Core 7 | Security spine
AI Governance, Assurance, and Risk
Part of the Applied AI Security and Assurance curriculum, authored by Cameron Hopkin, CISSP, CEH, CHFI. Published as a reference, not an enrollable course.
Description
Ties the technical spine to policy, compliance, and assurance. This is where alignment and post-training are treated as governance problems, and where measurable assurance is separated from paper compliance.
Outcomes
- Apply recognized AI risk frameworks.
- Construct and stress-test an assurance case.
- Evaluate post-training and alignment methods as governance controls.
- Argue accountability without hand-waving.
Modules
- Risk frameworks: the NIST AI Risk Management Framework and its Generative AI Profile (AI 600-1), plus relevant DoD and federal guidance.
- Standards and law: ISO/IEC 42001 as the first certifiable AI management system standard, and the EU AI Act.
- Assurance cases and how you argue a system is safe enough.
- Post-training as governance: RLHF, DPO, reward modeling, and their failure modes.
- Ethics, societal impact, and accountability.
- Measurable assurance versus paper compliance.
Signature lab
Write an assurance case for a real deployed system and then stress-test it to failure.
Reading anchors
- NIST AI Risk Management Framework and its Generative AI Profile (AI 600-1) [6].
- ISO/IEC 42001, the first certifiable AI management system standard [9].
- The EU AI Act, including its penalty regime [9].
Research thread
What separates measurable assurance from compliance theater, and how to close that gap.