Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations: Threat Models for Agentic AI
- Categorizing agentic threats: including misuse, privilege escalation, data leakage, and supply-chain risks.
- Defining adversary profiles and attacker capabilities uniquely associated with autonomous agents.
- Mapping critical assets, trust boundaries, and control points specific to agent operations.
Governance, Policy, and Risk Management
- Establishing governance frameworks for agentic systems, covering roles, responsibilities, and approval gates.
- Crafting policies for acceptable use, escalation rules, data handling, and ensuring auditability.
- Addressing compliance requirements and methods for collecting evidence for audits.
Non-Human Identity & Authentication for Agents
- Designing agent identities using service accounts, JWTs, and short-lived credentials.
- Implementing least-privilege access patterns and just-in-time credentialing strategies.
- Managing the identity lifecycle, including rotation, delegation, and revocation protocols.
Access Controls, Secrets, and Data Protection
- Applying fine-grained access control models and capability-based patterns for agent interactions.
- Securing secrets management, encryption in transit and at rest, and enforcing data minimization.
- Safeguarding sensitive knowledge sources and PII from unauthorized access by agents.
Observability, Auditing, and Incident Response
- Creating telemetry structures for agent behavior, including intent tracing, command logs, and provenance tracking.
- Integrating with SIEM systems, setting alerting thresholds, and ensuring forensic readiness.
- Developing runbooks and playbooks for responding to and containing agent-related incidents.
Red-Teaming Agentic Systems
- Planning red-team engagements: defining scope, rules of engagement, and safe failover mechanisms.
- Exploring adversarial techniques such as prompt injection, tool misuse, chain-of-thought manipulation, and API abuse.
- Executing controlled attacks to measure exposure and assess potential impact.
Hardening and Mitigations
- Implementing engineering controls like response throttles, capability gating, and sandboxing.
- Establishing policy and orchestration controls, including approval flows, human-in-the-loop mechanisms, and governance hooks.
- Deploying model and prompt-level defenses through input validation, canonicalization, and output filters.
Operationalizing Safe Agent Deployments
- Adopting deployment patterns such as staging, canary releases, and progressive rollouts for agents.
- Maintaining change control, robust testing pipelines, and pre-deployment safety checks.
- Fostering cross-functional governance among security, legal, product, and operations teams.
Capstone: Red-Team / Blue-Team Exercise
- Executing a simulated red-team attack against a sandboxed agent environment.
- Acting as the blue team to defend, detect, and remediate using established controls and telemetry.
- Presenting findings, outlining a remediation plan, and proposing policy updates.
Summary and Next Steps
Requirements
- A strong foundational knowledge in security engineering, system administration, or cloud operations.
- Proficiency with AI/ML concepts and a clear understanding of large language model (LLM) behaviors.
- Practical experience with identity and access management (IAM) and secure system design principles.
Target Audience
- Security engineers and red-team specialists.
- AI operations and platform engineers.
- Compliance officers and risk management professionals.
- Engineering leaders overseeing agent deployments.
21 Hours
Testimonials (1)
inventory and identifying the different risk exposures within AI