Aller au contenu
← Tous les cours

Expert · Leçons : 9

AI security frameworks and red teaming

How NIST AI RMF, MITRE ATLAS, the OWASP LLM Top 10 and CIS Controls fit together, who is responsible for what when you deploy an LLM, and how to plan, run and report an AI red-team engagement.

Commencer le cours

  1. 1 Why AI systems need their own security frameworks

    See what is different about the attack surface of models, LLM applications and agents, and how four frameworks (NIST, MITRE ATLAS, OWASP and CIS) fit together instead of competing.

    8 min
  2. 2 The NIST AI Risk Management Framework and its Generative AI Profile

    Understand the four functions of NIST AI RMF 1.0 (Govern, Map, Measure, Manage), what the Generative AI Profile adds, and where red teaming fits.

    8 min
  3. 3 MITRE ATLAS: mapping an attack on an AI system

    Learn how ATLAS organises tactics, techniques, mitigations and case studies, then map a real documented attack on an AI assistant step by step.

    8 min
  4. 4 The OWASP Top 10 for LLM Applications (and its agentic sibling)

    Learn the ten vulnerability categories in the 2025 OWASP LLM list, study prompt injection and excessive agency in depth, and see how the list maps to ATLAS.

    8 min
  5. 5 Is there shared responsibility for LLMs?

    See how vendor shared-responsibility models and the EU AI Act divide duties between model providers and the organisations that deploy them, and what that means for what you must test yourself.

    9 min
  6. 6 CIS Controls applied to AI systems

    Use CIS Controls v8.1 and the three AI companion guides CIS published in 2026 to check that baseline hygiene covers models, agents and their tool connections.

    8 min
  7. 7 Planning and running an AI red-team engagement

    Scope an engagement, design tests from the four frameworks, combine automated scanners such as garak and PyRIT with manual work, and report findings so that others can act on them.

    9 min
  8. 8 How Anthropic red-teams Claude

    Read what one model developer publishes about testing its own models, and separate what that covers from what an organisation deploying an LLM must still test itself.

    9 min
  9. 9 Capstone: a tabletop red-team exercise against a fictional agent

    Work through a complete engagement on an invented support agent: scope it, review the findings, map each to OWASP, ATLAS and NIST AI RMF, and write a remediation plan.

    10 min

Gratuit, sans compte, sans suivi. Votre progression reste dans ce navigateur.