Resources

Key frameworks, standards, and references for the workshop, pinned to the exact editions used in the course. Where links lead to living documents (ATLAS, OWASP), the referenced edition is noted. Verify currency at M5 content lock.

Four stacked horizontal layers, with bracket markers on the right spanning different subsets of the layers to show which reference covers which part of the stack.
How the frameworks stack and where each applies
Unofficial, CompTIA-alignedThis site is not affiliated with or endorsed by CompTIA, OWASP, NIST, MITRE, or the EU. All framework links point to the authoritative sources. Do not reproduce gated objectives verbatim.

Tokens: tokenizers & API costs

Tokens are the unit of both meaning and billing — these make that concrete.

RAG & local AI tools

Ways to run retrieval-augmented generation on your own machine — no API key, no data leaving the box.

Security frameworks & standards

The risk lists and control frameworks the labs and exam map to.

OWASP

OWASP Top 10 for LLM Applications 2025

The 2025 edition of the authoritative LLM security risk list — used throughout Days 2 and 3. Key 2025 additions: LLM07 System-Prompt Leakage and LLM08 Vector & Embedding Weaknesses. Published by the OWASP Gen AI Security Project.

Edition: 2025 — verify at M5 content lock.

OWASP

OWASP ML Security Top 10 v0.3 (2023 draft)

Machine-learning security risks covering training-data poisoning, model inversion, model theft, and adversarial examples. Draft standard (v0.3, 2023); cited in Days 2–3 defense discussions. Tracks threats to the ML pipeline itself, complementing the LLM Top 10.

Edition: v0.3 (2023 draft).

NIST

NIST AI RMF 1.0 + AI 600-1 GenAI Profile

The AI Risk Management Framework (AI RMF 1.0) and its companion NIST AI 600-1 GenAI Profile. Day 3 lab includes a hands-on AI RMF mapping worksheet (Govern, Map, Measure, Manage). AI 600-1 extends the framework with controls specific to generative AI (foundation models, RAG, agents).

AI RMF 1.0 (Jan 2023) · AI 600-1 (Jul 2024).

MITRE

MITRE ATLAS (live matrix)

Adversarial Threat Landscape for AI Systems — attack techniques and mitigations for ML/AI systems, structured like ATT&CK. Referenced live; the matrix is continuously updated by MITRE. Used in Day 2–3 threat modeling and Day 4 detection rule exercises.

Live — current edition as of access date.

Governance & regulation

What compliance obligations attach to an AI system, and when.

EU

EU AI Act — Primer

Key provisions: risk-tier classification (unacceptable / high / limited / minimal), transparency obligations, prohibited uses, and enforcement. Covered in the Day 3 governance module (D4 domain).

High-risk compliance deadline: 2 December 2027 — deferred by the Digital Omnibus package (provisional, pending formal adoption; re-verify at M5 content lock). General provisions applied from 2 August 2026.

Regulation (EU) 2024/1689. High-risk deadline: 2 Dec 2027 (Digital Omnibus — provisional).

Certification

The blueprint this workshop and the Friday exam are built against.

CompTIA

SecAI+ (CY0-001 V1) Objectives

CompTIA's official SecAI+ exam objectives — gated; linked only, not reproduced verbatim (copyright). Launched February 2026. Four domains: Basic AI Concepts (17%), Securing AI Systems (40%), AI-Assisted Security (24%), AI Governance/Risk/Compliance (19%).

Unofficial resource.This workshop is CompTIA-aligned training, not an official CompTIA product. The objectives PDF is gated at the link below.

CY0-001 V1, launched Feb 2026.

Additional Reading