Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations: Threat Models for Agentic AI
- Categorizing agentic threats: misuse, privilege escalation, data leakage, and supply-chain vulnerabilities.
- Defining adversary profiles and attacker capabilities specifically targeting autonomous agents.
- Mapping assets, defining trust boundaries, and identifying critical control points for agent interactions.
Governance, Policy, and Risk Management
- Establishing governance frameworks for agentic systems, including roles, responsibilities, and approval gates.
- Developing policies for acceptable use, escalation rules, data handling protocols, and auditability.
- Addressing compliance requirements and strategies for evidence collection during audits.
Non-Human Identity & Authentication for Agents
- Architecting agent identities using service accounts, JWTs, and short-lived credentials.
- Implementing least-privilege access patterns and just-in-time credentialing strategies.
- Managing the identity lifecycle, including rotation, delegation, and revocation processes.
Access Controls, Secrets, and Data Protection
- Applying fine-grained access control models and capability-based security patterns for agents.
- Managing secrets, enforcing encryption-in-transit and at-rest, and practicing data minimization.
- Safeguarding sensitive knowledge sources and PII from unauthorized access by agents.
Observability, Auditing, and Incident Response
- Designing telemetry for agent behavior, focusing on intent tracing, command logs, and provenance tracking.
- Integrating with SIEM systems, setting alerting thresholds, and ensuring forensic readiness.
- Developing runbooks and playbooks for managing agent-related incidents and containment procedures.
Red-Teaming Agentic Systems
- Planning red-team exercises by defining scope, rules of engagement, and safe failover mechanisms.
- Applying adversarial techniques such as prompt injection, tool misuse, chain-of-thought manipulation, and API abuse.
- Executing controlled attacks to measure system exposure and assess potential impact.
Hardening and Mitigations
- Implementing engineering controls like response throttles, capability gating, and sandboxing.
- Enforcing policy and orchestration controls through approval flows, human-in-the-loop interventions, and governance hooks.
- Deploying model and prompt-level defenses, including input validation, canonicalization, and output filtering.
Operationalizing Safe Agent Deployments
- Adopting deployment patterns such as staging, canary releases, and progressive rollouts for agents.
- Establishing change control procedures, testing pipelines, and pre-deployment safety checks.
- Facilitating cross-functional governance involving security, legal, product, and operations teams.
Capstone: Red-Team / Blue-Team Exercise
- Executing a simulated red-team attack against a sandboxed agent environment.
- Acting as the blue team to defend, detect, and remediate using established controls and telemetry.
- Presenting findings, outlining the remediation plan, and recommending policy updates.
Summary and Next Steps
Requirements
- A strong foundation in security engineering, system administration, or cloud operations.
- Proficiency in AI/ML concepts and an understanding of large language model (LLM) behaviors.
- Practical experience with identity & access management (IAM) and secure system design principles.
Target Audience
- Security engineers and red-team specialists.
- AI operations and platform engineers.
- Compliance officers and risk managers.
- Engineering leads overseeing the deployment of agent systems.
21 Hours
Testimonials (1)
inventory and identifying the different risk exposures within AI