AI-103 · 3 Credit Hours · 15-Day Intensive

AI Cybersecurity Foundations

Governance, risk management, threat landscape, and incident response for AI-enabled enterprises — grounded in NIST AI RMF, EU AI Act, ISO/IEC 42001, and OWASP Top 10 for LLMs.

📚 15 Lessons  ⏱ 4 contact hours/day  🎓 Moraine Valley Community College  🔗 Aligned: AAISM · NIST AI RMF · EU AI Act

3
Credit Hours
15
Lessons
20
Learning Objectives
4
Major Frameworks
10
OWASP LLM Items

🧭 Course OverviewWhat Genuinely Changes for AI

AI-103: AI Cybersecurity Foundations bridges traditional information security principles with the demands of AI-enabled enterprise environments. Built on the structure of ISACA's CISM domains — governance, risk management, program development, and incident management — this course adds the AI-specific layer that those frameworks do not yet fully address.

The course is organized around a core question: What genuinely changes when the systems you are securing learn from data, generate probabilistic outputs, and can be manipulated through their inputs in ways that have no parallel in traditional software? Students will work through governance frameworks, risk taxonomies, threat landscapes, architectural controls, and incident response — each adapted for the AI context.

Daily pattern: Each 4-hour class divides into Part A (mini-lecture + structured activity — poll, think-pair-share, or micro case) and Part B (lab, case study, or tabletop aligned to that day's objectives). Assessment artifacts are produced every day.

Prerequisites: Foundational cybersecurity knowledge equivalent to CompTIA Security+ or equivalent coursework. Familiarity with basic risk management concepts is helpful but not required.

📖 Using This CourseHow to Work Through the Material

Structure. The course is 15 lessons (labeled Day 1Day 15), each equivalent to roughly one 4-hour class session. Every lesson follows the same rhythm, so you always know what to expect:

Part A (mini-lecture + a short structured activity — poll, think-pair-share, or micro-case) → Part B (a lab, case study, or tabletop tied to that lesson's objectives) → a daily artifact you produce (memo, worksheet, or builder) → a short, ungraded knowledge check to confirm you're ready to move on.

Pacing (delivered across a term). Although each lesson is written as a "Day," this course is spaced across a full term — plan on one lesson per weekly session, not 15 consecutive days. Budget about 4 hours of guided/contact time per lesson plus independent time to finish the daily artifact. The spacing is a feature: use the gap between sessions to complete the artifact, review the knowledge check, and let concepts consolidate before the next unit. The capstone reuses your Day 1 artifacts, so keep your work organized as you go.

Suggested cadence: Days 1–5 (governance & risk foundations) → Days 6–10 (threat landscape & architecture) → Days 11–15 (policy, incident response, red-teaming & capstone). Knowledge checks are formative and do not affect your grade — use them to self-assess.

🧪 About the Labs & Activities

Every lesson includes hands-on activities — but in this course, "lab" means structured applied analysis, not live coding or attacking real systems. Activities are scenario classifiers, decision labs, matchers, and builders (risk registers, governance charters, threat models, defense matrices), plus think-pair-share and worksheets — all set in realistic scenarios such as an MVCC AI enrollment assistant. You apply the frameworks to a realistic case and produce a written artifact.

Where an activity mentions tools, API keys, or sandboxes, those appear as analysis material (things to reason about), not instructions to run live systems. No programming environment or coding is required. The capstone (Day 15) is a synthesis and presentation of your accumulated artifacts.

♿ Accessibility & Accommodations

Moraine Valley Community College is committed to equal access. If you need academic accommodations (extended time, alternate formats, assistive technology, or other support), please arrange them early through the college's disability-services office. Instructors will work with you to implement approved accommodations.

[Instructor: insert the official MVCC Center for Disability Services statement here — office name, location, phone, email, and the college's standard accommodation language — and link the syllabus accessibility policy.]

Materials accessibility. These web lessons use semantic headings, keyboard-operable interactions, and alt text on informative graphics; interactive cards and sorting activities include text fallbacks. If you encounter a barrier in any lesson, report it to your instructor so it can be fixed.

🗺 Core FrameworksThe Framework Stack

🛡️
NIST AI RMF 1.0
Voluntary risk management framework organized around four functions: Govern, Map, Measure, and Manage. The operating model of this course.
🏛️
ISO/IEC 42001
Certifiable AI Management System standard — the ISO 27001 analogue for AI. Defines auditable controls and processes for an AIMS.
⚖️
EU AI Act
Binding regulation (2024/1689) with extraterritorial reach. Risk-tiered obligations; fines up to €35M or 7% of global turnover.
🔓
OWASP LLM Top 10
Practitioner threat reference for LLM applications (2025 edition). Covers prompt injection, insecure output handling, supply chain, and more.
🤖
AAISM (ISACA)
Advanced in AI Security Management — ISACA's stackable credential for CISM/CISSP holders. Three domains: Governance, Risk, and Technologies & Controls.
🗡️
MITRE ATLAS
Adversarial Threat Landscape for AI Systems — ATT&CK-style knowledge base of real-world ML adversarial tactics and techniques.

🎯 Learning Objectives20 Course-Level Competencies

1Explain why traditional cybersecurity principles alone are insufficient for AI-enabled enterprises and where AAISM extends them.
2Identify the major AI governance frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act) and how they interrelate.
3Apply the four NIST AI RMF functions (Govern, Map, Measure, and Manage) to enterprise AI deployment.
4Classify AI systems under the EU AI Act's four risk tiers and identify required obligations.
5Differentiate AI risk categories: model risk, data risk, operational risk, ethical risk, and third-party risk.
6Recognize shadow AI patterns and apply appropriate governance responses.
7Conduct vendor and supply-chain risk assessments for AI-enabled solutions.
8Distinguish provider, deployer, and importer responsibilities under emerging AI regulation.
9Develop an enterprise AI acceptable use policy that holds up under audit.
10Describe the AI threat landscape and how it differs from traditional cyber threats.
11Identify and explain each of the OWASP Top 10 for LLM Applications (2025 edition).
12Match real-world attack scenarios to OWASP threat categories.
13Design a defense-in-depth architecture for an AI-enabled application.
14Apply controls across the AI data lifecycle — provenance, lineage, AIBOM, and model cards.
15Plan and conduct AI red-team exercises appropriate to system risk.
16Adapt the NIST SP 800-61 incident response lifecycle for AI-specific incidents.
17Execute a tabletop exercise for deepfake-enabled fraud, prompt injection, and model poisoning.
18Document AI incident lessons learned in a way that strengthens the AI governance program.
19Apply the AI shared-responsibility model to allocate security duties between the organization and its AI service providers across IaaS, PaaS, and SaaS deployments.
20Design an AI evaluation plan — selecting robustness, safety, and performance metrics with acceptance thresholds — and interpret benchmark and red-team results to justify a deploy / no-go decision.

📅 Lessons15-Day Course Schedule

Instructor Note: Each lesson follows a Part A / Part B structure. Part A covers lecture, concept exploration, and a structured activity (approx. 2 hours). Part B is a lab, case study, or tabletop exercise with a graded assessment artifact (approx. 2 hours). All 15 lessons are published and available below.

Unit 1 — Foundation: Extending Cybersecurity for AI (Days 1–3)
Day
1
Expanding Cybersecurity Principles for AI
Why traditional infosec is insufficient for AI-enabled enterprises; where AAISM extends it.
CISM Domains AAISM Non-determinism Data as Code Prompts as Attack Surface
Start Here
⏱ 4 hrs · LO #1
Open Lesson →
Day
2
AI Governance Foundations & Framework Landscape
How NIST AI RMF, ISO/IEC 42001, EU AI Act, and OWASP LLM Top 10 fit together — and when to reach for each one.
NIST AI RMF ISO 42001 EU AI Act OWASP LLM Top 10 Framework Stack
Now Available
⏱ 4 hrs · LO #2
Open Lesson →
Day
3
NIST AI RMF in Depth: Govern & Map
All 6 GOVERN categories, all 5 MAP categories, all 37 subcategories — with charter builder and MAP worksheet lab.
GOVERN 1–6 MAP 1–5 Charter Builder MAP Worksheet Sorter Activity
Now Available
⏱ 4 hrs · LO #3
Open Lesson →
Unit 2 — Governance & Regulation: Frameworks in Practice (Days 4–6)
Day
4
NIST AI RMF: Measure & Manage
All 22 MEASURE & 13 MANAGE subcategories — flip cards, expandable deep dives, risk register builder, scenario decision lab.
MEASURE 1–4 MANAGE 1–4 Risk Register Flip Cards Decision Lab
Now Available
⏱ 4 hrs · LO #3
Open Lesson →
Day
5
EU AI Act Risk Tiers & Obligations
All four risk tiers, nine high-risk requirements, four stakeholder roles, GPAI obligations — with flip cards, classification tree, and scenario labs.
Art. 5 Prohibited Annex III High Risk Articles 9–15 Provider vs Deployer GPAI Models
Now Available
⏱ 4 hrs · LO #4, #8
Open Lesson →
Day
6
AI Risk Categories & Shadow AI
Five AI risk categories beyond CIA triad, the three forces, shadow AI statistics and patterns, detection methods, and governance responses.
Five Risk Categories Three Forces Shadow AI Detection Block/Channel/Register Checklist Audit
Now Available
⏱ 4 hrs · LO #5, #6
Open Lesson →
Unit 3 — Threat Landscape: AI as Target (Days 7–9)
Day
7
AI as Target I: Threats, ATT&CK/ATLAS, & OWASP Landscape
MITRE ATLAS v5.1 (16 tactics, 84 techniques), NIST AI 100-2 E2025, OWASP framework stack — with interactive matrix, attack chain builder, and threat model lab.
MITRE ATLAS v5.1 NIST AI 100-2 Attack Chain Builder Threat Model Lab OWASP Mapping
Now Available
⏱ 4 hrs · LO #10, #11
Open Lesson →
Day
8
AI as Target II: OWASP Top 10 for LLMs Deep Dive
All 10 OWASP LLM items — attack paths, real incidents (EchoLeak, Mata v. Avianca), defenses that work vs. don't, attack lab, case matcher, defense builder.
LLM01–LLM10 Attack Lab Case Study Match Defense Builder Flip Cards
Now Available
⏱ 4 hrs · LO #11, #12
Open Lesson →
Day
9
AI as Target III: Attacks on Data & Models
Data poisoning taxonomy (5 types), backdoor/trojan mechanics, four drift types with PSI/ADWIN detection, MLOps pipeline security — flip cards, drift lab, defense matrix builder.
5 Poisoning Types Backdoor Mechanics 4 Drift Types MLOps Security Defense Matrix
Now Available
⏱ 4 hrs · LO #12, #13
Open Lesson →
Unit 4 — AI as Weapon & Secure Architecture (Days 10–12)
Day
10
AI as a Weapon: Deepfakes, Phishing & Influence Operations
Real statistics, documented incidents (Arup $25M, Romania election), economic shift analysis — detection lab, IO classifier, and defense builder for MVCC scenarios.
Deepfakes AI Phishing 82.6% BEC & TOAD Influence Ops Detection Lab
Now Available
⏱ 4 hrs · LO #14, #15
Open Lesson →
Day
11
Architecting Secure AI Systems & Lifecycle Controls
Defense in depth for AI, data lifecycle controls, AIBOM, model cards, and least privilege for agentic systems — interactive architecture lab, flip cards, and scored design exercise.
Defense in Depth AIBOM Model Cards Excessive Agency Data Lifecycle
Now Available
⏱ 4 hrs · LO #13, #14
Open Lesson →
Day
12
Vendor & Supply Chain Risk for AI
AI value chain, provider/deployer/importer roles, embedded AI risk, vendor tiering, structured assessment questionnaire, and contract clause governance lab.
AI Value Chain Vendor Assessment EU AI Act Roles Embedded AI Risk Contract Clauses
Now Available
⏱ 4 hrs · LO #7, #8
Open Lesson →
Unit 5 — Policies, Incident Response & Synthesis (Days 13–15)
Day
13
AI Policies, AUPs & Governance Documents
Build an AI AUP (8 components), Use Case Register, ISO 42001 document hierarchy, and AI IR Annex — with interactive AUP builder, policy gap analysis, and live register. Mini-Project Part 2 of 2.
AI AUP Builder Use Case Register ISO 42001 Docs IR Annex Policy Gap Analysis
Now Available
⏱ 4 hrs · LO #9
Open Lesson →
Day
14
AI Incident Response, Red Teaming & Tabletops
Six AI IR gaps, adapted NIST SP 800-61r3 lifecycle, 8-category red team framework, and three live tabletop exercises — deepfake fraud, prompt injection exfiltration, and model poisoning discovery.
NIST SP 800-61r3 AI Red Teaming Tabletop Exercise Deepfake TTX Lessons Learned
Now Available
⏱ 4 hrs · LO #15, #16, #17
Open Lesson →
Day
15
Synthesis & Final Capstone Presentations
15-day course map with day-by-day synthesis, 7 NIST trustworthiness characteristics mapped to all lessons, 8-component AI Security Program Pack, 12-minute presentation format with Q&A bank, structured peer review form, 18-objective self-assessment, career pathways, and an 8-question synthesis final quiz.
All 18 Objectives Trustworthiness Capstone Pack Peer Review Final Quiz
Now Available
⏱ 4 hrs · All LOs
Open Lesson →

📊 Grading BreakdownAssessment Structure

Assessment Category Description Weight
Daily Quizzes & Short Assignments One per lesson — knowledge checks, reflection prompts, short written responses 25%
Labs & In-Class Activity Write-Ups Submitted write-ups from Part B activities: case analyses, worksheets, architecture diagrams 20%
AI AUP + Vendor Risk Assessment Mini-Project Draft AI Acceptable Use Policy (Day 13) plus completed vendor risk assessment (Day 12) 20%
Final Capstone Project & Presentation Team-built AI Security Program Pack — use case register, risk classification, architecture, AUP, red team outline 25%
Participation Discussions, tabletop exercises, peer review contributions 10%