Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

ai-security-governance

AI Security — Governance, Risk & Secure AI Adoption Portfolio.

======================================================================================================================================

AI in Cyber Security — Governance Portfolio

Overview

This repository demonstrates AI in cyber security — how organizations use artificial intelligence to strengthen SOC operations, threat detection, and fraud prevention — alongside governance for securing AI systems (LLMs, copilots, third-party AI tools).

The portfolio covers both sides of the AI + security equation: using AI to defend the enterprise, and protecting AI from abuse, data leakage, and regulatory risk.

Areas Covered

  • AI in Cyber Security — SOC automation, UEBA, phishing ML, fraud detection, threat hunting
  • GenAI & LLM Security — Prompt injection, RAG security, jailbreak defense
  • AI for Fraud Detection — Payment fraud, ATO, mobile money abuse
  • AI for Phishing Detection — Email, BEC, smishing, AI-generated lures
  • AI for Threat Intelligence — IOC extraction, OSINT, MISP/STIX automation
  • AI for Malware Analysis — Sample triage, family classification, SOC integration
  • AI for Vulnerability Prioritization — EPSS, KEV, asset context, exploit prediction
  • Copilot Security — M365, GitHub, Copilot for Security governance
  • AI Security Governance Framework
  • AI Acceptable Use Policy Template
  • AI for SOC — Detection & Automation
  • AI Risk Assessment & Use-Case Classification
  • Prompt Injection & OWASP LLM Top 10 Threats
  • Secure AI Deployment & Acceptable Use
  • Third-Party AI Vendor Risk Assessment
  • AI Incident Response & Model Rollback
  • Regulatory Alignment (EU AI Act, NIST AI RMF)

Frameworks & Standards

  • NIST AI Risk Management Framework (AI RMF)
  • ISO/IEC 42001 — AI Management System
  • OWASP Top 10 for LLM Applications
  • EU AI Act — Risk Classification
  • MITRE ATLAS — Adversarial Threat Landscape for AI

Technologies & Tools

  • LLM platforms: Azure OpenAI, AWS Bedrock, on-premise models
  • Guardrails: NeMo Guardrails, Azure Content Safety
  • Monitoring: Model logging, prompt audit trails, anomaly detection
  • Testing: Red teaming for LLMs, jailbreak testing frameworks

Repository Structure

governance

AI in cyber security strategy, policy, and governance committee structure.

controls

AI for SOC detection, secure deployment checklist, and access control.

risk

AI risk assessment methodology and use-case classification matrix.

threats

OWASP LLM Top 10, prompt injection, data leakage, and model poisoning guides.

incident-response

AI-specific incident playbooks and model rollback procedures.

Related Repository

For AI/ML system security (MLOps, model pipelines, adversarial ML, drift detection), see: ai-ml-security-operations

Key Competencies

Domain Capabilities
Governance AI policy, risk appetite, executive reporting
Risk Use-case classification, DPIA integration, vendor assessment
Security Prompt injection defense, data leakage prevention, access control
Operations Model monitoring, audit logging, incident handling
Compliance EU AI Act readiness, NIST AI RMF alignment

Author

Gitsimbanyi Prosper

Senior Manager | Cyber Security | AI Security | Governance