Strengthen AI governance and manage enterprise AI security risks using advanced AI security management practices.
Learners will learn how to manage AI-related security risks, implement AI governance frameworks, address compliance and ethical considerations, and apply security controls across AI systems and generative AI environments.
- Why get AAISM certified: Learn how to implement AI governance, manage AI security risks, apply compliance controls and secure enterprise AI and generative AI environments.
- Why AAISM matters: AI security management capabilities help organizations reduce AI-related risks, strengthen governance and support responsible and secure AI adoption.
- Who should attend: Security leaders, governance professionals, risk managers, AI practitioners and IT professionals responsible for securing and governing AI environments.
Build advanced AI governance and security management capabilities to support secure and responsible AI adoption with Trainocate. HRD Corp Claimable.

Overview
Develop the essential skills to safely guide AI transformation with the first credential built for tomorrow’s secure enterprise.
ISACA Advanced in AI Security Management (AAISM) validates security management professionals’ ability to demonstrate their expertise in AI. This credential builds upon existing security best practices to enhance expertise and adapt to the evolving AI-driven landscape, ensuring robust protection and a strategic edge.
As AI transforms business and security architecture, enterprise risk profiles are changing dynamically. Security leaders must do more than react. They must evaluate, adapt and guide organizations through new AI-driven systems and models, ethical considerations and security tools. Professionals today require both the technical context and leadership mindset to manage AI-specific vulnerabilities with confidence.
AAISM goes beyond simply visualizing AI security. It signifies expertise in driving AI governance and program management, assessing and mitigating AI risk, and utilizing AI technologies and controls to enhance security and streamline monitoring. ISACA’s AAISM certification meets this need by building on globally recognized credentials like CISM and CISSP. It equips leaders to:
- Evaluate and secure AI-enabled systems across the enterprise
- Integrate AI into existing security operations and workflows
- Identify and respond to risks tied to AI technologies
- Reinforce governance, compliance and responsible innovation
Discover Top ISACA Certifications for Malaysia’s Digital Trust Future: Advance your AI, cybersecurity, audit, governance, risk, and privacy capabilities with ISACA certifications built for the high impact roles organizations need in 2026.
Skills Covered
- Evaluate and secure AI-enabled systems across the enterprise
- Integrate AI into existing security operations and workflows
- Identify and respond to risks tied to AI technologies
- Reinforce governance, compliance and responsible innovation
Target Audience
- Security professionals holding a CISM or CISSP.
- Mid-to-late career.
- Some experience assessing, implementing and maintaining AI systems.

Module 1: AI Governance and Program Management
A. Stakeholder Considerations, Industry Frameworks, and Regulatory Requirements
- Organizational Structure and Overall Governance
- Roles and Responsibilities
- Charter and Steering Committee
- Identifying Stakeholders
- Risk Appetite and Tolerance
- Frameworks, Standards, and Regulations
- Selecting appropriate Frameworks
- Business and Use Cases for AI
- Privacy Considerations
B. AI-related Strategies, Policies, and Procedures
- AI Strategy
- Consumer v. Enterprise
- Buy vs. Build
- AI Policies
- Responsible Use
- Acceptable Use
- AI Procedures
- Implementation
- Manuals
- Ethics
C. AI Asset and Data Life Cycle Management
- AI Asset and Data Inventory
- Inventory management
- Model cards
- Data handling, classification, discovery
- Data Augmentation and Cleaning
- Data Storage
- Data Protection
- Destruction
D. AI Security Program Development and Management
- Documented Program Plan
- Security team, roles, responsibilities, and proficiencies
- Alignment to existing info sec
- Use of AI-enabled security tools in the program
- Metrics and management
- KRIs and KPIs for AI use with regard to the security
- Management reporting
E. Business Continuity and Incident Response
- Incident detection
- Notification
- Incident classification
- Criticality and severity
- Resiliency
- Business Continuity Plan
- Red-button requirements for compliance
- Incident response playbooks specifically for AI
- Break glass policies/ go no go
- Authority
- RTO RPO – AI perspective
- Disaster recovery
- Testing
Module 2: AI Risk Management
A. AI Risk Assessment, Thresholds, and Treatment
- Impact assessment
- conformity assessment
- PIAs
- Risk documentation
- Acceptable levels of risk
- Treatment plans
- KRIs and KPIs for AI us
B. AI-related Strategies, Policies, and Procedures
- PEN test
- Vulnerability tests
- Red teaming
- AI related vulnerabilities
- Adversarial threats
- Threat intelligence
- AI-enabled threats/Attack chains
- Anomalies
- Threat landscape
- Deep fakes
- Insider threat
- AI agents
C. AI Vendor and Supply Chain Management
- Dependencies of software packages and libraries
- Vendor due diligence and contracts
- SLAs
- Vendor usage
- Accountability models
- Provider vs. deployer
- Third, fourth, and fifth parties
- Ownership and intellectual property
- Access controls
- Liability
- Vendor monitoring for risk and changes
Module 3: AI Technologies and Controls
A. AI Security Architecture and Design
- Change management
- SDL
- Secure by design
- Securing infrastructure as code
- Data flows
- Approved base models
- Interconnectivity and interaction with architecture
B. AI Life Cycle (e.g., model selection, training, and validation)
- Testing models interconnectivity
- Linkages between models
- Regression
- Model testing
- Progression
- TEVV
- Model accuracy testing and evaluation
C. Data Management Controls
- Data collection
- Data control
- Data Poisoning
- BIAS
- Accuracy
- Data position requirements
D. Privacy, Ethical, Trust and Safety Controls
- Explainability
- Privacy controls – like right to be forgotten, data subject rights
- Consent
- Transparency
- Decision making
- Fairness
- Ethics
- Automated decision making
- Human in the loop
- Trust and safety – content moderation
- Potential harm
- Environmental impacts
- Data minimization and anonymization
E. Security Controls and Monitoring
- Security monitoring metrics
- Selecting the right controls
- Implementing controls
- Self-assessment of controls (CSA)
- Control life cycle
- Continuous monitoring
- KPIs and KRIs for security controls and monitoring
- Technical controls
- Threat controls mapping
- Security awareness training
Dates & Locations
July 22, 2026 - July 23, 2026
July 22, 2026 - July 23, 2026
September 17, 2026 - September 18, 2026
September 17, 2026 - September 18, 2026
November 12, 2026 - November 13, 2026
November 12, 2026 - November 13, 2026

Exam & Certification
Advanced in AI Security Management (AAISM)
From the creators of the award-winning CISM certification, ISACA Advanced in AI Security Management™ (AAISM™) certification prepares experienced IT security professionals to navigate the evolving risks of AI, implement essential controls, and ensure its responsible and effective use across the organization.
Passing the AAISM exam proves your ability to identify, assess, monitor and mitigate risk in a future shaped by disruptive technologies. You’ll be prepared to effectively leverage AI in security operations and deliver assurance across key practice areas, including:
- Modern Threat Response: confronting evolving threats with clarity and control. Confirms your ability to detect and respond to risks introduced by AI systems throughout the enterprise while adapting best practices.
- Operational AI Readiness: leveraging AI to reinforce security posture. Demonstrates your ability to evaluate, integrate and manage AI tools within security operations to increase visibility, reduce latency and achieve better outcomes.
- Strategic Agility: evolving with the pace of innovation. Validates your capacity to securely implement enterprise AI solutions to meet organizational objectives.
- Forward-Looking Leadership: increasing credibility in a dynamic industry. Empowers you to lead with confidence, precision and decisiveness.
Training & Certification Guide
Frequently Asked Questions
Speak to a Training Consultant
All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631























