AI TRAININGS · ISO/IEC 27001:2022 · ISO/IEC 42001:2023 · NIST AI RMF 1.0

AI in Information Security Management — ISO/IEC 27001

Bring AI systems, assistants and model providers into ISMS scope through defensible asset, risk, control, supplier, incident and audit evidence.

Recommended format2 days · 12 instructional hours · live workshop
PrerequisiteWorking knowledge of the relevant management system is helpful; licensed standards remain the controlling source.
Scope boundaryTraining supports competence and implementation planning. It is not certification, accredited auditor training, legal advice or a conformity assessment.

Who should attend

AI in ISO/IEC 27001

  • CISOs, ISMS managers and security governance leads
  • Risk, privacy, legal and internal audit teams
  • Security architecture, cloud and engineering teams
  • AI product owners, data owners and procurement

Learning outcomes

  1. 01

    Set defensible AI and ISMS scope boundaries

  2. 02

    Build AI asset, data-flow and supplier inventories

  3. 03

    Assess confidentiality, integrity and availability risks plus AI-specific harms

  4. 04

    Select and justify controls without claiming a universal Annex A mapping

  5. 05

    Define secure AI acquisition, development and operational change

  6. 06

    Prepare incident, monitoring and audit evidence

Detailed training outline

8 modules, each tied to a working output.

Bring AI systems, assistants and model providers into ISMS scope through defensible asset, risk, control, supplier, incident and audit evidence.

  1. 01

    ISMS scope and AI system context

    Identify organizational context, interested parties, AI lifecycle roles, shared-responsibility boundaries and interfaces that belong in ISMS scope.

  2. 02

    AI assets, data flows and classification

    Inventory models, prompts, system instructions, datasets, embeddings, vector stores, evaluations, credentials, outputs, logs, users and provider services.

  3. 03

    AI-enhanced information security risk assessment

    Develop scenarios for data disclosure, prompt injection, excessive agency, poisoned retrieval, insecure output handling, model theft, availability loss, shadow AI and misleading output.

  4. 04

    Risk treatment and control justification

    Select organizational, people, physical and technological controls from actual risk treatment needs; document applicability, ownership, implementation evidence and residual risk.

  5. 05

    Identity, access, secrets and data lifecycle

    Apply least privilege, workload identity, segregation, secret handling, input restrictions, retention, deletion, masking and controlled use of sensitive data.

  6. 06

    Secure acquisition, development and model operations

    Define security requirements, approved architectures, evaluation gates, adversarial testing, component provenance, environment separation, deployment approval and rollback.

  7. 07

    Provider, cloud and supply-chain assurance

    Assess contractual data use, model training terms, sub-processors, security evidence, logging, incident notice, data location, resilience, change notice, portability and exit.

  8. 08

    Monitoring, incident response and audit evidence

    Define logging, detection, abuse reporting, model-quality signals, triage, containment, evidence preservation, regulatory escalation, internal audit sampling and management-review inputs.

Participant working pack

Participant working pack

Training supports competence and implementation planning. It is not certification, accredited auditor training, legal advice or a conformity assessment.

Authoritative references

Authoritative references

Working knowledge of the relevant management system is helpful; licensed standards remain the controlling source.

AI TRAININGS

Request dates and delivery format

Training supports competence and implementation planning. It is not certification, accredited auditor training, legal advice or a conformity assessment.