Free Download Total ISACA Advanced in AI Security Management (AAISM)
Published 8/2026
Created by Total Seminars Over 1 Million Enrollments, Michael Solomon
MP4 | Video: h264, 1920x1080 | Audio: AAC, 44.1 KHz, 2 Ch
Level: Intermediate | Genre: eLearning | Language: English | Duration: 47 Lectures ( 6h 30m ) | Size: 8.4 GB
Build an AI security program: governance, risk, vendors, incidents, and controls. Unofficial AAISM exam prep.
What you'll learn
Prepare for all three domains of the ISACA AAISM certification exam, covering every one of the thirteen exam objectives
Determine whether your organization is a provider or a deployer under the EU AI Act, and what each role legally obliges you to do
Build an AI governance program: steering committee charter, risk appetite, asset inventory, policy set, and executive reporting
Assess and manage AI risk - impact analysis, risk registers, treatment planning, and resiliency for production models
Run due diligence on AI vendors and manage third, fourth, and fifth-party AI supply chain risk
Threat model an LLM application using MITRE ATLAS and the OWASP LLM Top 10, and scope AI penetration testing
Detect, classify, and respond to AI incidents, including red-button and break-glass controls for production systems
Select, implement, and monitor AI security controls across the model lifecycle, from data pipeline to deployed systemRequirements
Working familiarity with information security, risk management, audit, or compliance - this is not an entry-level security course
No machine learning, data science, or programming experience required; the course teaches no model building and requires no coding
No lab environment, software, or subscriptions needed - all lessons are video-based
To sit the AAISM exam itself, ISACA requires candidates to hold an active CISM or CISSP certification. The course content is valuable to any AI security or governance practitioner, but registering for the exam requires meeting ISACA's eligibility criteria.Description
Enterprise AI has outrun enterprise security. This course closes the gap.
Your organization is deploying AI faster than it can govern it. Models are going into production without an owner, vendors are answering security questionnaires with certifications that say nothing about their training data, and the board has started asking questions that nobody in the room can answer. Meanwhile a new class of regulation - led by the EU AI Act - is assigning legal obligations to companies based on a role most of them have never formally determined.
This course teaches you how to govern, assess, and secure AI systems in a real enterprise, and prepares you for ISACA's Advanced in AI Security Management (AAISM) certification exam. It covers all three exam domains and every one of the thirteen exam objectives, taught by Dr. Michael Solomon across 47 focused video lessons.
What makes this different from a generic AI course
This is not an introduction to machine learning, and it is not a prompt-engineering course. It assumes you already work in security, risk, audit, or compliance, and it starts where your existing expertise stops: at the point where AI systems break the assumptions your current controls were built on.
Every module is built around a decision you will actually have to make. Which governance model fits your organization. Whether you are a provider or a deployer under the EU AI Act, and what each role obliges you to do. What to ask an AI vendor that a SOC 2 report will not answer. How to classify an AI incident when your existing severity matrix has no category for a model that started producing subtly wrong output three weeks ago. When to press the red button on a production model, who is allowed to press it, and what has to be true before you turn it back on.
Why your existing controls do not simply extend to AI
Most security programs try to absorb AI as one more asset class, and most of them discover the same four problems. A model that passes acceptance testing can degrade quietly in production, so a control that verifies something once is no longer a control. The training data is an attack surface, which means your supply chain now includes parties you have never contracted with and cannot audit. A model update changes system behavior without changing a line of code, so your change management process never sees it. And the vendor at the center of it will hand you an ISO 27001 certificate or a SOC 2 report that is necessary but nowhere near sufficient.
This course works through each of those, not as theory but as the specific controls, documents, and decisions that address them - and it names the failure patterns that show up when organizations skip the step.
What the course covers
Domain 1 - AI Governance and Program Management
Governance structures and steering committee charters - centralized, federated, and hybrid models, and how to choose
Stakeholder identification, RACI, and accountability that survives an audit
AI risk appetite and risk tolerance, and how they drive every escalation rule downstream
Framework selection and regulatory alignment: the EU AI Act, NIST AI RMF, and ISO/IEC 42001
AI use case governance, intake, and approval; consumer versus enterprise AI strategy
Buy-versus-build decisions, AI policy development, acceptable use, and responsible use principles
AI asset inventory, model cards, and documentation standards
Data classification, discovery, augmentation, cleaning, secure storage, retention, and destruction
Building an AI security program: team structure, proficiencies, metrics, KPIs and KRIs, and executive reporting
AI incident detection, notification, classification, and severity
AI resiliency and business continuity planning; RTO, RPO, and disaster recovery for models
Red-button and break-glass controls for production AIDomain 2 - AI Risk Management
AI risk assessment and impact analysis; risk documentation and treatment planning
Penetration testing and vulnerability testing of AI systems - scoping, authorization, and findings disposition
Threat modeling for LLM applications: attack surfaces, trust boundaries, MITRE ATLAS, and the OWASP LLM Top 10
Threat intelligence and AI attack chains; deepfakes, insider threat, and AI agents
Vendor due diligence and contracts; provider versus deployer accountability; third, fourth, and fifth-party risk
Intellectual property ownership and liability; vendor monitoring and risk change managementDomain 3 - AI Technologies and Controls
AI security architecture and change management - why a model update is not a patch
Model testing, regression testing, and continuous evaluation of deployed models
Data management controls and data poisoning: provenance, integrity, and pipeline access
Privacy, ethical, and trust controls; explainability, bias, and fairness
Control selection, implementation, and lifecycle management
Security monitoring metrics and threat-to-control mappingHow the course is taught
Forty-seven video lessons, six and a half hours total, each one focused enough to watch in a single sitting. Three orientation lessons open the course with what the credential is, what the exam looks like, and what it can do for your career. Every lesson after that maps to a specific exam objective, so you always know which part of the blueprint you are covering.
The course includes 106 knowledge-check questions, each tied to the lesson it tests and the exam objective it covers, so you can find and close a weak area rather than simply retaking a practice test until the score improves.
What you will be able to do when you finish
Walk into a steering committee and propose a governance model, and know what a charter has to contain. Read your own AI stack against the EU AI Act and say which role your organization holds and what that obliges. Sit across from an AI vendor knowing which categories a due-diligence questionnaire has to cover and why a SOC 2 report does not close them. Take an AI incident from first alert through classification, notification, and containment without improvising. Tell your board what your AI risk actually is, in terms they can act on. And go into the AAISM exam having covered all thirteen objectives on the blueprint.
Common questions
Do I need a technical background? No. There is no coding, no model building, and no lab. You need working familiarity with security, risk, audit, or compliance - the course starts from there.
Is this only useful if I sit the exam? No. The exam blueprint is a well-built map of what an AI security practitioner needs to know, which is why the course follows it. Everything here applies to the job whether or not you ever register for the exam.
Which frameworks does it use? The course works from the EU AI Act throughout, and draws on the NIST AI Risk Management Framework, ISO/IEC 42001, MITRE ATLAS, and the OWASP LLM Top 10 where each applies.
Who this is for
Security managers, IT risk professionals, internal auditors, compliance officers, privacy leads, and consultants who are being asked to evaluate AI systems and have no established playbook for it. You do not need to be a data scientist. You do not need to be able to train a model. You need to understand how AI systems introduce risk, how to evaluate the controls over them, and how to apply governance and audit methodology in an AI context - which is exactly what this course teaches and exactly what the AAISM exam tests.
About the instructor
Dr. Michael Solomon has spent his career at the intersection of security, risk, and governance, and has authored and taught certification courseware across the security profession. He teaches the material the way a practitioner needs it: the concept, the decision it drives, and the failure pattern that shows up when organizations get it wrong.
Who this course is for
Security managers and CISOs who have just been handed AI as a new remit and need a program, not a reading list
IT risk professionals and internal auditors who are being asked to assess AI systems with no established methodology
Compliance officers, privacy leads, and DPOs who own EU AI Act readiness and need to know what their organization actually owes
Third-party risk and procurement professionals now responsible for evaluating AI vendors
Security architects and engineers who need to threat model and secure LLM applications and AI data pipelines
CISM and CISSP holders pursuing the AAISM credential as a specialization
Consultants advising enterprises on AI governance, risk, and securityHomepage
Code:
https://www.udemy.com/course/total-isaca-advanced-in-ai-security-management-aaism
View hidden content is available for registered users!
No Password - Links are Interchangeable