Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations: Threat Modeling for Autonomous AI Systems
- Classification of autonomous threats, including misuse, privilege escalation, data exfiltration, and supply-chain vulnerabilities
- Profiling adversaries and assessing attacker capabilities specific to autonomous agent operations
- Identifying critical assets, establishing trust boundaries, and determining essential control points for agent interactions
Governance, Policy, and Risk Management
- Establishing governance frameworks for autonomous systems, defining roles, responsibilities, and approval authorities
- Developing policies that define acceptable use, escalation procedures, data handling protocols, and audit requirements for government operations
- Addressing compliance obligations and establishing evidence collection standards for regulatory audits
Non-Human Identity and Authentication Protocols
- Architecture of machine identities, including service accounts, JSON Web Tokens (JWTs), and ephemeral credentials
- Implementing least-privilege access models and just-in-time credential provisioning
- Managing identity lifecycles, including rotation, delegation, and revocation processes for government systems
Access Controls, Secrets Management, and Data Protection
- Deploying fine-grained access control models and capability-based authorization patterns for agents
- Securing secrets, enforcing encryption in transit and at rest, and applying data minimization principles
- Safeguarding sensitive knowledge bases and Personally Identifiable Information (PII) against unauthorized agent access
Observability, Auditing, and Incident Response
- Designing telemetry frameworks for agent behavior, including intent tracing, command logging, and data provenance
- Integrating Security Information and Event Management (SIEM) systems, defining alert thresholds, and ensuring forensic readiness
- Developing runbooks and playbooks for managing agent-related incidents and executing containment measures
Red-Teaming Autonomous Systems
- Planning red-team engagements, defining scope, rules of engagement, and safe failover mechanisms
- Evaluating adversarial techniques such as prompt injection, tool misuse, chain-of-thought manipulation, and API exploitation
- Executing controlled attacks to measure system exposure and potential impact on government missions
System Hardening and Mitigation Strategies
- Implementing engineering controls, including response throttling, capability gating, and sandboxing environments
- Applying policy and orchestration controls, such as approval workflows, human-in-the-loop validation, and governance hooks for government oversight
- Deploying model-level defenses, including input validation, canonicalization, and output filtering mechanisms
Operationalizing Secure Agent Deployments
- Utilizing deployment patterns such as staging, canary releases, and progressive rollouts for agent systems
- Managing change control, testing pipelines, and pre-deployment safety verification checks
- Facilitating cross-functional governance coordination among security, legal, product, and operations teams
Capstone: Red-Team / Blue-Team Exercise
- Conducting a simulated red-team attack against a sandboxed agent environment
- Defending, detecting, and remediating threats as the blue team utilizing established controls and telemetry data
- Presenting findings, remediation strategies, and recommended policy updates
Summary and Next Steps
Requirements
- Demonstrated expertise in security engineering, system administration, or cloud operations
- Working knowledge of artificial intelligence/machine learning (AI/ML) principles and the operational dynamics of large language models (LLMs)
- Proficiency in identity and access management (IAM) frameworks and the implementation of secure system architectures
Audience
- Security engineers and red team operators
- AI operations and platform engineering personnel
- Compliance specialists and risk management professionals
- Engineering leadership overseeing agent deployments
21 Hours