Course Outline
Foundational Concepts of Artificial Intelligence and Cybersecurity
- Key distinctions between traditional systems and AI architectures from a security standpoint
- Comprehensive review of the AI lifecycle, encompassing data acquisition, model training, inference, and operational deployment
- Classification of AI-related risks into technical, ethical, legal, and organizational categories
Threat Vectors Specific to Artificial Intelligence
- Vulnerabilities associated with adversarial inputs and model integrity compromises
- Risks of model inversion attacks and unauthorized data extraction
- Threats posed by data poisoning during the training phase
- Security concerns within generative AI systems, including large language model misuse and prompt injection techniques
Frameworks for Managing Security Risks
- Application of the NIST Artificial Intelligence Risk Management Framework (NIST AI RMF)
- Alignment with ISO/IEC 42001 and other relevant industry standards for government operations
- Integration of AI risk assessments into existing enterprise Governance, Risk, and Compliance (GRC) structures
Principles of AI Governance and Regulatory Compliance
- Requirements for accountability, traceability, and auditability in AI systems
- The role of transparency, explainability, and fairness as critical security attributes
- Mitigation strategies for bias, discrimination, and potential downstream adverse impacts
Enterprise Preparedness and Policy Development
- Clarification of roles and responsibilities within organizational AI security programs
- Essential policy components covering the acquisition, development, utilization, and decommissioning of AI technologies
- Management of third-party risks associated with external AI tool providers
Regulatory Environment and International Developments
- Analysis of the EU AI Act and its implications for international regulatory harmonization
- Examination of U.S. Executive Order on Safe, Secure, and Trustworthy Artificial Intelligence
- Overview of emerging national frameworks and sector-specific compliance guidance for government entities
Optional Workshop: Risk Mapping and Internal Assessment
- Aligning practical AI applications with the core functions of the NIST AI RMF
- Conducting structured self-assessments of organizational AI risk posture
- Identification of internal deficiencies in AI security readiness for government agencies
Conclusion and Strategic Next Steps
Requirements
- Proficiency in fundamental cybersecurity concepts
- Practical knowledge of information technology governance and risk management frameworks
- Awareness of artificial intelligence principles is beneficial but not mandatory
Target Audience
- Information technology security personnel
- Risk management specialists
- Regulatory compliance officers
Testimonials (2)
I really enjoyed learning about AI attacks and the tools out there to begin practicing and actively using for security testing. I took a lot of knowledge away which I didn't have at the beginning and the course met what I hoped it would be. My favorite part shown from the training was Comet Browser and was amazed at what it could do. Definitely something will be looking into more. Overall it was a great course and enjoyed learning all OWASP GenAI Top 10.
Patrick Collins - Optum
Course - OWASP GenAI Security
The profesional knolage and the way how he presented it before us