🧭 Course OverviewWhat Genuinely Changes for AI
AI-103: AI Cybersecurity Foundations bridges traditional information security principles with the demands of AI-enabled enterprise environments. Built on the structure of ISACA's CISM domains — governance, risk management, program development, and incident management — this course adds the AI-specific layer that those frameworks do not yet fully address.
The course is organized around a core question: What genuinely changes when the systems you are securing learn from data, generate probabilistic outputs, and can be manipulated through their inputs in ways that have no parallel in traditional software? Students will work through governance frameworks, risk taxonomies, threat landscapes, architectural controls, and incident response — each adapted for the AI context.
Daily pattern: Each 4-hour class divides into Part A (mini-lecture + structured activity — poll, think-pair-share, or micro case) and Part B (lab, case study, or tabletop aligned to that day's objectives). Assessment artifacts are produced every day.
Prerequisites: Foundational cybersecurity knowledge equivalent to CompTIA Security+ or equivalent coursework. Familiarity with basic risk management concepts is helpful but not required.
📖 Using This CourseHow to Work Through the Material
Structure. The course is 15 lessons (labeled Day 1–Day 15), each equivalent to roughly one 4-hour class session. Every lesson follows the same rhythm, so you always know what to expect:
Part A (mini-lecture + a short structured activity — poll, think-pair-share, or micro-case) → Part B (a lab, case study, or tabletop tied to that lesson's objectives) → a daily artifact you produce (memo, worksheet, or builder) → a short, ungraded knowledge check to confirm you're ready to move on.
Pacing (delivered across a term). Although each lesson is written as a "Day," this course is spaced across a full term — plan on one lesson per weekly session, not 15 consecutive days. Budget about 4 hours of guided/contact time per lesson plus independent time to finish the daily artifact. The spacing is a feature: use the gap between sessions to complete the artifact, review the knowledge check, and let concepts consolidate before the next unit. The capstone reuses your Day 1 artifacts, so keep your work organized as you go.
Suggested cadence: Days 1–5 (governance & risk foundations) → Days 6–10 (threat landscape & architecture) → Days 11–15 (policy, incident response, red-teaming & capstone). Knowledge checks are formative and do not affect your grade — use them to self-assess.
🧪 About the Labs & Activities
Every lesson includes hands-on activities — but in this course, "lab" means structured applied analysis, not live coding or attacking real systems. Activities are scenario classifiers, decision labs, matchers, and builders (risk registers, governance charters, threat models, defense matrices), plus think-pair-share and worksheets — all set in realistic scenarios such as an MVCC AI enrollment assistant. You apply the frameworks to a realistic case and produce a written artifact.
Where an activity mentions tools, API keys, or sandboxes, those appear as analysis material (things to reason about), not instructions to run live systems. No programming environment or coding is required. The capstone (Day 15) is a synthesis and presentation of your accumulated artifacts.
♿ Accessibility & Accommodations
Moraine Valley Community College is committed to equal access. If you need academic accommodations (extended time, alternate formats, assistive technology, or other support), please arrange them early through the college's disability-services office. Instructors will work with you to implement approved accommodations.
[Instructor: insert the official MVCC Center for Disability Services statement here — office name, location, phone, email, and the college's standard accommodation language — and link the syllabus accessibility policy.]
Materials accessibility. These web lessons use semantic headings, keyboard-operable interactions, and alt text on informative graphics; interactive cards and sorting activities include text fallbacks. If you encounter a barrier in any lesson, report it to your instructor so it can be fixed.
🗺 Core FrameworksThe Framework Stack
🛡️
NIST AI RMF 1.0
Voluntary risk management framework organized around four functions: Govern, Map, Measure, and Manage. The operating model of this course.
🏛️
ISO/IEC 42001
Certifiable AI Management System standard — the ISO 27001 analogue for AI. Defines auditable controls and processes for an AIMS.
⚖️
EU AI Act
Binding regulation (2024/1689) with extraterritorial reach. Risk-tiered obligations; fines up to €35M or 7% of global turnover.
🔓
OWASP LLM Top 10
Practitioner threat reference for LLM applications (2025 edition). Covers prompt injection, insecure output handling, supply chain, and more.
🤖
AAISM (ISACA)
Advanced in AI Security Management — ISACA's stackable credential for CISM/CISSP holders. Three domains: Governance, Risk, and Technologies & Controls.
🗡️
MITRE ATLAS
Adversarial Threat Landscape for AI Systems — ATT&CK-style knowledge base of real-world ML adversarial tactics and techniques.
🎯 Learning Objectives20 Course-Level Competencies
1Explain why traditional cybersecurity principles alone are insufficient for AI-enabled enterprises and where AAISM extends them.
2Identify the major AI governance frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act) and how they interrelate.
3Apply the four NIST AI RMF functions (Govern, Map, Measure, and Manage) to enterprise AI deployment.
4Classify AI systems under the EU AI Act's four risk tiers and identify required obligations.
5Differentiate AI risk categories: model risk, data risk, operational risk, ethical risk, and third-party risk.
6Recognize shadow AI patterns and apply appropriate governance responses.
7Conduct vendor and supply-chain risk assessments for AI-enabled solutions.
8Distinguish provider, deployer, and importer responsibilities under emerging AI regulation.
9Develop an enterprise AI acceptable use policy that holds up under audit.
10Describe the AI threat landscape and how it differs from traditional cyber threats.
11Identify and explain each of the OWASP Top 10 for LLM Applications (2025 edition).
12Match real-world attack scenarios to OWASP threat categories.
13Design a defense-in-depth architecture for an AI-enabled application.
14Apply controls across the AI data lifecycle — provenance, lineage, AIBOM, and model cards.
15Plan and conduct AI red-team exercises appropriate to system risk.
16Adapt the NIST SP 800-61 incident response lifecycle for AI-specific incidents.
17Execute a tabletop exercise for deepfake-enabled fraud, prompt injection, and model poisoning.
18Document AI incident lessons learned in a way that strengthens the AI governance program.
19Apply the AI shared-responsibility model to allocate security duties between the organization and its AI service providers across IaaS, PaaS, and SaaS deployments.
20Design an AI evaluation plan — selecting robustness, safety, and performance metrics with acceptance thresholds — and interpret benchmark and red-team results to justify a deploy / no-go decision.
📅 Lessons15-Day Course Schedule
Instructor Note: Each lesson follows a Part A / Part B structure. Part A covers lecture, concept exploration, and a structured activity (approx. 2 hours). Part B is a lab, case study, or tabletop exercise with a graded assessment artifact (approx. 2 hours). All 15 lessons are published and available below.
Expanding Cybersecurity Principles for AI
Why traditional infosec is insufficient for AI-enabled enterprises; where AAISM extends it.
CISM Domains
AAISM
Non-determinism
Data as Code
Prompts as Attack Surface
AI Governance Foundations & Framework Landscape
How NIST AI RMF, ISO/IEC 42001, EU AI Act, and OWASP LLM Top 10 fit together — and when to reach for each one.
NIST AI RMF
ISO 42001
EU AI Act
OWASP LLM Top 10
Framework Stack
NIST AI RMF in Depth: Govern & Map
All 6 GOVERN categories, all 5 MAP categories, all 37 subcategories — with charter builder and MAP worksheet lab.
GOVERN 1–6
MAP 1–5
Charter Builder
MAP Worksheet Sorter Activity
NIST AI RMF: Measure & Manage
All 22 MEASURE & 13 MANAGE subcategories — flip cards, expandable deep dives, risk register builder, scenario decision lab.
MEASURE 1–4
MANAGE 1–4
Risk Register
Flip Cards
Decision Lab
EU AI Act Risk Tiers & Obligations
All four risk tiers, nine high-risk requirements, four stakeholder roles, GPAI obligations — with flip cards, classification tree, and scenario labs.
Art. 5 Prohibited
Annex III High Risk
Articles 9–15
Provider vs Deployer
GPAI Models
AI Risk Categories & Shadow AI
Five AI risk categories beyond CIA triad, the three forces, shadow AI statistics and patterns, detection methods, and governance responses.
Five Risk Categories
Three Forces
Shadow AI Detection
Block/Channel/Register
Checklist Audit
AI as Target I: Threats, ATT&CK/ATLAS, & OWASP Landscape
MITRE ATLAS v5.1 (16 tactics, 84 techniques), NIST AI 100-2 E2025, OWASP framework stack — with interactive matrix, attack chain builder, and threat model lab.
MITRE ATLAS v5.1
NIST AI 100-2
Attack Chain Builder
Threat Model Lab
OWASP Mapping
AI as Target II: OWASP Top 10 for LLMs Deep Dive
All 10 OWASP LLM items — attack paths, real incidents (EchoLeak, Mata v. Avianca), defenses that work vs. don't, attack lab, case matcher, defense builder.
LLM01–LLM10
Attack Lab
Case Study Match
Defense Builder
Flip Cards
AI as Target III: Attacks on Data & Models
Data poisoning taxonomy (5 types), backdoor/trojan mechanics, four drift types with PSI/ADWIN detection, MLOps pipeline security — flip cards, drift lab, defense matrix builder.
5 Poisoning Types
Backdoor Mechanics
4 Drift Types
MLOps Security
Defense Matrix
AI as a Weapon: Deepfakes, Phishing & Influence Operations
Real statistics, documented incidents (Arup $25M, Romania election), economic shift analysis — detection lab, IO classifier, and defense builder for MVCC scenarios.
Deepfakes
AI Phishing
82.6% BEC & TOAD
Influence Ops
Detection Lab
Architecting Secure AI Systems & Lifecycle Controls
Defense in depth for AI, data lifecycle controls, AIBOM, model cards, and least privilege for agentic systems — interactive architecture lab, flip cards, and scored design exercise.
Defense in Depth
AIBOM
Model Cards
Excessive Agency
Data Lifecycle
Vendor & Supply Chain Risk for AI
AI value chain, provider/deployer/importer roles, embedded AI risk, vendor tiering, structured assessment questionnaire, and contract clause governance lab.
AI Value Chain
Vendor Assessment
EU AI Act Roles
Embedded AI Risk
Contract Clauses
AI Policies, AUPs & Governance Documents
Build an AI AUP (8 components), Use Case Register, ISO 42001 document hierarchy, and AI IR Annex — with interactive AUP builder, policy gap analysis, and live register. Mini-Project Part 2 of 2.
AI AUP Builder
Use Case Register
ISO 42001 Docs
IR Annex
Policy Gap Analysis
AI Incident Response, Red Teaming & Tabletops
Six AI IR gaps, adapted NIST SP 800-61r3 lifecycle, 8-category red team framework, and three live tabletop exercises — deepfake fraud, prompt injection exfiltration, and model poisoning discovery.
NIST SP 800-61r3
AI Red Teaming
Tabletop Exercise
Deepfake TTX
Lessons Learned
Synthesis & Final Capstone Presentations
15-day course map with day-by-day synthesis, 7 NIST trustworthiness characteristics mapped to all lessons, 8-component AI Security Program Pack, 12-minute presentation format with Q&A bank, structured peer review form, 18-objective self-assessment, career pathways, and an 8-question synthesis final quiz.
All 18 Objectives
Trustworthiness
Capstone Pack
Peer Review
Final Quiz
📊 Grading BreakdownAssessment Structure
| Assessment Category |
Description |
Weight |
| Daily Quizzes & Short Assignments |
One per lesson — knowledge checks, reflection prompts, short written responses |
25% |
| Labs & In-Class Activity Write-Ups |
Submitted write-ups from Part B activities: case analyses, worksheets, architecture diagrams |
20% |
| AI AUP + Vendor Risk Assessment Mini-Project |
Draft AI Acceptable Use Policy (Day 13) plus completed vendor risk assessment (Day 12) |
20% |
| Final Capstone Project & Presentation |
Team-built AI Security Program Pack — use case register, risk classification, architecture, AUP, red team outline |
25% |
| Participation |
Discussions, tabletop exercises, peer review contributions |
10% |