Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations: Threat Models for Agentic AI
- Categorizing agentic threats: misuse, privilege escalation, data leakage, and supply-chain vulnerabilities.
- Profiling adversaries and assessing attacker capabilities specific to autonomous agent environments.
- Mapping assets, defining trust boundaries, and identifying critical control points for agent interactions.
Governance, Policy, and Risk Management
- Establishing governance frameworks for agentic systems, including roles, responsibilities, and approval gates.
- Crafting policies that address acceptable use, escalation protocols, data handling standards, and auditability.
- Addressing compliance requirements and ensuring evidence collection for regulatory audits.
Non-Human Identity & Authentication for Agents
- Designing agent identities using service accounts, JWTs, and short-lived credentials.
- Implementing least-privilege access patterns and just-in-time credentialing mechanisms.
- Managing identity lifecycles, including rotation, delegation, and revocation strategies.
Access Controls, Secrets, and Data Protection
- Applying fine-grained access control models and capability-based patterns tailored for agents.
- Overseeing secrets management, encryption (in-transit and at-rest), and data minimization practices.
- Safeguarding sensitive knowledge sources and PII from unauthorized access by agents.
Observability, Auditing, and Incident Response
- Building telemetry for agent behavior, covering intent tracing, command logs, and provenance tracking.
- Integrating with SIEM platforms, defining alerting thresholds, and preparing for forensic analysis.
- Developing runbooks and playbooks for managing agent-related incidents and containment.
Red-Teaming Agentic Systems
- Planning red-team engagements, including scope definition, rules of engagement, and safe failover procedures.
- Executing adversarial techniques such as prompt injection, tool misuse, chain-of-thought manipulation, and API abuse.
- Conducting controlled attacks to measure exposure levels and assess impact.
Hardening and Mitigations
- Deploying engineering controls like response throttles, capability gating, and sandboxing.
- Implementing policy and orchestration controls, including approval flows, human-in-the-loop mechanisms, and governance hooks.
- Applying model and prompt-level defenses such as input validation, canonicalization, and output filtering.
Operationalizing Safe Agent Deployments
- Utilizing deployment patterns such as staging, canary releases, and progressive rollouts for agents.
- Enforcing change control, testing pipelines, and pre-deployment safety checks.
- Coordinating cross-functional governance across security, legal, product, and operations teams.
Capstone: Red-Team / Blue-Team Exercise
- Executing a simulated red-team attack against a sandboxed agent environment.
- Defending, detecting, and remediating as the blue team using established controls and telemetry.
- Presenting findings, remediation plans, and proposed policy updates.
Summary and Next Steps
Requirements
- Proficient understanding of security engineering, system administration, or cloud operations.
- Working knowledge of AI/ML concepts, particularly regarding the behavior of Large Language Models (LLMs).
- Demonstrated experience in Identity & Access Management (IAM) and secure system design.
Target Audience
- Security engineers and red-team specialists.
- AI operations and platform engineers.
- Compliance officers and risk management professionals.
- Engineering leaders with responsibility for agent deployments.
21 Hours
Testimonials (1)
inventory and identifying the different risk exposures within AI