A professional credential for the person who has to actually run AI security, mapped for the classroom.
Where NIST AI RMF, ISO/IEC 42001, and the EU AI Act tell an organization what to do, AAISM is ISACA's attempt to certify that a specific professional knows how to do it โ govern, assess risk on, and technically secure AI systems inside a real enterprise.
Three domains, one credential โ a professional's competence, not a system's control set.
Purpose & Origin
What AAISM is, why ISACA built it, and who it's actually for.
What it is
AAISM โ Advanced in AI Security Management โ is a professional certification from ISACA, the organization behind long-established credentials like CISM (security management), CRISC (risk management), and CGEIT (governance). AAISM applies that same credentialing model specifically to AI security management.
Why it was created
Frameworks like NIST AI RMF and ISO/IEC 42001 describe what an organization's AI risk program should look like โ but none of them certify that an individual professional actually has the judgment to run one. AAISM fills that gap: a way for security and risk professionals to demonstrate AI-specific competence the way CISM already demonstrates general security-management competence.
Who it's for
Practitioners already working in security, risk, audit, or governance roles โ often already CISM, CISSP, CRISC, or CGEIT holders โ who are being asked to extend their existing expertise to cover AI-enabled systems, and want a credential that documents that extension.
How it's positioned
ISACA describes it as a stackable, advanced-level credential rather than an entry-level certificate โ built for someone who already manages security or risk programs and needs the AI-specific layer, not someone starting a security career from zero.
How to Use This Guide
Built for a course session introducing a credential-based career pathway, not a substitute for ISACA's own study materials.
- Treat this as a competency map, not a syllabus. AAISM's three domains describe what a professional should be able to do โ govern, assess risk, and secure AI systems โ mirroring the same three moves you've already studied through NIST AI RMF, ISO/IEC 42001, and the OWASP/ATLAS threat catalogs.
- Notice the direction of fit. The other frameworks in this course describe an AI system or organization's obligations. AAISM describes a person's competence to carry those obligations out โ it's the credential that says "this professional can actually run the program those frameworks call for."
- Map each domain back to what you already know. Domain 1 (Governance) draws on NIST's GOVERN function and ISO 42001's Clauses 4โ5. Domain 2 (Risk Management) draws on NIST's MAP/MEASURE/MANAGE and ISO 42001 Clause 6/8. Domain 3 (Technologies & Controls) draws on OWASP's LLM Top 10 and MITRE ATLAS.
- Use the "Credential at a Glance" section for orientation, not for exam prep. If you or a student is actually pursuing AAISM, go to ISACA directly for eligibility, exam format, and study materials โ this guide exists to place the credential in context, not to prepare someone to sit the exam.
Credential at a Glance
High-level orientation only โ confirm every detail here against ISACA's current program page before relying on it.
ISACA โ the same organization behind CISM, CRISC, CGEIT, and CISA.
Advanced-level professional certification, not an entry-level certificate.
Security, risk, audit, and governance professionals extending into AI-specific responsibilities.
Three domains: Governance, Risk Management, and Technologies & Controls.
Positioned as stackable โ intended to complement, not replace, credentials like CISM or CISSP.
isaca.org โ for prerequisites, exam format, domain weightings, and renewal/CPE requirements.
AAISM vs. the Frameworks You've Already Studied
The other tools in this course describe systems and organizations. This one describes a person.
| NIST AI RMF / ISO 42001 / EU AI Act | OWASP LLM Top 10 / MITRE ATLAS | AAISM | |
|---|---|---|---|
| What it certifies | An organization's process or product | Nothing โ a threat reference, not a certification | An individual professional's competence |
| Unit of analysis | The AI management system or AI system | The attack surface or attacker technique | The practitioner running the program |
| Typical holder | N/A โ organizations comply or certify | N/A โ practitioners reference it | A security/risk/governance professional |
| How they connect | A credentialed AAISM professional is the person expected to actually implement NIST/ISO/EU AI Act obligations and defend against OWASP/ATLAS-cataloged threats. | ||
Governance โ establishing accountability for AI
The competencies for building and running the oversight structure an organization's AI use actually needs โ policy, roles, reporting, and alignment with strategy and risk appetite.
Ensuring AI initiatives are pursued in service of actual business objectives and risk appetite, not adopted for its own sake โ and that leadership understands the trade-offs it's approving.
Establishing AI use policies, an AI governance committee or equivalent body, and clear escalation paths โ the practical machinery behind a policy document.
Defining who owns a given model or AI system, who signs off on deployment, and who is accountable when something goes wrong โ accountability that has to survive contact with an actual incident.
Translating external obligations โ the EU AI Act, ISO/IEC 42001, sector-specific regulation โ into internal policy a practitioner can actually operationalize.
Reporting AI risk posture and program maturity to leadership in terms they can act on โ a skill CISM already emphasizes for security generally, extended here to AI specifics.
Risk Management โ identifying and treating AI-specific risk
The competencies for finding, sizing, and deciding what to do about the risks AI systems specifically introduce โ and folding that work into the organization's existing enterprise risk management, rather than running it as a separate silo.
Recognizing risk categories that don't map cleanly onto traditional IT risk โ model risk, data risk, algorithmic bias, third-party/vendor AI risk, and adversarial risk.
Running structured assessments of a given AI system's potential impact on individuals, the organization, and third parties โ the practitioner-level skill behind what NIST AI RMF's Map function and ISO 42001's impact-assessment clauses call for.
Maintaining a live AI risk register and integrating it into the organization's broader enterprise risk management process, rather than tracking AI risk in a parallel, disconnected system.
Applying the organization's stated risk appetite to real AI deployment decisions โ mitigate, transfer, avoid, or accept โ and documenting the reasoning well enough to survive an audit.
Tracking AI risk over time as models drift, usage expands, and new threats emerge โ risk management as a continuous practice, not a one-time assessment before launch.
Technologies & Controls โ securing AI systems technically
The competencies for actually implementing and validating technical controls across an AI system's lifecycle โ the domain that draws most directly on threat catalogs like OWASP's LLM Top 10 and MITRE ATLAS.
Understanding enough of how a given AI system is built โ training pipeline, model, inference layer, retrieval/tooling โ to assess whether its controls are actually appropriate.
Applying access control, data governance, and model-protection practices across the AI lifecycle โ securing training data, model artifacts, and inference endpoints as distinct assets with distinct risks.
Securing the pipeline that builds and deploys models โ versioning, CI/CD for ML, dependency and supply-chain checks โ not just the deployed model itself.
Evaluating a system against known attack patterns โ the technical link back to OWASP's LLM Top 10 and MITRE ATLAS's tactic/technique matrix โ before and after deployment.
Adapting traditional incident-response processes for AI-specific events โ prompt injection, model poisoning, deepfake-enabled fraud โ where the failure mode doesn't look like a conventional breach.
Classroom Uses
Ways instructors have used this structure with students.
Career pathway discussion
Use AAISM's three domains as a jumping-off point to discuss how a security-management career (CISM, CRISC, CISSP) extends into AI-specific roles โ useful for students already holding or pursuing those credentials.
Framework-to-domain mapping
Have students map specific NIST AI RMF categories, ISO 42001 clauses, or OWASP/ATLAS entries onto the AAISM domain each would fall under โ reinforcing that these tools all describe pieces of the same job.
Role-play: the AAISM-credentialed hire
Have students write a one-page justification for why an organization should hire or promote someone with this credential, using specific competencies from all three domains.
Currency-check exercise
Assign students to look up the current AAISM domain weightings, prerequisites, and exam format on isaca.org and report what, if anything, has changed since this guide was written โ a live lesson in how quickly a new credential evolves.
Sources & Further Reading
This guide is a teaching summary of a newer, evolving credential โ verify everything here before treating it as authoritative.
ISACA โ AAISM program page
The authoritative source for eligibility, exam blueprint, domain weightings, and renewal requirements.isaca.org โ search "AAISM"
ISACA โ related credentials
CISM, CRISC, and CGEIT program pages, useful for understanding the credentialing model AAISM extends.isaca.org/credentialing