Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Establishing the foundation: threat modeling for agentic AI systems
- Identifying threat categories: misuse, privilege escalation, data leakage, and supply-chain vulnerabilities
- Profiling adversaries and mapping their capabilities specifically to autonomous agents
- Defining assets, trust boundaries, and critical control points for agent operations
Governance, Policy Frameworks, and Risk Management
- Establishing governance structures: roles, responsibilities, and approval mechanisms
- Crafting policies: acceptable use, escalation protocols, data handling standards, and auditability requirements
- Aligning with compliance needs and strategies for evidence collection in audits
Non-Human Identity and Authentication for AI Agents
- Designing agent identities: leveraging service accounts, JWTs, and ephemeral credentials
- Applying least-privilege access models and implementing just-in-time credentialing
- Managing the identity lifecycle, including rotation, delegation, and revocation strategies
Access Control, Secret Management, and Data Protection
- Implementing fine-grained access control and capability-based security patterns for agents
- Managing secrets, ensuring encryption both in transit and at rest, and enforcing data minimization
- Safeguarding sensitive knowledge bases and PII from unauthorized agent interactions
Observability, Audit Trails, and Incident Response
- Building telemetry for agent behavior: tracing intent, logging commands, and establishing provenance
- Integrating with SIEMs, setting alert thresholds, and maintaining forensic readiness
- Developing runbooks and playbooks for responding to and containing agent-related incidents
Red-Teaming Agentic Systems
- Planning red-team engagements: defining scope, establishing rules of engagement, and ensuring safe failover procedures
- Executing adversarial tactics: prompt injection, tool misuse, chain-of-thought manipulation, and API abuse
- Conducting controlled attacks to measure exposure levels and impact
Hardening Measures and Mitigation Strategies
- Applying engineering controls: response throttling, capability gating, and sandboxing
- Enforcing policy and orchestration controls: approval workflows, human-in-the-loop mechanisms, and governance hooks
- Implementing model and prompt-level defenses: input validation, canonicalization, and output filtering
Operationalizing Safe Agent Deployments
- Adopting deployment patterns: staging, canary releases, and progressive rollouts for agents
- Managing change control, testing pipelines, and pre-deployment safety checks
- Coordinating cross-functional governance: aligning security, legal, product, and operations playbooks
Capstone Project: Red-Team vs. Blue-Team Simulation
- Launching a simulated red-team attack against a sandboxed agent environment
- Defending, detecting, and remediating as the blue team using established controls and telemetry
- Presenting findings, remediation plans, and updated policy recommendations
Summary and Recommended Next Steps
Requirements
- A strong foundation in security engineering, system administration, or cloud operations
- Proficiency with AI/ML concepts and an understanding of large language model (LLM) behaviors
- Practical experience with Identity and Access Management (IAM) and secure system architecture
Target Audience
- Security engineers and red-team specialists
- AI operations engineers and platform architects
- Compliance officers and risk management professionals
- Engineering leaders overseeing the deployment of AI agents
21 Hours
Testimonials (1)
inventory and identifying the different risk exposures within AI