Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations: Threat Models for Agentic AI
- Categories of agentic threats: misuse, privilege escalation, data leakage, and supply-chain vulnerabilities.
- Adversary profiles and attacker capabilities unique to autonomous agents.
- Mapping assets, trust boundaries, and critical control points relevant to agent operations.
Governance, Policy, and Risk Management
- Governance frameworks for agentic systems, including roles, responsibilities, and approval gates.
- Policy design covering acceptable use, escalation protocols, data handling standards, and auditability.
- Compliance considerations and strategies for collecting audit evidence.
Non-Human Identity and Authentication for Agents
- Designing agent identities using service accounts, JWTs, and short-lived credentials.
- Applying least-privilege access patterns and just-in-time credentialing mechanisms.
- Strategies for identity lifecycle management, rotation, delegation, and revocation.
Access Controls, Secrets, and Data Protection
- Fine-grained access control models and capability-based patterns for agent environments.
- Secrets management, encryption in transit and at rest, and data minimization practices.
- Protecting sensitive knowledge sources and PII from unauthorized agent access.
Observability, Auditing, and Incident Response
- Designing telemetry for agent behavior, including intent tracing, command logging, and provenance tracking.
- SIEM integration, alerting thresholds, and ensuring forensic readiness.
- Developing runbooks and playbooks for agent-related incident containment and response.
Red-Teaming Agentic Systems
- Planning red-team exercises, defining scope, rules of engagement, and safe failover procedures.
- Adversarial techniques such as prompt injection, tool misuse, chain-of-thought manipulation, and API abuse.
- Conducting controlled attacks to measure exposure and assess impact.
Hardening and Mitigations
- Engineering controls including response throttles, capability gating, and sandboxing.
- Policy and orchestration controls involving approval flows, human-in-the-loop mechanisms, and governance hooks.
- Model and prompt-level defenses such as input validation, canonicalization, and output filtering.
Operationalizing Safe Agent Deployments
- Deployment patterns for agents, including staging, canary releases, and progressive rollouts.
- Change control, testing pipelines, and pre-deployment safety checks.
- Cross-functional governance playbooks integrating security, legal, product, and operations teams.
Capstone: Red-Team / Blue-Team Exercise
- Executing a simulated red-team attack against a sandboxed agent environment.
- Defending, detecting, and remediating as the blue team using established controls and telemetry.
- Presenting findings, remediation plans, and necessary policy updates.
Summary and Next Steps
Requirements
- A strong foundation in security engineering, system administration, or cloud operations.
- Proficiency in AI/ML concepts and an understanding of large language model (LLM) behaviors.
- Experience with Identity and Access Management (IAM) and secure system design principles.
Target Audience
- Security engineers and red-team specialists.
- AI operations and platform engineers.
- Compliance officers and risk management professionals.
- Engineering leads accountable for agent deployment strategies.
21 Hours
Testimonials (1)
inventory and identifying the different risk exposures within AI