🧭 Course OverviewWhat Genuinely Changes for AI
AI-103: AI Cybersecurity Foundations bridges traditional information security principles with the demands of AI-enabled enterprise environments. Built on the structure of ISACA's CISM domains — governance, risk management, program development, and incident management — this course adds the AI-specific layer that those frameworks do not yet fully address.
The course is organized around a core question: What genuinely changes when the systems you are securing learn from data, generate probabilistic outputs, and can be manipulated through their inputs in ways that have no parallel in traditional software? Students will work through governance frameworks, risk taxonomies, threat landscapes, architectural controls, and incident response — each adapted for the AI context.
Daily pattern: Each 4-hour class divides into Part A (mini-lecture + structured activity — poll, think-pair-share, or micro case) and Part B (lab, case study, or tabletop aligned to that day's objectives). Assessment artifacts are produced every day.
Prerequisites: Foundational cybersecurity knowledge equivalent to CompTIA Security+ or equivalent coursework. Familiarity with basic risk management concepts is helpful but not required.
Structure. The course is 15 lessons (labeled Day 1–Day 15), each equivalent to roughly one 4-hour class session. Every lesson follows the same rhythm, so you always know what to expect:
Part A (mini-lecture + a short structured activity — poll, think-pair-share, or micro-case) → Part B (a lab, case study, or tabletop tied to that lesson's objectives) → a daily artifact you produce (memo, worksheet, or builder) → a short, ungraded knowledge check to confirm you're ready to move on.
Pacing (delivered across a term). Although each lesson is written as a "Day," this course is spaced across a full term — plan on one lesson per weekly session, not 15 consecutive days. Budget about 4 hours of guided/contact time per lesson plus independent time to finish the daily artifact. The spacing is a feature: use the gap between sessions to complete the artifact, review the knowledge check, and let concepts consolidate before the next unit. The capstone reuses your Day 1 artifacts, so keep your work organized as you go.
Suggested cadence: Days 1–5 (governance & risk foundations) → Days 6–10 (threat landscape & architecture) → Days 11–15 (policy, incident response, red-teaming & capstone). Knowledge checks are formative and do not affect your grade — use them to self-assess.
🧪 About the Labs & Activities
Every lesson includes hands-on activities — but in this course, "lab" means structured applied analysis, not live coding or attacking real systems. Activities are scenario classifiers, decision labs, matchers, and builders (risk registers, governance charters, threat models, defense matrices), plus think-pair-share and worksheets — all set in realistic scenarios such as an MVCC AI enrollment assistant. You apply the frameworks to a realistic case and produce a written artifact.
Where an activity mentions tools, API keys, or sandboxes, those appear as analysis material (things to reason about), not instructions to run live systems. No programming environment or coding is required. The capstone (Day 15) is a synthesis and presentation of your accumulated artifacts.
♿ Accessibility & Accommodations
Moraine Valley Community College is committed to equal access. If you need academic accommodations (extended time, alternate formats, assistive technology, or other support), please arrange them early through the college's disability-services office. Instructors will work with you to implement approved accommodations.
[Instructor: insert the official MVCC Center for Disability Services statement here — office name, location, phone, email, and the college's standard accommodation language — and link the syllabus accessibility policy.]
Materials accessibility. These web lessons use semantic headings, keyboard-operable interactions, and alt text on informative graphics; interactive cards and sorting activities include text fallbacks. If you encounter a barrier in any lesson, report it to your instructor so it can be fixed.
Use these tools to generate instructional assets for course design, teaching materials, faculty development, and training workflows.
📅 Lessons15-Day Course Schedule
Instructor Note: Each lesson follows a Part A / Part B structure. Part A covers lecture, concept exploration, and a structured activity (approx. 2 hours). Part B is a lab, case study, or tabletop exercise with a graded assessment artifact (approx. 2 hours). All 15 lessons are published and available below.
📊 Grading BreakdownAssessment Structure
| Assessment Category | Description | Weight |
|---|---|---|
| Daily Quizzes & Short Assignments | One per lesson — knowledge checks, reflection prompts, short written responses | 25% |
| Labs & In-Class Activity Write-Ups | Submitted write-ups from Part B activities: case analyses, worksheets, architecture diagrams | 20% |
| AI AUP + Vendor Risk Assessment Mini-Project | Draft AI Acceptable Use Policy (Day 13) plus completed vendor risk assessment (Day 12) | 20% |
| Final Capstone Project & Presentation | Team-built AI Security Program Pack — use case register, risk classification, architecture, AUP, red team outline | 25% |
| Participation | Discussions, tabletop exercises, peer review contributions | 10% |