Hello and welcome to the world of AI security! Whether you’re a seasoned security expert looking to expand into AI or a newcomer to the field entirely, navigating the wealth of available resources can feel overwhelming. I wanted to share a curated list of materials I’ve collected and found helpful on my learning journey to help you build a solid foundation in AI security, covering everything from foundational knowledge, threats, and vulnerabilities to AI governance frameworks.
1. AI Frameworks, Standards & Guidelines
Government & Standards Frameworks
- AI Risk Management Framework — NIST
- DHS AI in Critical Infrastructure Framework — DHS Generative AI Public Sector Playbook
- AI Data Security Best Practices — CISA
Industry Standards & Guidelines
- ISO 42001 — AI Management System (AIMS) — Official Guide
- ISO 42001 — AI Management System- Controls explained
- Google’s Secure AI Framework
- EU AI Act
- OpenAI Preparedness Framework v2
- SFIA AI Skills Framework
- SANS Critical AI Security Guidelines v1.1
2. Threat Intelligence & Risk Assessment
Threat Frameworks & Taxonomies
- OWASP Top 10 for LLMs
- MITRE ATLAS Framework
- Microsoft AI Agent Failure Modes Taxonomy
- SANS AI Security Risk-Based Approach 2025
- The Vulnerable MCP Project
Risk Assessment &Â Analysis
- Adding Structure to AI Harm — Georgetown CSET
- Cybersecurity Risks of AI-Generated Code
- MIT AI Risk Repository
3. Learning & Education
Training Programs
- AI Security Fundamentals — Microsoft Learn
- Build Strong Security Posture for AI — Microsoft
- AWS Securing Generative AI Course — New AWS Skill Builder course for securing GenAI.
- Coursera: AI for Cybersecurity
Certifications
- AIGP Training — IAPP
- AIGP Certification Masterclass — Udemy
- AAIA Certification — ISACA
4. Practical Security Implementation
Security Testing & Red Teaming
- PyRIT — Hacking Generative AI
- Web LLM Attacks — PortSwigger
- AI Security Solutions Landscape by OWASP
Organizational Implementation
- Responsible AI Policy Template
- JPMorgan Open Letter to Suppliers
- How to Scale Responsible AI in Enterprise
5. Emerging Threats & Current Events
- What Is Shadow AI — IBM
- Cisco State of AI Security Report 2025 — Inaugural comprehensive AI security report
- Orca 2024 State of AI Security Report — Real-world AI security risks in production environments
- MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits
- MCP Security Exposed: What You Need to Know Now by Palo Alto
This list should give you a pretty solid starting point for diving into AI security, though the field continues to evolve rapidly with new threats, frameworks, and solutions emerging regularly. If you have any resources to share, definitely drop them in the comments.
Disclaimer
The content provided in this resource compilation is for informational and educational purposes only and does not constitute legal, regulatory, cybersecurity, or professional advice. While every effort has been made to ensure accuracy and currency of the information, including the use of AI tools for content organization and formatting, the rapidly evolving nature of AI security means that some details may become outdated. Readers should independently verify all information, consult with qualified professionals for specific guidance, and conduct their own due diligence before implementing any security measures or frameworks. The inclusion of any resource, framework, or tool does not constitute an endorsement of its effectiveness or suitability for any particular use case. The views and recommendations expressed are those of the author and do not necessarily reflect the opinions or policies of any affiliated organizations, employers, or the creators of the referenced resources.