AAISM Certification Training — The AI Layer on Top of Your CISSP
Domain 3 is 38% of the AAISM exam and it is the one part your CISSP never taught you. Fifty days, live-coached, domain-weighted 31/31/38, and the AI layer stops being the thing you nod along to.
Coached by Manoj Sharma — CISSP, CISM, CCSP, CRISC · ISC² #557313
Get Your Personalised AAISM Study Plan
Fill in your details and our team will map your route from CISSP or CISM into AAISM.
CISSP Batch 56 Starting 28 June 2026
You have run security programmes for years. Nobody taught you what a model is.
You already hold CISSP or CISM. You can read a governance question, reach the answer before you have finished the stem, and be right. Two decades of doing the work built that instinct, and AAISM will reward it.
Then the question turns. The final movement of an AAISM item often rests on something else entirely — whether you know what a model card records, which learning paradigm inherits the flaws sitting in its labels, or what an organisation is obliged to do the moment drift crosses its threshold. None of that is judgement. All of it is vocabulary nobody ever gave you a reason to sit down and learn.
“Candidates rarely fail AAISM on judgement. They fail on the AI-shaped layer they never made time to learn properly.”
A gap with a shape that clear is a solvable problem. This is AAISM certification training built on that single premise: teach the AI layer first, read governance and risk through it, then spend real time in the technology domain that decides more of your score than any other.
What is the ISACA AAISM certification?
The ISACA Advanced in AI Security Management™ (AAISM™) is a certification for experienced security managers who are accountable for how their organisation adopts, governs and secures artificial intelligence.
ISACA launched AAISM in August 2025, making it the first AI-centric credential aimed squarely at the security management chair rather than at engineers or auditors. It is built on top of CISM and CISSP rather than in place of either — ISACA assumes the holder already knows how to run a security programme, and tests what changes when the thing being governed learns from data instead of following written rules.
AAISM and AAIA are not the same credential and are routinely confused. AAISM is ISACA’s AI security management certification, for the person who owns the AI security posture. AAIA — Advanced in AI Audit — is ISACA’s AI audit certification, built for CISA holders providing independent assurance. Different chair, different job, different exam.
The credential exists now because the accountability question arrived before the answers did. The EU AI Act assigns duties to named providers and deployers. The NIST AI Risk Management Framework describes functions that somebody must own. ISO/IEC 42001 asks for a management system with defined responsibility. Boards, regulators, auditors and insurers have all started asking who is accountable for AI risk — and AAISM certifies the person who answers.
The accountability gap is real. AAISM certifies who closes it.
If you already hold CISSP or CISM, you are eligible today — the only decision left is when you start.
Why a two-day AAISM bootcamp cannot work
Domain 3 is 38% of the exam and, for this audience, largely new material. Two days of slides against material you have never seen is not preparation — it is exposure.
| What preparation needs | Self-study | 2-day bootcamp | Cybernous AAISM Toolkit |
|---|---|---|---|
| AI literacy foundation before governance | Day 0 primer | ||
| Live coaching | 2 days | Throughout | |
| 1:1 mentorship with the instructor | yes | ||
| Structured day-by-day plan | 50 days | ||
| Domain-weighted time allocation | DIY | Generic | 31 / 31 / 38 |
| Full-length mocks (90 Q / 150 min) | Limited | 1 | 5 |
| Domain revision days | Days 17, 28, 42 | ||
| Confusion Clinic — lookalike pairs | yes | ||
| Practical artifacts you keep | 8 |
Day 0 — the AI literacy primer nobody else gives you
Day 0 is one uncounted evening, before the programme formally begins, that installs the vocabulary the entire AAISM syllabus quietly assumes you already have. It contains no exam content. That is the point. Every other AAISM resource opens with governance and spends weeks teaching you to govern something nobody has defined for you. We refuse to teach governance about AI for three weeks before telling you what a model is.
Nine concepts, one evening, thirty minutes:
By the end of it you can say what a model actually is and why it cannot be reviewed the way a firewall rule can — the difference between a system that misclassifies and a system that fabricates, and why fine-tuning your own data into a foundation model creates a deletion problem no DPO enjoys hearing about. Then Domain 3 stops being a wall of foreign words and becomes engineering you can reason about — which is what makes the remaining 45 days work.
A 50-day AAISM study plan, honestly counted
Fifty days means 45 study days and 5 rest days, with Day 0 as an uncounted evening before the first of them. We publish the arithmetic rather than rounding it into a marketing number, because the plan only works if you can actually keep it. Reading runs 30 to 38 minutes on a study day; artifacts are separate — 10 to 15 minutes on your own organisation, done when you have time.
| Phase | Days | Focus | Domain |
|---|---|---|---|
| Primer | Day 0 | AI literacy foundation | — |
| Foundation | 1–17 | AI governance and programme management, revision Day 17 | D1 · 31% |
| Risk | 18–28 | AI threats, bias, model and supply chain risk, revision Day 28 | D2 · 31% |
| Technology | 29–42 | Types of AI, life cycle, TEVV, controls, revision Day 42 | D3 · 38% |
| Final Sprint | 43–50 | 5 mocks, Confusion Clinic, exam strategy | All |
Rest days fall on Days 7, 14, 21, 35 and 46. They are scheduled, not earned. A plan you abandon in week four because it never let you breathe is worse than a slower plan you finish, and the material consolidates while you are not thinking about it.
“Rest is not the reward you collect after the exam. It is part of how you pass it.”
50 days. 3 domains. 5 mocks. Nothing left to figure out on your own.
Get a personalised plan mapped to your CISSP or CISM date on a free strategy call.
The three AAISM domains — and where the exam actually sits
AI Governance and Program Management
- AI readiness and governance concepts
- Roles, responsibilities and the accountability model
- Standards and regulations — NIST AI RMF, ISO/IEC 42001, the EU AI Act
- Use cases, the business case and AI strategy
- Policies, procedures and acceptable use
- Programme components, continuity and AI incident response
AI Risk Management
- AI-specific threats and the adversarial landscape
- Prompt injection, data poisoning and evasion
- Bias by source — systemic, statistical, human — and each remedy
- Model risk, data risk and acceptable limits
- Third-party and AI supply chain risk
- Risk assessment, treatment and continuous monitoring
AI Technologies and Controls
- Types of AI, machine learning paradigms and neural networks
- Algorithms and the working vocabulary of AI
- Secure AI architecture and design
- The seven-phase AI life cycle, with TEVV as its assurance gate
- Data governance, data security, privacy and PETs
- Zero trust for AI, shadow AI, drift thresholds, HITL and AITL
Domains 1 and 2 are your home ground with an AI layer laid over the top — governance and risk, doing what governance and risk have always done, applied to an object that learns. Domain 3 is different in kind. It is the technology itself, it is 38% of the exam, and its questions are the most direct in the bank: definitional, categorical, placement-based. Most candidates give it the least time. That is the whole opportunity.
AAISM exam format, scoring and cost
| Number of questions | 90 |
| Duration | 150 minutes (2.5 hours) |
| Question type | Multiple choice, one best answer |
| Scoring scale | 200–800 |
| Passing score | 450 |
| Delivery | PSI test centre or remote proctored, year-round |
| Eligibility window | 6 months from registration |
| Exam fee | USD 459 ISACA member / USD 599 non-member |
| Application fee | USD 50 after passing |
| CPE to maintain | 10 hrs/year in AI; 30 hrs per 3-year cycle |
Exam fees are paid directly to ISACA and are entirely separate from Cybernous training fees. Figures above are per ISACA’s official exam content outline and are subject to change by ISACA.
Can you sit AAISM? The honest answer.
AAISM requires an active CISM or CISSP credential. There is no waiver, no experience substitution and no alternative qualifying certification.
You hold an active CISSP or CISM
You are eligible today. Nothing to check, nothing to wait for, no endorsement pending. The only decision left is when you sit, and the 50-day plan works backwards from that date.
Enrol NowYou are preparing for CISSP or CISM
You become eligible the day your credential goes active. The efficient move is to finish the prerequisite and stack AAISM straight after, while you are still in study rhythm. Finish with the CISSP Success Toolkit or the CISM Success Toolkit, then map both dates on one call.
Book a Strategy CallYou hold neither
Then AAISM is not your next certification. The eligibility path is CISSP or CISM first — typically 60 to 100 days with us — then AAISM immediately after. If you need AI security capability now rather than a credential later, GAESP is our GenAI security programme, open to everyone with no prerequisite.
Map My RouteEverything in the AAISM Success Toolkit
Nothing here is an add-on or an upgrade tier. Every enrolment includes all twelve from day one.
Day 0 AI Literacy Primer
Nine core AI concepts before the syllabus begins.
Live theory sessions
All three domains, taught live, recorded for replay.
Live exam practice sessions
Question dissection in the room, not homework.
The 50-day structured plan
Daily reading targets, honestly measured.
Smart notes for all three domains
The syllabus compressed and weighted against the question bank.
Eight practical artifacts
Readiness snapshot, AI charter, framework selection note, use-case gate, build-versus-buy worksheet, acceptable-use table, model card, TEVV gate checklist and monitoring threshold sheet.
AAISM-format question bank
Weighted 31/31/38, management-keyword answers.
Five full-length mocks
90 questions, 150 minutes, 450 to pass.
Domain revision days
Days 17, 28 and 42 — one per domain.
The Confusion Clinic
Every lookalike pair on this syllabus, separated and drilled.
1:1 mentorship with Coach Manoj
The coach himself, not a teaching assistant.
180-day LMS access
Plus the alumni community, which does not expire.
You finish with an AI governance programme, not a folder of notes
Every week of this programme carries one practical artifact, built on your own organisation. Ten to fifteen minutes each, done separately from the reading, using the day’s material while it is still warm. By Day 50 you are holding a readiness snapshot, a one-page AI charter, a framework selection note, a use-case gate, a build-versus-buy worksheet, a three-tier acceptable-use table, a model card, a TEVV gate checklist and a monitoring threshold sheet with named owners against every threshold.
Read that list again as your CISO would. It is not study output. It is the opening pages of a working AI governance programme, and the model card in particular is the document an auditor asks for first.
The credential proves you know it. The artifacts prove you did it.
Manoj Sharma
CISSP · CISM · CCSP · CRISC · ISC² #557313 · CISM-2050416
29+
Years Experience
793+
CISSP-Certified
400+
ISC² Endorsements
Twenty-nine years in cybersecurity, a practising CISO, and a military background before either. Author of The CISSP Codebreaker and of the AAISM 50-day method this programme runs on.
The numbers behind the method: 793+ CISSP-certified professionals, 2,000+ certified across the CISSP, CISM and CCSP programmes, and 400+ ISC² endorsements signed personally. He does not hand coaching to junior teaching assistants. He is the one on screen every week, and the one answering your 1:1.
One honest paragraph, because you would work it out anyway. AAISM is a new credential and we have no AAISM results to show you. What is not new is the method — the same live-coached, domain-weighted, practice-heavy structure that produced a 98.4% first-attempt pass rate across 793+ CISSP-certified professionals. The syllabus is new. The way it gets taught has fifteen years of evidence behind it.
AAISM, AAIA or GAESP — which one is yours?
AAISM
- For
- Security managers owning AI risk
- Prerequisite
- Active CISM or CISSP
- Issued by
- ISACA
- Choose it when
- You own the AI security posture
AAIA
- For
- Auditors giving independent assurance over AI
- Prerequisite
- CISA or equivalent audit credential
- Issued by
- ISACA
- Choose it when
- You audit it from an independent seat
GAESP
- For
- Any security professional needing AI capability now
- Prerequisite
- None
- Issued by
- Cybernous programme
- Choose it when
- You need the skills before the credential
Pick based on the chair you sit in, not on which sounds more advanced. If you are accountable for how your organisation deploys AI — the policies, the controls, the incident response — AAISM is yours. If you provide independent assurance over somebody else’s AI, AAIA is yours, and it is not a lesser credential; it is a different seat. AAISM and AAIA complement each other rather than compete — organisations that get AI governance right end up with both, held by different people, exactly as they do with CISM and CISA today.
2,000+ professionals certified using this coaching method
AAISM is a new credential and we have no AAISM outcomes to show yet. What we can show you is the method — these are CISSP and CISM students of the same coach, the same live coaching, the same structure.
Rajesh Kumar
Senior Security Analyst, TCS
“Cybernous training helped me clear CISSP in my first attempt. The hands-on labs and mentoring made all the difference.”
Priya Sharma
CISO, Tech Startup
“The corporate training program transformed our security team. Highly professional and results-driven.”
Ahmed Hassan
Cybersecurity Consultant
“Best investment in my career. The practical approach and exam strategies were invaluable.”
Local context, local currency, your timezone
Gulf
UAE AI Charter · NESA · SDAIA AI Ethics Principles
APAC
Singapore Model AI Governance and AI Verify · MAS FEAT · India DPDP Act
Americas
NIST AI RMF · Colorado AI Act · Canada AIDA
Europe
EU AI Act · GDPR Article 22 · NIS2
Still Confused? Request a Callback
Contact us today to map your route into AAISM under the expert guidance of Manoj Sharma.
AAISM certification — frequently asked questions
Questions answered. Your 50-day countdown can start today.
Still have doubts? Reach out — we're happy to help before you enrol.
Start Your 50-Day AAISM Certification Training
Fifty days, three domains, five mocks, and the AI layer taught first instead of assumed — with Coach Manoj on screen every week.
Written by Manoj Sharma, Founder of Cybernous — CISSP, CISM, CCSP, CRISC · ISC² Member #557313
Exam format, scoring and fee details are per ISACA’s published AAISM exam content outline and are subject to change by ISACA.
AAISM™ and AAIA™ are trademarks of ISACA. Cybernous Infosec Consulting LLP is an independent training provider and is not affiliated with, accredited by, or endorsed by ISACA.