ALREADY HAVE AN AAISM CERTIFICATION? LOG IN TO MYISACA

What is covered on the AAISM exam?

The ISACA Advanced in AI Security Management™ (AAISM™) exam consists of 90 questions covering three job practice domains, all testing your knowledge and ability on real-life job practices leveraged by AI security management professionals.

Job practice areas tested for and validated by an AAISM certification

31% DOMAIN 1 – AI GOVERNANCE AND PROGRAM MANAGEMENT

This Domain demonstrates your ability to advise stakeholders on implementing AI security solutions through appropriate and effective policy, data governance, program management and incident response.

A–STAKEHOLDER CONSIDERATIONS, INDUSTRY FRAMEWORKS, AND REGULATORY REQUIREMENTS
B–AI-RELATED STRATEGIES, POLICIES, AND PROCEDURES
C–AI ASSET AND DATA LIFE CYCLE MANAGEMENT
D–AI SECURITY PROGRAM DEVELOPMENT AND MANAGEMENT
E–BUSINESS CONTINUITY AND INCIDENT RESPONSE

31% DOMAIN 2 – AI RISK MANAGEMENT

This Domain confirms your skill at assessing and managing risks, threats, vulnerabilities and supply chain issues related to the enterprise-wide adoption of AI.

A–AI RISK ASSESSMENT, THRESHOLDS, AND TREATMENT
B–AI THREAT AND VULNERABILITY MANAGEMENT
C–AI VENDOR AND SUPPLY CHAIN MANAGEMENT

38% DOMAIN 3 – AI TECHNOLOGIES AND CONTROLS

This Domain focuses on optimizing AI security and highlights your knowledge of security technologies, techniques and controls tailored to AI systems.

A–AI SECURITY ARCHITECTURE AND DESIGN
B–AI-RELATED STRATEGIES, POLICIES, AND PROCEDURES
C–DATA MANAGEMENT CONTROLS
D–PRIVACY, ETHICAL, TRUST AND SAFETY CONTROLS
E–SECURITY CONTROLS AND MONITORING

Supporting Tasks

  1. Collaborate on charter, roles, and responsibilities for governance and management of AI to align with business objectives.
  2. Establish and maintain AI-specific security policies and procedures to inform the development and implementation of AI standards and guidelines.
  3. Ensure the responsible use of AI by utilizing leading practices, ethical principles, regulatory requirements, and industry frameworks.
  4. Participate in or oversee the AI risk management life cycle, including impacts on enterprise risk.
  5. Identify and assess the AI threat landscape.
  6. Monitor for internal and external AI-related factors to identify the need for reassessment of risk.
  7. Design and implement testing and vulnerability management of AI solutions.
  8. Conduct AI impact assessments and ensure conformity with regulatory requirements.
  9. Embed, monitor, and verify AI security requirements when utilizing vendor AI-enabled solutions.
  10. Design and implement security architecture specifically for AI.
  11. Advise on the integration of AI architecture as part of enterprise architecture.
  12. Design, implement, and regularly review AI security controls to treat risk to an acceptable level.
  13. Establish and maintain processes to identify, inventory, and classify data and assets related to AI.
  14. Identify and treat security risk associated with data used in the AI life cycle.
  15. Establish and maintain AI-specific processes to investigate, document, and report on AI security incidents in accordance with regulatory and contractual requirements.
  16. Establish and maintain AI incident handling processes, including containment, notification, escalation, eradication, and recovery.
  17. Address AI security risk as part of business continuity and disaster recovery planning.
  18. Define and monitor security metrics for AI solutions used throughout the organization.
  19. Review and implement AI security tools as part of the information security program.
  20. Conduct risk-based human oversight of AI inputs/outputs including trust and safety, quality, explainability, and robustness.
  21. Develop and maintain AI-specific security awareness training and acceptable use guidelines.
  22. Advise on security risk and controls related to the AI solution development life cycle within an organization.

Getting ready for the current exam

ISACA offers a variety of exam preparation resources including group training, self-paced training and study resources in various languages to help you prepare for the current certification exam. Choose what works for your schedule and your studying needs.