Jason Edwards
Certified: The ISACA AAISM Audio Course
Welcome to Certified: The ISACA AAISM Audio Course. If you’re responsible for security, risk, assurance, or governance and AI is now part of your environment, you’re in the right place. This course is designed to help you prepare for the ISACA AAISM certification with clear explanations and practical framing, so the topics feel manageable instead of abstract. Each episode stays focused on the concepts the exam tests, while still connecting them to real situations you might face when reviewing AI use cases, third-party AI services, or internal model development. Expect straightforward definitio...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 41 — Notify and escalate during AI incidents with the right triggers (Task 16) 14.02.2026 13:34
This episode teaches how to notify and escalate during AI incidents using clear triggers that prevent both overreaction and dangerous delay, which is exactly what AAISM scenarios test when they ask who should be informed and when. You will learn to define incident severity for AI by combining impact, exposure scope, data sensitivity, and controllability, then map each level to specific notificatio...
Episode 40 — Contain AI incidents quickly by limiting access and stopping risky flows (Task 16) 14.02.2026 10:53
This episode teaches containment actions tailored to AI incidents, emphasizing rapid access limitation and flow interruption, which AAISM often tests as the most defensible first move when uncertainty is high. You will learn to identify the fastest containment levers, such as disabling or rotating keys, restricting service accounts, pausing specific endpoints, blocking risky prompts or integration...
Episode 39 — Report AI security incidents on time without losing accuracy (Task 15) 14.02.2026 11:16
This episode focuses on timely incident reporting while preserving accuracy, which AAISM treats as a disciplined process that balances speed, evidence, and stakeholder needs. You will learn how to define reporting triggers, align to notification requirements, and provide early updates that are explicit about what is confirmed, what is suspected, and what is still being investigated. We walk throug...
Episode 38 — Document AI incidents clearly for regulators, contracts, and executive updates (Task 15) 14.02.2026 12:43
This episode teaches how to document AI incidents so the record supports regulatory expectations, contractual commitments, and executive decision-making, which the AAISM exam often evaluates through communication and evidence quality. You will learn to capture a clear timeline, scope and impact, affected systems and data, containment actions, and the rationale for key decisions, while maintaining...
Episode 37 — Investigate AI security incidents by collecting the right evidence fast (Task 15) 14.02.2026 13:29
This episode explains how to investigate AI security incidents by quickly collecting evidence that preserves accuracy under pressure, which AAISM scenarios test through triage and investigation choices. You will learn what “right evidence” means in AI contexts, including prompt and response logs, model version and configuration details, pipeline and data lineage records, access logs for service ac...
Episode 36 — Domain 1 quick review: governance, policies, assets, metrics, and training (Tasks 1–3) 14.02.2026 12:28
This episode reinforces Domain 1 by connecting governance, policies, asset inventory, metrics, and training into one coherent operating model, because AAISM questions often test whether you can see how these components support each other. You will revisit how charters and roles create decision rights, how policies become enforceable standards and procedures, and how inventories and classifications...
Episode 35 — Operationalize tools with tuning, ownership, and measurable outcomes (Task 19) 14.02.2026 11:26
This episode teaches how to operationalize AI security tools so they deliver measurable risk reduction over time, which the AAISM exam tests through questions about sustainability, governance routines, and control effectiveness. You will learn to assign tool ownership, define tuning cycles, and set measurable outcomes such as improved detection accuracy, reduced time to triage, increased inventory...
Episode 34 — Implement AI security tools into monitoring, alerting, and response workflows (Task 19) 14.02.2026 12:32
This episode explains how to implement AI security tools so they produce usable monitoring, alerts, and response actions rather than isolated dashboards, which AAISM scenarios often frame as operational integration and accountability. You will learn to connect tool telemetry to alert routing, triage procedures, and escalation paths, including how to define what constitutes an incident versus a per...
Episode 33 — Review AI security tools by coverage, gaps, and operational fit (Task 19) 14.02.2026 12:20
This episode focuses on evaluating AI security tools the way the AAISM exam expects: by asking what risks they cover, what gaps remain, and whether the tools can actually be operated at scale with reliable outcomes. You will learn to assess tool capabilities across key areas such as visibility into model endpoints, prompt and output monitoring, data lineage and integrity checks, access control int...
Episode 32 — Use metrics to prioritize work and prove security program value (Task 18) 14.02.2026 13:41
This episode teaches how to use AI security metrics to prioritize limited time and budget while also demonstrating program value in terms leaders understand, which AAISM commonly tests through governance and reporting scenarios. You will learn to translate metric trends into decisions, such as which models need deeper assessment, which teams need targeted training, or which controls require tuning...
Episode 31 — Monitor AI metrics to spot misuse, drift, and early incident signals (Task 18) 14.02.2026 14:16
This episode explains how to monitor AI metrics in a way that reveals misuse, drift, and early incident signals before they become customer-impacting failures, which is a recurring AAISM exam expectation for operational readiness. You will learn to differentiate performance drift from security-relevant anomalies, then connect each metric to a practical response action, such as triggering deeper re...
Episode 30 — Define AI security metrics leaders can understand and act on (Task 18) 14.02.2026 16:04
This episode teaches how to define AI security metrics that drive decisions, because AAISM scenarios often test whether you can choose measurements that are meaningful to executives and useful to operators. You will learn to distinguish activity metrics from outcome metrics, and to build a small set that reflects risk reduction, control performance, and exposure trends, such as inventory coverage,...
Episode 29 — Build an AI security program that fits the enterprise security program (Task 19) 14.02.2026 18:27
This episode explains how to integrate AI security into the broader enterprise security program so controls are consistent, measurable, and supportable, which is a common AAISM theme when questions ask how to avoid “special case” security that fails in operations. You will learn how to align AI security governance with existing risk processes, identity standards, data protection controls, logging...
Episode 28 — Manage retention and deletion to reduce long-term AI data exposure (Task 14) 14.02.2026 19:12
This episode focuses on retention and deletion as risk-reduction controls for AI data, which AAISM tests through scenarios involving compliance obligations, privacy expectations, and the operational reality that data and logs tend to accumulate. You will learn how to define retention rules for training data, evaluation data, embeddings, prompts, and inference logs based on business need, legal dut...
Episode 27 — Preserve data integrity so models stay reliable and trustworthy (Task 14) 14.02.2026 16:40
This episode teaches integrity protections that keep AI data trustworthy, because AAISM scenarios often hinge on whether model behavior can be relied on when data pipelines are exposed to change and manipulation. You will learn what integrity means for AI data, including completeness, accuracy, provenance, and resistance to unauthorized modification, and how to use controls such as lineage trackin...
Episode 26 — Protect training and test data with access control and secure storage (Task 14) 14.02.2026 18:26
This episode explains how to protect training and test data so confidentiality and compliance are preserved, and why AAISM questions often focus on access control and storage choices as the most defensible first steps. You will learn to apply least privilege to datasets, enforce separation between environments, use strong identity and authentication for pipelines and analysts, and ensure storage c...
Episode 25 — Identify data risks across the AI life cycle: leaks and tampering (Task 14) 14.02.2026 18:32
This episode teaches how to identify data risks across the AI life cycle, focusing on leakage and tampering threats that AAISM frequently tests through scenarios involving training data, evaluation sets, and production inputs and outputs. You will learn to map where data enters, moves, transforms, and is stored, then identify risk points such as over-permissive access, unsafe sharing, pipeline exp...
Episode 24 — Keep the AI inventory accurate with routine governance checks (Task 13) 14.02.2026 18:36
This episode shows how to keep an AI inventory accurate over time, because AAISM expects you to treat inventory as a living control rather than a one-time project. You will learn governance routines that maintain accuracy, including onboarding checklists for new models and vendors, periodic attestations by owners, change-management hooks that require inventory updates, and automated discovery sign...
Episode 23 — Classify AI assets by sensitivity, criticality, and compliance scope (Task 13) 14.02.2026 18:44
This episode explains how to classify AI assets so controls can be applied proportionally, which is a common AAISM decision point when scenarios ask what to protect first and how to justify the level of protection. You will learn to classify by sensitivity of data and outputs, business criticality of the AI service, operational impact of downtime, and compliance scope such as regulated data types...
Episode 22 — Inventory AI assets: models, prompts, data, and key dependencies (Task 13) 14.02.2026 16:59
This episode teaches how to build an AI asset inventory that is useful for security, audit, and incident response, which AAISM scenarios often test by asking what must be known before you can manage risk. You will define AI assets broadly to include models, training and evaluation datasets, prompt libraries, system prompts, embeddings, inference logs, endpoints, service accounts, secrets, and thir...
Episode 21 — Refresh training when threats, tools, and regulations change (Task 21) 14.02.2026 16:58
This episode explains how to keep AI security awareness training current so it remains effective as new model capabilities, attacker methods, and compliance obligations evolve, which the AAISM exam often frames as “how do you prevent training from going stale.” You will learn how to set refresh triggers based on incidents, tool changes, vendor updates, policy revisions, and regulatory developments...
Episode 20 — Build AI security awareness training that sticks in daily work (Task 21) 14.02.2026 18:23
This episode teaches how to design AI security awareness training that changes day-to-day decisions rather than only satisfying a checkbox, which AAISM scenarios often evaluate through effectiveness, coverage, and reinforcement. You will learn to tailor training to roles, focusing on the specific mistakes each group can realistically make, such as developers mishandling secrets in pipelines, analy...
Episode 19 — Create acceptable use guidelines that reduce risky AI behavior (Task 21) 14.02.2026 19:13
This episode shows how acceptable use guidelines for AI reduce operational risk by setting clear boundaries on tools, data, prompts, outputs, and escalation, and how AAISM questions test your ability to choose controls that change user behavior. You will learn what to include, such as prohibited data types, approval requirements for external AI services, handling of generated content, and reportin...
Episode 18 — Essential Terms: Plain-Language Glossary for fast, accurate recall (Tasks 1–22) 14.02.2026 15:00
This episode builds a high-yield vocabulary baseline for AAISM by defining essential terms the way the exam uses them, then anchoring each term to a governance, risk, or control implication. You will learn to distinguish similar concepts that are easy to confuse under time pressure, such as risk acceptance versus exception handling, monitoring versus testing, and assurance versus implementation. W...
Episode 17 — Keep AI security policies current using ownership and change control (Task 2) 14.02.2026 16:28
This episode explains how policy maintenance becomes a security control, especially for AI where systems, threats, and regulations evolve quickly, and how AAISM scenarios test governance maturity through change management. You will learn to assign clear policy owners, define review triggers, and use change control to prevent silent drift between stated requirements and actual practice. We cover pr...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.