01Overview
The entry point to the curriculum: the AI threat landscape, an attack taxonomy and core defensive principles, drawn from documented public cases.
The defensive core: AI threat taxonomy, control-plane implementation, token security, pipeline and model integrity, and AI incident response.
Intended for: Security practitioners moving into AI security or deepening it
02Learning outcomes
Proposed- Trace a request through an AI system and name its trust boundaries
- Distinguish application-layer attacks from model-layer compromise
- Apply foundational token and credential controls to AI systems
- Read and apply SHALL, SHOULD and MAY control requirements
- Triage an AI incident report using a four-phase method
- State what evidence shows a control is working, and what it cannot show
03Proposed case references
Source review pendingProposed connection, subject to source review. The threat taxonomy taught here follows the attack classification applied to cases I-3 to I-6. Learners use the same categories used to classify these documented cases, not a taxonomy built from scratch.
04Proposed framework references
Under reviewControl framework alignment and control level are published with the approved specification. Referencing a framework does not mean its publisher has approved or endorsed a course.
05How a request crosses an AI system
Proposed06Syllabus
4 modules · 9 topics · proposedAI threat landscape and system boundaries
- Components and trust boundaries
- Where AI differs from conventional software
Threats to data, models and applications
- Threats across the lifecycle
- Reading a public incident disclosure
- Lab 01 · Trace a request through an AI pipeline
Defensive principles and control context
- Token and credential lifecycle
- SHALL, SHOULD and MAY in practice
Applying concepts to incident material
- A four-phase triage method
- Lab 02 · Triage an AI incident report
07Practical labs
Proposed- Scenario
- A deployed AI assistant with retrieval, tools and an API.
- Inputs
- Architecture diagram, configuration extract, request log.
- Task
- Follow one request and mark where identity, data or configuration could change.
- Output
- An annotated pipeline map naming each trust boundary.
- Criteria
- Completeness, accuracy, support from the inputs.
- Scenario
- A published incident disclosure involving an AI system.
- Inputs
- Disclosure text and a timeline extract.
- Task
- Classify it, separate known from unknown, choose next steps.
- Output
- A short written triage note.
- Criteria
- Classification, stated limits, justified next steps.
08Assessment
Proposed · draft specificationCovers all four modules
Retake rules in the regulations
Both reviewed against criteria
Proposed rule: a passing exam score alone would not be enough; both labs would also need to be passed.
09Instructor
Instructors are practitioners appointed against a written standard for the ASD domain.