Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations: Threat Modeling for Agentic AI
- Categories of agentic threats: misuse, escalation, data leakage, and supply-chain vulnerabilities.
- Adversary profiles and attacker capabilities relevant to autonomous agents.
- Mapping assets, trust boundaries, and key control points for agent systems.
Governance, Policy, and Risk Management
- Governance frameworks for agentic systems, including roles, responsibilities, and approval gates.
- Crafting policies: acceptable use, escalation rules, data handling, and auditability.
- Compliance considerations and gathering evidence for audits.
Non-Human Identity & Authentication for Agents
- Architecting agent identities: service accounts, JWTs, and short-lived credentials.
- Implementing least-privilege access patterns and just-in-time credentialing.
- Managing identity lifecycle, rotation, delegation, and revocation.
Access Controls, Secrets, and Data Protection
- Fine-grained access control models and capability-based patterns for agents.
- Secrets management, encryption in transit and at rest, and data minimization strategies.
- Safeguarding sensitive knowledge sources and PII from unauthorized agent access.
Observability, Auditing, and Incident Response
- Designing telemetry for agent behavior: intent tracing, command logs, and provenance.
- SIEM integration, setting alerting thresholds, and ensuring forensic readiness.
- Developing runbooks and playbooks for agent-related incidents and containment.
Red-Teaming Agentic Systems
- Planning red-team exercises: defining scope, rules of engagement, and safe failover procedures.
- Adversarial techniques: prompt injection, tool misuse, chain-of-thought manipulation, and API abuse.
- Conducting controlled attacks to measure exposure and impact.
Hardening and Mitigations
- Engineering controls: response throttles, capability gating, and sandboxing.
- Policy and orchestration controls: approval flows, human-in-the-loop mechanisms, and governance hooks.
- Model and prompt-level defenses: input validation, canonicalization, and output filtering.
Operationalizing Safe Agent Deployments
- Deployment strategies: staging, canary releases, and progressive rollouts for agents.
- Change control, testing pipelines, and pre-deployment safety checks.
- Cross-functional governance: playbooks for security, legal, product, and ops teams.
Capstone: Red-Team / Blue-Team Exercise
- Execute a simulated red-team attack on a sandboxed agent environment.
- Defend, detect, and remediate as the blue team using established controls and telemetry.
- Present findings, a remediation plan, and recommended policy updates.
Summary and Next Steps
Requirements
- Robust experience in security engineering, system administration, or cloud operations.
- Working knowledge of AI/ML concepts and the behavior of large language models (LLMs).
- Proficiency in identity & access management (IAM) and secure system design principles.
Target Audience
- Security engineers and red-team specialists.
- AI operations and platform engineers.
- Compliance officers and risk management professionals.
- Engineering leads overseeing agent deployments.
21 Hours
Testimonials (1)
inventory and identifying the different risk exposures within AI