# AI Security Monitoring and Incident Response Course (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/ai-security-monitoring-and-incident-response-self-paced>

## Overview

A focused, practitioner-level course on the two things traditional IT monitoring and incident response do not cover well for AI systems: knowing what a compromise looks like, and knowing what to do about it. The framing that makes it work is that an AI system inherits every traditional attack surface and then adds new ones tied to data, models and inference behavior — an attacker can manipulate what a model learns from, or what it sees at run time, without ever reaching the infrastructure. Monitoring therefore has to move from "is the system running" to "is the system behaving the way it is supposed to, on data it is supposed to see, for the purposes it was approved for."

**The practical core is a signals table that maps observed patterns to likely causes** , paired with the first-hour triage sequence. A sustained spike in near-identical unusual inputs reads as adversarial probing; a slow accuracy decline reads as drift; an unexplained query spike from one credential reads as an extraction attempt. From there the course turns to judgment — separating anomalies from incidents, preserving the evidence responders routinely lose (model version in use, surrounding prompt and response logs, training data lineage, guardrail configuration in effect), and classifying severity by impact rather than technical complexity. Its sharpest teaching point: an incorrect benefits determination caused by a data integrity failure is a high-severity incident even though nothing technically broke. The final module applies the four-phase incident response lifecycle with containment actions specific to AI, including model rollback to a validated version, disabling automated decision-making in favor of human review, quarantining a compromised training data source, and closing a confirmed prompt injection vector. It sits deliberately downstream of [AI Security & Governance for Government Course (Self-Paced)](https://www.graduateschool.edu/courses/ai-security-and-governance-for-government-self-paced), which covers the governance landscape this course does not repeat.

## What you'll learn

- Explain how AI systems introduce security risks that differ from, or compound, traditional IT risks
- Use the working vocabulary of AI security incidents, including data poisoning, adversarial examples, prompt injection, model drift and model extraction
- Describe what continuous monitoring means for a high-impact AI system, beyond uptime and throughput
- Distinguish the four categories of AI monitoring and select the technique that fits each
- Apply a risk-based approach to security event logging for AI systems, and identify what must be captured and retained
- Read common monitoring signals and identify what each most likely indicates
- Recognize which anomalies qualify as AI security incidents and which do not
- Preserve the evidence unique to AI incidents, including model version, prompt and response logs, and training data lineage
- Classify incident severity by impact on safety, rights, mission and data rather than by technical complexity
- Apply the four-phase incident response lifecycle to an AI-specific scenario
- Select containment actions specific to AI systems, including model rollback and disabling automated decisioning
- Carry out post-incident activity including root cause analysis and revalidation before returning a system to automated operation

## Curriculum

#### Module 1

- Foundations: The AI Security Landscape and Federal Policy Context (1h50)
- Why AI systems need a different security lens
- The shared vocabulary of data poisoning, adversarial examples, prompt injection, model drift, model extraction and supply-chain risk
- What counts as an AI incident, covering malicious, accidental and environmental causes
- The specific current guidance that bears on monitoring and incident response
- Who you work with day to day

#### Module 2

- AI Security Monitoring Practices (1h50)
- What continuous monitoring means for high-impact AI systems
- The four monitoring categories of data quality and integrity, model performance and behavior, access and usage, and output and impact
- Baseline and anomaly detection, threshold alerting, adversarial input detection and human-in-the-loop review
- Risk-based security logging built on continuous event monitoring and threat hunting capability areas
- A signals table mapping observed patterns to likely causes

#### Module 3

- Identifying and Classifying AI Security Incidents (1h50)
- Recognizing an AI security incident
- The evidence and artifacts unique to AI incidents
- Classifying severity by impact on safety, legal rights, benefits, critical infrastructure and sensitive data
- The initial triage sequence
- A prompt-injection case scenario worked end to end

#### Module 4

- AI Incident Response, Reporting, and Post-Incident Actions (1h50)
- The four-phase lifecycle of preparation, detection and analysis, containment eradication and recovery, and post-incident activity, each mapped to AI-specific activity
- Containment actions specific to AI systems
- Internal reporting and escalation
- Root cause analysis, updating impact assessments and monitoring plans, revalidation before return to automated operation, and when stakeholder communication is warranted

## Pricing

**Tuition:** $799
