- Maps to ISACA Domain 1, AI Governance and Program Management (31%).
- Build governance structures that keep AI systems in line with organizational security policies and ethical standards.
- Create and enforce AI-specific security policies and procedures that inform AI standards and guidelines.
- Engage business and technical stakeholders so security is part of AI initiatives from the start.
- Define key performance indicators to monitor and report on AI security governance.
Advanced in AI Security Management™ (AAISM™) Certification Training Course
Build the governance, risk, and control skills security managers need to protect enterprise AI. Accumentum prepares active CISM and CISSP holders for ISACA’s Advanced in AI Security Management (AAISM) exam.
Govern AI, manage AI risk, and apply AI security controls at the management level.
The Advanced in AI Security Management™ (AAISM™) Certification Training Course with Accumentum prepares experienced security managers to govern AI, manage AI risk, and apply controls to AI systems. ISACA launched AAISM on August 19, 2025, and describes it as the first and only AI-centric security management certification.
AAISM is not an entry-level credential. ISACA requires AAISM candidates to hold an active CISM or CISSP, and says the credential fits people with proven experience in security or advisory roles and some expertise assessing, implementing, and maintaining AI systems. This course is written for that audience.
The ten modules follow ISACA’s three AAISM exam domains: AI Governance and Program Management (31%), AI Risk Management (31%), and AI Technologies and Controls (38%). Topics include AI policy and program structure, AI threat and vulnerability management, vendor and supply chain risk, AI security architecture, the AI life cycle, data management controls, privacy and ethics controls, and AI incident response.
Sessions stay at the management level: who owns an AI risk, what control treats it to an acceptable level, how you would report it, and how you would explain the decision to leadership. Scenarios and case discussions support that focus.
Build AAISM exam readiness and practical AI security management skills.
Govern AI security
Set charter, roles, policies, and program structure for AI so security requirements line up with business objectives, regulation, and ethical principles.
Manage AI risk
Assess and treat AI risk, identify the AI threat landscape, manage AI vulnerabilities, and set security expectations for AI vendors and the supply chain.
Apply AI technologies and controls
Advise on AI security architecture, secure the AI life cycle from model selection through validation, and apply data, privacy, trust and safety, and monitoring controls.
Lead AI incident response
Build AI-specific processes to investigate, contain, report, and recover from AI security incidents, and include AI in business continuity planning.
Who Should Attend
- Information security managers who hold an active CISM or CISSP and are responsible for AI systems in their organization.
- Security architects and advisors who are asked to review, approve, or secure AI projects.
- Governance, risk, and compliance leaders with a security background who need to manage AI risk across the enterprise.
- Security leaders moving into roles such as AI security manager or AI risk lead.
Prerequisites
- ISACA requires AAISM exam candidates to hold an active CISM or CISSP certification. Confirm your eligibility with ISACA before you register for the exam.
- ISACA says AAISM candidates should have some experience assessing, implementing, and maintaining AI systems.
- The course assumes working knowledge of security management, risk, and governance at the CISM or CISSP level, plus basic AI concepts such as machine learning models and training data.
- Training does not replace ISACA’s certification requirements. After passing the exam you must still apply to ISACA and meet its ethics and CPE rules.
The AAISM training course covers all three ISACA domains across ten modules.
Every module opens with the ISACA domain it maps to, so you can see how governance, risk, and controls fit together across the course.
- Maps to ISACA Domain 2, AI Risk Management (31%).
- Identify AI threats such as adversarial attacks, model poisoning, and data manipulation.
- Design and implement controls that counter AI-specific vulnerabilities and protect system integrity.
- Use threat intelligence to address emerging AI security risks early.
- Plan testing and vulnerability management for AI solutions.
- Maps to ISACA Domain 3, AI Technologies and Controls (38%).
- Protect AI algorithms against tampering so outputs stay reliable.
- Safeguard AI models from unauthorized access and adversarial manipulation.
- Apply security measures that support model transparency and accountability.
- Apply security practices across the AI model life cycle, from selection and training through validation, deployment, and retirement.
- Maps to ISACA Domain 3, AI Technologies and Controls (38%).
- Apply principles such as fairness and accountability to the way AI systems are secured and managed.
- Implement controls that address bias and support equitable AI outcomes.
- Use risk-based human oversight of AI inputs and outputs, including trust and safety, quality, explainability, and robustness of results.
- Manage and report ethical breaches in AI systems responsibly.
- Maps to ISACA Domain 1, AI Governance and Program Management (31%).
- Understand how AI regulations, for example the EU AI Act, affect security management.
- Build security programs that meet data privacy and AI-specific requirements such as GDPR.
- Conduct AI impact assessments and confirm conformity with regulatory requirements.
- Prepare compliance reports that show how AI security requirements are met.
- Maps to ISACA Domain 3, AI Technologies and Controls (38%).
- Establish processes to identify, inventory, and classify data and assets related to AI.
- Implement and manage privacy controls such as anonymization in AI data pipelines.
- Identify and treat security risk in data used for AI training and inference.
- Audit data security practices against privacy requirements.
- Maps to ISACA Domain 1, AI Governance and Program Management (31%).
- Develop incident response plans for AI-specific security breaches and failures.
- Establish AI incident handling processes, including containment, notification, escalation, eradication, and recovery.
- Investigate, document, and report AI security incidents in line with regulatory and contractual requirements.
- Address AI security risk in business continuity and disaster recovery planning.
- Maps to ISACA Domain 2, AI Risk Management (31%).
- Secure AI systems delivered as SaaS, PaaS, and IaaS.
- Apply shared responsibility models to cloud-based AI deployments.
- Plan security for AI systems that run across on-premises and cloud infrastructure.
- Embed, monitor, and verify AI security requirements when using vendor AI-enabled solutions.
- Maps to ISACA Domain 1, AI Governance and Program Management (31%).
- Create an AI security program that brings together people, processes, and technology.
- Allocate budget, tools, and staff to AI security objectives.
- Build security into the AI solution development life cycle.
- Define and monitor security metrics for AI solutions and develop AI-specific security awareness training and acceptable use guidelines.
- Maps to ISACA Domain 2, AI Risk Management (31%).
- Address security risks in generative AI systems, such as deepfakes and content manipulation.
- Secure AI applications in Internet of Things (IoT) and edge computing environments.
- Review security considerations for AI-driven automation tools and AI security tools used by the security program.
- Monitor internal and external AI-related factors that signal when risk needs to be reassessed.
Designed for security managers preparing for the ISACA AAISM exam.
Instructor-Led Sessions
Live virtual sessions with instructors focused on AI security governance, risk, and control decisions.
Management Scenarios
Case studies that ask what a security manager should decide, report, or change when AI enters the business.
Domain-Mapped Materials
Study materials organized by ISACA’s three AAISM domains and their published weights.
Exam Readiness Review
Review of the exam structure, domain coverage, and ISACA-style question stems before you schedule.
Prepare for the ISACA Advanced in AI Security Management exam.
AAISM Exam Readiness
Accumentum’s AAISM course prepares active CISM and CISSP holders to govern AI, manage AI risk, and apply AI controls across all three ISACA domains.

ISACA launched the Advanced in AI Security Management (AAISM) certification on August 19, 2025. ISACA describes it as the first and only AI-centric security management certification.
The AAISM exam has 90 questions across three domains: AI Governance and Program Management (31%), AI Risk Management (31%), and AI Technologies and Controls (38%).
AAISM candidates must hold an active CISM or CISSP. Exams are computer-based and taken at PSI testing centers or through remote proctoring. Remote proctoring is not available to residents of India, Mainland China, and Hong Kong. After you register, you have six months to take the exam.
To become certified you must hold an active CISM or CISSP, pass the exam, apply within five years of passing, pay ISACA’s application processing fee, and follow ISACA’s Code of Professional Ethics and CPE policy. Certified holders earn 10 hours of AI CPE each year.
Accumentum is an independent training provider. ISACA sets and changes exam rules, fees, and policies, so confirm current details on isaca.org before you register.
How Accumentum’s AAISM course lines up with ISACA’s exam, who is eligible, how the exam is delivered, and what ISACA requires after you pass.
Enroll in the ISACA AAISM Certification Training Course with Accumentum.
Enroll in the Advanced in AI Security Management™ (AAISM™) Certification Training Course with Accumentum to prepare for ISACA’s AI security management exam.
You will work through all three AAISM domains with an instructor and practice the governance, risk, and control decisions that security managers make when AI enters the business.
Before you enroll, confirm that you hold an active CISM or CISSP, since ISACA requires one to sit the exam. For course dates and enrollment help, visit Accumentum’s registration page.
Lead AI security decisions with AAISM training.
Prepare for the ISACA AAISM exam while you build the governance, risk, and control skills security managers need when AI enters the business.