# Using AI in Cybersecurity Operations Course (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/using-ai-in-cybersecurity-operations-course-self-paced>

## Overview

Security teams already use AI to speed up detection and triage, and attackers are testing its weaknesses. This foundational, self-paced course shows practitioners how to apply AI to log analysis, alert triage, and threat detection, and how to validate AI output before acting on it.

The course then covers the risks AI introduces, including prompt injection, framed through MITRE ATLAS and the OWASP Top 10 for Large Language Model Applications. It closes with the NIST AI Risk Management Framework and CISA guidance on secure AI deployment. No coding or hosted lab is required.

## What you'll learn

- Explain how generative AI and large language models fit into a modern security operations workflow.
- Use AI tools to summarize, prioritize, and triage high volumes of log and alert data.
- Evaluate an AI-generated finding before acting on it, rather than assuming the tool's output is correct.
- Recognize the signs of a prompt injection attempt directed at an AI system.
- Identify the tactics MITRE ATLAS uses to describe attacks against AI-enabled systems.
- Apply the OWASP Top 10 for Large Language Model Applications to spot common AI-related weaknesses.
- Describe how the NIST AI Risk Management Framework structures the management of AI risk.
- Apply CISA guidance on secure AI deployment to everyday security operations decisions.
- Distinguish appropriate from inappropriate uses of AI tools in a security operations setting.
- Draft a basic acceptable-use position for how a security team introduces AI tools responsibly.
- Explain why human review remains necessary when AI tools support detection and triage.
- Assess where in the SOC workflow AI adds the most value and where it introduces the most risk.

## Curriculum

#### Module 1: Understanding AI and Machine Learning for Security Operations

- Lessons: 
  - What Generative AI and Large Language Models Are
  - How Machine Learning Already Supports Detection
  - Where AI Fits in the SOC Workflow
  - Capabilities and Limits of Current AI Tools

- Applied activity: given a short description of a SOC's daily alert volume, learners identify which stages of the workflow, collection, triage, investigation, and response, are reasonable candidates for AI assistance and which are not.

#### Module 2: Applying AI to Detection, Log Analysis, and Alert Triage

- Lessons: 
  - Using AI to Summarize and Triage Log Data
  - AI-Assisted Threat Detection and Correlation
  - Reading AI-Generated Alerts and Screenshots: A Walkthrough
  - Validating AI Output Before Acting On It

- Applied activity: learners review screenshots of an AI tool's summarized output for a batch of security logs and a related alert, then decide what to escalate, what to dismiss, and what needs human follow-up before either.

#### Module 3: Prompt Injection and the Adversarial AI Threat Landscape

- Lessons: 
  - How Prompt Injection Attacks Work
  - MITRE ATLAS and Adversarial Tactics Against AI Systems
  - The OWASP Top 10 for Large Language Model Applications
  - Data Poisoning, Model Manipulation, and Supply Chain Risk

- Applied activity: learners review a screenshot of a flagged prompt injection alert from an AI-enabled security tool and identify which part of the input triggered the flag and which MITRE ATLAS tactic it maps to.

#### Module 4: Governance and Responsible Use of AI in Security Operations

- Lessons: 
  - The NIST AI Risk Management Framework Overview
  - CISA Guidance on Secure AI Deployment
  - Human Oversight and Policy for AI-Assisted Work
  - Building a Responsible AI Adoption Plan for a Security Team

- Applied activity: learners draft a short, one-paragraph acceptable-use statement for AI tools on a hypothetical security team, based on the module's governance material.

## Pricing

**Tuition:** $799
