AI Security & Governance: A Practitioner’s Program
Build practical skills to govern, secure and operate enterprise AI systems — from LLMs and RAG applications to AI agents and production AI operations.
AI Security and Governance Training Overview
AI is rapidly moving into enterprise applications, RAG systems, AI agents and business workflows. This hands-on AI security and governance training program helps technology, security, risk, compliance and business teams understand how to securely develop, deploy, govern and operate AI systems.
Across three days, participants explore AI governance, AI risk management, responsible AI, ISO/IEC 42001, NIST AI RMF, AI threat modeling, LLM security, RAG security, agentic AI security and AI operations through practical exercises, case studies and a hands-on capstone.
Govern → Secure → Operate AI
The program connects governance and risk with the engineering realities of modern AI. Participants move from understanding governance requirements to securing AI systems and then operating them responsibly in production.
Govern AI
AI foundations, responsible AI, regulatory considerations, ISO/IEC 42001, NIST AI RMF, auditability and accountability.
Secure AI
AI development, threat modeling, prompt injection, data poisoning, supply-chain risk, guardrails and secure AI practices.
Operate AI
RAG, AI agents, secure data, MLOps/AIOps, monitoring, observability and incident response for AI systems.
AI Governance, Risk & Compliance (AI GRC)
AI GRC brings together AI governance, risk management and compliance practices needed to deploy AI responsibly and securely. This program introduces practical approaches for identifying AI risks, establishing governance controls, documenting AI systems and working with recognized frameworks and standards.
Frameworks, Standards & Security References
The curriculum introduces the following frameworks and references as part of the governance and security learning journey.
Who Should Attend AI Security & Governance Training?
What You’ll Learn
- A common language for AI, ML, LLMs and agentic systems across technical and non-technical teams
- How to navigate AI governance and risk concepts including EU AI Act, NIST AI RMF and ISO/IEC 42001
- A repeatable method for threat-modeling AI systems using MAESTRO and STRIDE
- Hands-on approaches to secure AI development, guardrails and cost/token optimization
- How RAG and agent architectures work — and how to protect the data and access paths behind them
- Operational practices for monitoring, observing and responding to AI incidents in production
- A capstone experience applying governance, security and operational controls to a real-world scenario
What Does AI Security Training Cover?
The security component focuses on the risks introduced by modern AI applications and the controls used to reduce them. Topics include:
- Prompt injection, data leakage and output validation
- Data poisoning, model theft and AI supply-chain risks
- AI threat modeling using STRIDE, MITRE ATLAS and MAESTRO
- Input/output validation, guardrails, sandboxing and secrets management
- RAG security, vector-store access control and sensitive-data protection
- AI agent security, tool calling, human-in-the-loop controls and orchestration risks
- Monitoring, observability and incident response for production AI systems
AI Governance with ISO/IEC 42001 and NIST AI RMF
The program introduces participants to ISO/IEC 42001 and the NIST AI Risk Management Framework (AI RMF) as part of a broader AI governance and risk-management perspective. Participants also explore responsible AI principles, auditability, accountability, model versioning and lineage tracking.
This is a practitioner-focused training program. It should not be interpreted as an accredited ISO/IEC 42001 certification unless a separate certification offering is explicitly stated by the training provider.
AI Security & Governance Training Curriculum
Module 1Definitions & Terminology
- Core AI/ML vocabulary — machine learning, deep learning, LLMs, tokens, embeddings, inference, fine-tuning, hallucinations and prompt engineering.
Module 2Types of AI & AI Applications
- Overview of generative AI, predictive AI, classification, NLP, computer vision and real-world enterprise use cases.
Module 3AI Agents
- What AI agents are, how they differ from simple LLM calls — autonomy, tool use, planning loops, memory and multi-agent architectures.
Module 4Standards & Regulatory Landscape
- EU AI Act, NIST AI RMF, ISO/IEC 42001, Executive Orders and sector-specific requirements.
Module 5AI Security & Governance Frameworks
- OWASP Top 10 for LLMs, ISO/IEC 42001, NIST AI RMF and MITRE ATLAS.
Module 6Explainability (XAI)
- Why AI decisions need to be interpretable — SHAP, LIME, attention visualization and regulatory considerations.
Module 7Auditability & Accountability
- Logging AI decisions, audit trails, model versioning and lineage tracking.
Module 8AI Data Readiness (AIDR)
- Data quality, governance, bias detection and labeling standards.
Module 9Responsible AI Principles
- Fairness, transparency, privacy, safety, inclusiveness and reliability.
Module 1AI Development Lifecycle (AIDLC)
- Problem framing, data preparation, model selection, training, evaluation, deployment and decommissioning.
Module 2AI as a Consumer (Copilot, ChatGPT, etc.)
- Prompt hygiene, data leakage prevention, acceptable-use policies and output validation.
Module 3Token Optimization
- Context-window management, prompt compression, chunking, caching and model/tier selection to reduce latency and cost.
Module 4AI in Applications (Integration Patterns)
- APIs, SDKs, orchestration layers and architecture patterns including retrieval-augmented, agentic and fine-tuned systems.
Module 5AI Threat Modeling
- Prompt injection, data poisoning, model theft and supply-chain risks mapped to STRIDE and MITRE ATLAS.
Module 6MAESTRO Framework
- AI security threat modeling methodology and its layers.
Module 7Secure AI Development Practices
- Input/output validation, guardrails, sandboxing and secrets management.
Module 1Retrieval-Augmented Generation (RAG)
- Chunking strategies, embedding models, vector databases, retrieval pipelines and re-ranking.
Module 2AI Agents (Advanced)
- Tool calling, reasoning workflows, guardrails, human-in-the-loop and multi-agent orchestration.
Module 3Secure Data Modeling for AI
- Access controls on vector stores, data classification, PII/PHI filtering and differential privacy.
Module 4AI Operations (AIOps / MLOps)
- Model deployment pipelines, A/B testing, canary rollouts, model registry and versioning.
Module 5Monitoring & Observability
- Drift detection, performance degradation, hallucination tracking and cost monitoring.
Module 6Incident Response for AI Systems
- Containment strategies, bias incidents, data breach through AI and communication playbooks.
Module 7Capstone Exercise
- Threat-model a RAG-based AI application, identify risks, apply controls from Days 1–3 and present findings.
Delivery Details
- Delivered as classroom or live virtual instructor-led training — 3 full-day sessions, or split across 6 half-days to fit your team’s schedule
- Includes real-world case studies and a hands-on capstone applying governance, security and operations controls to a RAG-based scenario
- Labs and exercises are illustrative and may vary by trainer approach and participant technical background
- Can be delivered as a customized corporate training program aligned to your organization’s AI initiatives and audience
Frequently Asked Questions About AI Security & Governance Training
What is AI security and governance training?
Who should attend AI governance and security training?
Does the program cover ISO/IEC 42001?
Does the training cover NIST AI RMF?
Does the program include AI threat modeling?
Does the course cover LLM, RAG and generative AI security?
Is this AI security training suitable for corporate teams?
Is this an ISO/IEC 42001 certification program?
Can the program be customized for our organization?
Build AI Security & Governance Capability Across Your Team
Discuss your AI security, governance, risk or responsible AI training requirements with the Optimistik Infosystems team.
Request This ProgramRelated AI Training
Key Topics
- AI Governance & AI GRC
- AI Security & Threat Modeling
- ISO/IEC 42001
- NIST AI RMF
- LLM & Generative AI Security
- RAG Security
- AI Agent Security
- AI Operations & Incident Response