantee
- Course completion certificate from kodestree