Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Microsoft

Risk and Security Strategy

Microsoft via Coursera

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
This course covers the full arc of AI risk management and security strategy. You’ll classify and populate AI risk registers using the NIST AI RMF, prioritize risks for treatment, quantify financial exposure using the FAIR methodology, apply STRIDE threat modeling to AI inference endpoints, and evaluate alignment between the AI security roadmap and corporate strategy. Familiarity with cybersecurity risk concepts and organizational strategy frameworks is recommended. By the end of this course, you'll be able to build and manage a complete AI risk register, estimate annualized loss expectancy for AI scenarios, document threat mitigations in architecture decision records, and identify gaps between your security roadmap and organizational strategy. This course is designed for security managers, risk analysts, and AI governance leads who are responsible for assessing and treating AI-specific risks and who are comfortable with cybersecurity risk concepts and organizational strategy frameworks.

Syllabus

  • AI Risk Register: Map Risk Categories
    • This module introduces the NIST AI RMF (National Institute of Standards and Technology Artificial Intelligence Risk Management Framework) and its four functions, a practical working taxonomy (data, model, usage) for fast risk triage, and the crosswalk that maps each working category to its authoritative NIST AI 600-1 category. Learners build the conceptual foundation needed to recognize and classify AI risks before populating a register in the next module.
  • AI Risk Register: Populate the Register
    • This module moves from classification to artifact production. Learners populate an AI risk register for a voice-bot project, assigning categories, owners, and initial scores, and recording the NIST AI 600-1 mapping for each entry, producing a governance artifact (referred to in this course as a portfolio-ready artifact—this is course terminology, not an official NIST designation) aligned to the NIST AI RMF.
  • Prioritize the Risk Register
    • This module turns a populated risk register into a sequenced treatment plan. Learners analyze Likelihood–Impact scores, factor in qualitative considerations beyond raw scores, and identify the top five AI risks that warrant mitigation workshops. The "top five" is the output of this analysis, not a predefined list.
  • Risk Treatment: Evaluate Residual Risk
    • This module addresses the "what now" question after mitigation. Learners rescore risks post-control, evaluate residual exposure against organizational tolerance, and draft a recommendation memo defending acceptance for low-residual items and further treatment for the rest.
  • AI Risk Exposure: Quantify Monetary Loss
    • This module gives learners a working command of FAIR methodology—the variables, the math, and the calculator workflow—to estimate annualized loss expectancy for an AI data-leak scenario and add the figure to the risk register.
  • AI Risk Exposure: Analyze Insurance Gaps
    • This module turns cyber-insurance policy wording into a control checklist that AI governance leaders can defend. Learners compare a sample cyber-insurance policy against current AI controls, identify the unmet requirements that could trigger exclusions or void coverage, and produce a gap briefing for the security manager.
  • STRIDE AI Endpoint: Map Threats to the Endpoint
    • This module builds the conceptual foundation for AI endpoint threat modeling. Learners map the six STRIDE threat categories to AI inference endpoint attack surfaces—from prompt injection at the API edge to model extraction at the inference layer—building the analytical command they'll need to produce mitigations and an ADR (an Architecture Decision Record, a structured document that captures a significant architectural decision).
  • STRIDE AI Endpoint: Document Mitigations in the ADR
    • This module turns identified threats into engineered mitigations and a defensible Architecture Decision Record. Learners pair threats with mitigation choices, weigh trade-offs (cost, performance, completeness), and produce a complete ADR (An Architecture Decision Record is a structured document that captures a significant architectural decision) ready for upload to an architecture repository.
  • AI Security Roadmap: Map Initiatives to Strategy
    • This module builds the analytical foundation for roadmap-to-strategy alignment work. Learners study corporate security strategy structure and AI security roadmap structure, then use a provided alignment matrix to map each AI security initiative to one or more strategy pillars, surfacing both misaligned initiatives and coverage gaps.
  • AI Security Roadmap: Recommend Course Corrections
    • This module moves from alignment analysis to executive-facing recommendation. Learners study course correction options for misaligned initiatives and coverage gaps, then present and defend a recommendation to a CISO-level audience in a Coach Role Play, practicing the upward communication skill that determines whether course corrections actually happen.
  • GenAI Module: AI-Assisted Risk & Threat Analysis
    • Lead on GenAI use in AI governance work rather than being surprised by it. This module gives CB3 governance professionals a working command of how generative AI tools accelerate risk register population, STRIDE threat enumeration, and alignment analysis, and the verification patterns that protect against hallucinations, confidentiality leakage, and audit trail gaps. You'll produce a portfolio-ready GenAI-assisted analysis with an annotated evaluation that demonstrates the human-in-the-loop oversight that makes GenAI use defensible at the governance level. Cross-platform applicability: This module teaches GenAI governance using Microsoft's enterprise AI stack (Azure OpenAI, Microsoft Purview, Azure AI Content Safety) because that is the credential's anchor ecosystem and where the enterprise data protection conversation lands most clearly for CB3 learners. Learners working in non-Microsoft environments can map the same concepts to equivalent enterprise stacks—AWS Bedrock + Macie + Guardrails, GCP Vertex AI + Sensitive Data Protection + Model Armor, or comparable—without losing the underlying skill. The Microsoft anchor is the canonical example; the governance pattern transfers.
  • Project Module: AI Risk & Security Strategy Report
    • Integrate everything you've built into a single executive-facing AI Risk and Security Strategy Report. You'll produce a portfolio-ready report for a new GenAI initiative that combines a populated risk register, prioritization analysis, a FAIR-quantified exposure scenario, a STRIDE threat model with ADR-documented mitigations, and a roadmap alignment commentary, the kind of integrated deliverable a CB3 AI governance leader is expected to produce ahead of an executive go/no-go decision.

Taught by

Microsoft

Reviews

Start your review of Risk and Security Strategy

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.