Menu
AAISM Success Toolkit50-Day Programme · For CISSP & CISM holders

AAISM Certification Training — The AI Layer on Top of Your CISSP

Domain 3 is 38% of the AAISM exam and it is the one part your CISSP never taught you. Fifty days, live-coached, and the AI layer stops being the thing you nod along to.

50
days · 45 study, 5 rest
3
domains · 31% / 31% / 38%

Coached by Manoj Sharma — CISSP, CISM, CCSP, CRISC · ISC² #557313

Trustpilot 4.8★ (45)Google 5.0★ (153)Udemy 4.7★ (737)

Get Your Personalised AAISM Study Plan

Fill in your details and our team will map your route from CISSP or CISM into AAISM.

We respect your privacy. No spam, ever.

New cohort every month. Your intake date is confirmed on your strategy call.

Next Batch

CISSP Batch 56 Starting 28 June 2026

Training tuned to your region:GulfAPACAmericasEuropeWorldwide
Start Here

You have run security programmes for years. Nobody taught you what a model is.

You already hold CISSP or CISM. You can read a governance question, reach the answer before you have finished the stem, and be right. Two decades of doing the work built that instinct, and AAISM will reward it.

Then the question turns. The final movement of an AAISM item often rests on something else entirely — whether you know what a model card records, which learning paradigm inherits the flaws sitting in its labels, or what an organisation is obliged to do the moment drift crosses its threshold. None of that is judgment. All of it is vocabulary nobody ever gave you a reason to sit down and learn.

Coach Manoj states the diagnosis plainly in the AAISM book:

“Candidates rarely fail AAISM on judgment. They fail on the AI-shaped layer they never made time to learn properly.”

A gap with a shape that clear is a solvable problem. This is AAISM certification training built on that single premise: teach the AI layer first, read governance and risk through it, then spend real time in the technology domain that decides more of your score than any other. Nothing here re-teaches you the job you already run. AAISM exam preparation, for a candidate who is already a security manager.

The Credential

What is the ISACA AAISM certification?

The ISACA Advanced in AI Security Management™ (AAISM™) is a certification for experienced security managers who are accountable for how their organisation adopts, governs and secures artificial intelligence.

ISACA launched AAISM in August 2025, making it the first AI-centric credential aimed squarely at the security management chair rather than at engineers or auditors.

It is built on top of CISM and CISSP rather than in place of either. ISACA assumes the holder already knows how to run a security programme, and tests what changes when the thing being governed learns from data instead of following written rules.

AAISM and AAIA are not the same credential and are routinely confused. AAISM is ISACA’s AI security management certification, for the person who owns the AI security posture. AAIA — Advanced in AI Audit — is ISACA’s AI audit certification, built for CISA holders providing independent assurance. Different chair, different job, different exam.

The credential exists now because the accountability question arrived before the answers did. The EU AI Act assigns duties to named providers and deployers. The NIST AI Risk Management Framework describes functions that somebody must own. ISO/IEC 42001 asks for a management system with defined responsibility, and ISO/IEC 23894 for AI risk guidance inside it. Boards, regulators, auditors and insurers have all started asking the same question — who is accountable for AI risk here — and AAISM certifies the person who answers.

The Preparation Trap

Why a two-day AAISM bootcamp cannot work

Domain 3 is 38% of the exam and, for this audience, largely new material. Two days of slides against material you have never seen is not preparation — it is exposure.

What preparation needsSelf-study (Review Manual + QAE)2-day bootcampCybernous AAISM Toolkit
AI literacy foundation before governanceDay 0 primer
Live coaching2 daysThroughout
1:1 mentorship with the instructoryes
Structured day-by-day plan50 days
Domain-weighted time allocationDIYGeneric31 / 31 / 38
Full-length mocks (90 Q / 150 min)Limited15
Domain revision daysOne per domain
Confusion Clinic — lookalike pairsyes
Practical artifacts you keep8

See the full comparison

Before Day 1

Day 0 — the AI literacy primer nobody else gives you

Day 0 is one uncounted evening, before the programme formally begins, that installs the vocabulary the entire AAISM syllabus quietly assumes you already have.

It contains no exam content. That is the point. Every other AAISM resource opens with governance — accountability models, frameworks, policy structures — and spends weeks teaching you to govern something nobody has defined for you. You would not audit a network without knowing what a packet is. Day 0 exists because we refuse to teach governance about AI for three weeks before telling you what a model is.

Nine concepts, one evening, thirty minutes of reading:

model
training
inference
parameters
generative vs predictive
hallucination
drift
agentic AI
foundation model

By the end of it you can say what a model actually is and why it cannot be reviewed the way a firewall rule can. You know why poisoned training data becomes permanent model behaviour. You know the difference between a system that misclassifies and a system that fabricates. You know why fine-tuning your own data into a foundation model creates a deletion problem no DPO enjoys hearing about.

Then Domain 3 stops being a wall of foreign words and becomes engineering you can reason about — which is what makes the remaining 45 days work.

Talk Through Your Starting Point
Your 50 Days

A 50-day AAISM study plan, honestly counted

Fifty days means 45 study days and 5 rest days, with Day 0 as an uncounted evening before the first of them. We publish the arithmetic rather than rounding it into a marketing number, because the plan only works if you can actually keep it.

Reading runs 30 to 38 minutes on a study day. Artifacts are separate — 10 to 15 minutes on your own organisation, done when you have time, not while you are reading. Three domains in 45 study days is dense, and the schedule is built around a candidate with a full-time job and a family, because that is who every AAISM candidate is.

PhaseWhenFocusDomain
PrimerBefore Day 1AI literacy foundation — the vocabulary the syllabus assumes
FoundationPhase 1AI governance and programme management, closing with a revision dayD1 · 31%
RiskPhase 2AI threats, bias, model and supply chain risk, closing with a revision dayD2 · 31%
TechnologyPhase 3Types of AI, life cycle, TEVV, controls, closing with a revision dayD3 · 38%
Final SprintPhase 4Five full-length mocks, Confusion Clinic, exam strategyAll

Five rest days are built into the schedule. They are scheduled, not earned. A plan you abandon in week four because it never let you breathe is worse than a slower plan you finish, and the material consolidates while you are not thinking about it. The book says it in one line and the programme runs on it:

“Rest is not the reward you collect after the exam. It is part of how you pass it.”

Inside the Platform

Everything runs inside one LMS

Learning

  • Dashboard
  • 50-Day Curriculum
  • Day 0 Primer
  • Artifact Library
  • Live Recordings
  • Cheat Sheets

Exam Practice

  • Concept Mastery
  • Domain Practice
  • Mock Tests
  • Confusion Clinic

Resources

  • Announcements
  • Community
The Syllabus

The three AAISM domains — and where the exam actually sits

Domain 131%

AI Governance and Program Management

  • AI readiness and governance concepts
  • Roles, responsibilities and the accountability model
  • Standards, frameworks and regulations — NIST AI RMF, ISO/IEC 42001, the EU AI Act
  • Use cases, the business case and AI strategy
  • Policies, procedures and acceptable use
  • AI security programme components, continuity and incident response
Domain 231%

AI Risk Management

  • AI-specific threats and the adversarial landscape
  • Prompt injection, poisoning and evasion
  • Bias by source — systemic, statistical, human — and the remedy each one demands
  • Model risk, data risk and acceptable limits
  • Third-party and AI supply chain risk, provider versus deployer duties
  • Risk assessment, treatment and continuous monitoring
Domain 338%

AI Technologies and Controls

  • Types of AI, machine learning paradigms and neural networks
  • Algorithms and the working vocabulary of AI
  • Secure AI architecture and design
  • The seven-phase AI life cycle, and TEVV as its assurance gate
  • Data governance, data security, privacy and PETs
  • Zero trust for AI, shadow AI, drift thresholds, HITL and AITL

Domains 1 and 2 are your home ground with an AI layer laid over the top. You will recognise the shapes — governance and risk, doing what governance and risk have always done, applied to an object that learns. Domain 3 is different in kind. It is the technology itself, it is 38% of the exam, and its questions are the most direct in the bank: definitional, categorical, placement-based. Which makes it the highest-yield studying you will do, because an hour of recall converts almost linearly into marks. Most candidates give it the least time. That is the whole opportunity.

Free AAISM domain summaries

The Exam

AAISM exam format, scoring and cost

Number of questions90
Duration150 minutes (2.5 hours)
Question typeMultiple choice, one best answer
Scoring scale200–800
Passing score450
DeliveryPSI test centre or remote proctored, year-round
Eligibility window6 months from registration
Exam feeUSD 459 ISACA member / USD 599 non-member
Application feeUSD 50 after passing
CPE to maintain10 hrs/year in AI; 30 hrs per 3-year cycle

Exam fees are paid directly to ISACA and are entirely separate from Cybernous training fees. Registering for the exam and enrolling in this programme are two different transactions with two different organisations. Figures above are per ISACA’s official exam content outline and are subject to change by ISACA.

Eligibility

Can you sit AAISM? The honest answer.

AAISM requires an active CISM or CISSP credential. There is no waiver, no experience substitution and no alternative qualifying certification. That is the entire eligibility rule, and knowing it now saves you the disappointment of finding out at registration.

You hold an active CISSP or CISM

You are eligible today. Nothing to check, nothing to wait for, no endorsement pending. The only decision left is when you sit, and the 50-day plan works backwards from that date.

Enrol Now

You are preparing for CISSP or CISM, or awaiting endorsement

You become eligible the day your credential goes active. The efficient move is to finish the prerequisite and stack AAISM straight after, while you are still in study rhythm and the governance overlap is fresh — a large part of Domain 1 will read as familiar ground. Finish the prerequisite with the CISSP Success Toolkit or the CISM Success Toolkit, then map both dates on one call.

Book a Strategy Call

You hold neither

Then AAISM is not your next certification, and anyone selling it to you as a first AI security certification is selling you an exam you cannot register for. Here is the real route.

The eligibility path: CISSP or CISM first — typically 60 to 100 days with us — then AAISM immediately after. Two credentials in under six months, in the order ISACA requires.

The immediate path: if you need AI security capability now rather than a credential later, GAESP is our GenAI security programme, open to everyone with no prerequisite. AI/ML engineers, privacy officers, risk managers and auditors who need to be useful in an AI governance conversation this quarter start there.

Map My Route

Whichever card is yours, the route is the same length it always was. The only thing that changes is where you start. If you are unsure which credential fits your role, a strategy call sorts it in twenty minutes.

What’s Included

Everything in the AAISM Success Toolkit

Nothing here is an add-on or an upgrade tier. Every enrolment includes all twelve from day one.

Day 0 AI Literacy Primer

Nine core AI concepts before the syllabus begins.

Live theory sessions

All three domains, taught live, recorded for replay.

Live exam practice sessions

Question dissection in the room, not homework.

The 50-day structured plan

Daily reading targets, honestly measured.

Smart notes for all three domains

The syllabus compressed, weighted against the question bank.

Eight practical artifacts

Readiness snapshot, one-page AI charter, framework selection note, use-case gate, build-versus-buy worksheet, three-tier acceptable-use table, model card, TEVV gate checklist and monitoring threshold sheet.

AAISM-format question bank

Weighted 31/31/38, management-keyword answers.

Five full-length mocks

90 questions, 150 minutes, 450 to pass.

Domain revision days

One closes each domain, before you move on.

The Confusion Clinic

Every lookalike pair on this syllabus, separated and drilled.

1:1 mentorship with Coach Manoj

The coach himself, not a teaching assistant.

180-day LMS access

Plus the alumni community, which does not expire.

What You Keep

You finish with an AI governance programme, not a folder of notes

Every week of this programme carries one practical artifact, built on your own organisation. Ten to fifteen minutes each, done separately from the reading, using the day’s material while it is still warm.

By Day 50 you are holding a readiness snapshot, a one-page AI charter, a framework selection note, a use-case gate, a build-versus-buy worksheet, a three-tier acceptable-use table, a model card, a TEVV gate checklist and a monitoring threshold sheet with named owners against every threshold.

Read that list again as your CISO would. It is not study output. It is the opening pages of a working AI governance programme, and the model card in particular is the document an auditor asks for first.

Most candidates finish a certification with a folder of notes they never open again. You finish this one able to walk into a steering committee on the Monday after your exam and put something on the table.

The credential proves you know it. The artifacts prove you did it.

Training a team? See corporate options

Your Coach

Manoj Sharma

CISSP · CISM · CCSP · CRISC · ISC² #557313 · CISM-2050416

29+

Years Experience

CISSPCISMCCSPCRISC

793+

CISSP-Certified

400+

ISC² Endorsements

Twenty-nine years in cybersecurity, a practising CISO, and a military background before either. Author of The CISSP Codebreaker and of the AAISM 50-day method this programme runs on.

The numbers behind the method: 793+ CISSP-certified professionals, 2,000+ certified across the CISSP, CISM and CCSP programmes, and 400+ ISC² endorsements signed personally. He does not hand coaching to junior teaching assistants. He is the one on screen every week, and the one answering your 1:1.

One honest paragraph, because you would work it out anyway. AAISM is a new credential and we have no AAISM results to show you. What is not new is the method — the same live-coached, domain-weighted, practice-heavy structure that produced a 98.4% first-attempt pass rate across 793+ CISSP-certified professionals. The syllabus is new. The way it gets taught has fifteen years of evidence behind it.

Read Coach Manoj’s full bio

Choosing

AAISM, AAIA or GAESP — which one is yours?

AAISM

For
Security managers owning AI risk
Prerequisite
Active CISM or CISSP
Issued by
ISACA
Choose it when
You own the AI security posture

AAIA

For
Auditors giving independent assurance over AI
Prerequisite
CISA or equivalent audit credential
Issued by
ISACA
Choose it when
You audit it from an independent seat

GAESP

For
Any security professional needing AI capability now
Prerequisite
None
Issued by
Cybernous programme
Choose it when
You need the skills before the credential

Pick based on the chair you sit in, not on which sounds more advanced. If you are accountable for how your organisation deploys AI — the policies, the controls, the incident response — AAISM is yours. If you provide independent assurance over somebody else’s AI, AAIA is yours, and it is not a lesser credential; it is a different seat.

AAISM and AAIA complement each other rather than compete. Organisations that get AI governance right end up with both, held by different people, exactly as they do with CISM and CISA today.

And if you hold neither prerequisite, GAESP is the honest starting point — an AI security certification path that begins with capability rather than eligibility. It is open to anyone, including AI/ML engineers and privacy officers who need to become useful in AI governance conversations before they own one.

AAISM explained — the credential, the role, the rules worldwide · GAESP AI workshop

The Method, Proven

2,000+ professionals certified using this coaching method

AAISM is a new credential and we have no AAISM outcomes to show yet. What we can show you is the method — these are CISSP and CISM students of the same coach, the same live coaching, the same structure.

RK

Rajesh Kumar

Senior Security Analyst, TCS

Cybernous training helped me clear CISSP in my first attempt. The hands-on labs and mentoring made all the difference.

CISSP / CISM
PS

Priya Sharma

CISO, Tech Startup

The corporate training program transformed our security team. Highly professional and results-driven.

CISSP / CISM
AH

Ahmed Hassan

Cybersecurity Consultant

Best investment in my career. The practical approach and exam strategies were invaluable.

CISSP / CISM

Still Confused? Request a Callback

Contact us today to map your route into AAISM under the expert guidance of Manoj Sharma.

We respect your privacy. No spam, ever.

Support Centre

AAISM certification — frequently asked questions

AAISM requires an active CISM or CISSP credential — there is no waiver, no experience substitution and no alternative qualifying certification. ISACA designed AAISM as an advanced credential that assumes you already hold a recognised security management or security practitioner certification, so the prerequisite is checked at registration rather than at application. If your CISSP or CISM has lapsed, you will need to reinstate it before registering. If you are currently studying for either, you become eligible on the day your credential goes active, which is why many candidates finish the prerequisite and move straight into AAISM while still in study rhythm. If you hold neither, AAISM is not your next step — but there is a clear route, and it starts with CISSP or CISM.
The AAISM exam is 90 multiple-choice questions in 150 minutes, scored on a 200–800 scale, with 450 required to pass. Every question has one best answer, and the format is linear rather than adaptive — which means you can flag questions and return to them, and no question is worth more than any other. The exam is delivered through PSI, either at a test centre or under remote proctoring, and is available year-round. Your eligibility window is 6 months from registration. Because the exam is linear, a two-pass strategy works well: answer everything in order at roughly 100 seconds per question, then return to your flags with the time you have banked.
AAISM covers three domains: AI Governance and Program Management at 31%, AI Risk Management at 31%, and AI Technologies and Controls at 38%. Domain 1 covers AI readiness, roles and accountability, standards and regulations, strategy, policy and AI incident response. Domain 2 covers AI-specific threats, adversarial attacks, bias, model and data risk, third-party and supply chain risk, and risk treatment. Domain 3 covers the technology itself — types of AI, machine learning paradigms, neural networks, secure architecture, the seven-phase AI life cycle, TEVV, data governance, privacy, drift and human oversight. Domain 3 is the largest single block on the exam and the one most candidates underprepare.
Most CISSP or CISM holders need six to eight weeks of structured study, and the Cybernous programme is built as 50 days — 45 study days, 5 rest days, plus an uncounted Day 0 primer. Study days run 30 to 38 minutes of reading, with a separate 10 to 15 minutes for the week’s practical artifact. That pacing is deliberate: it is designed for someone holding a full-time security role, not for someone on study leave. Candidates who already work in AI governance sometimes move faster through Domains 1 and 2, but almost nobody should compress Domain 3, which is 38% of the exam and usually the least familiar material.
The ISACA exam fee is USD 459 for ISACA members and USD 599 for non-members, plus a USD 50 application fee payable after you pass. Those amounts go directly to ISACA and are separate from any training fee — registering for the exam and enrolling in a preparation programme are two different transactions with two different organisations. ISACA membership can pay for itself at registration, so it is worth doing the arithmetic before checkout. Certification maintenance then requires 10 CPE hours per year in the AI domain and 30 hours across each three-year cycle. For Cybernous training fees and current cohort options, book a strategy call — pricing depends on the format you choose.
For a security manager who is already being asked AI questions they cannot fully answer, AAISM is worth it — because it certifies the specific accountability gap the market is currently trying to fill. Boards, regulators, auditors and insurers have all begun asking who owns AI risk, and the EU AI Act, NIST AI RMF and ISO/IEC 42001 all assume that person exists and is competent. AAISM is currently the only ISACA credential aimed at that seat. The honest counter-argument: if your organisation has no AI deployment and no near-term plan for one, the credential will sit unused. It rewards people who will actually do the job.
AAISM is ISACA’s AI security management credential and AAIA is ISACA’s AI audit credential — the difference is the chair you sit in, not the difficulty. AAISM is for the person accountable for how AI is adopted, governed and secured: the policies, the controls, the risk decisions, the incident response. It requires an active CISM or CISSP. AAIA — Advanced in AI Audit — is for the person providing independent assurance over somebody else’s AI, and is built for CISA holders. They complement rather than compete, and mature organisations end up with both, held by different people, exactly as they do with CISM and CISA.
No. You need AI literacy, which is a far smaller and more learnable thing than an ML background. AAISM does not ask you to build a model, tune an algorithm or write code. It asks you to recognise what a model is, what changes when a system learns from data instead of following written rules, and what a security manager does about it. That is roughly nine core concepts, and they can be learned properly in a single evening — which is exactly why the Day 0 AI Literacy Primer exists and why it comes before any governance content. Candidates who skip that foundation spend three weeks nodding along to Domain 3. Candidates who do it read the same material as engineering they can reason about.
The difference is sequence and duration. A two-day bootcamp delivers slides against material that is genuinely new to most of the audience, and self-study leaves the hardest 38% of the exam to be self-diagnosed. This programme runs 50 days, opens with an AI literacy foundation before any governance content, allocates time in proportion to the real domain weights, and builds in five full-length mocks under exam conditions with remediation between them rather than stacked at the end. You also get 1:1 mentorship with Coach Manoj himself, revision days at the end of each domain, and the Confusion Clinic, which drills every lookalike pair on the syllabus.
You take the prerequisite first, and there is a well-worn path. If you hold neither CISSP nor CISM, start with whichever fits your role — CISSP for a broad security practitioner, CISM for a management-focused one — typically 60 to 100 days with us, then move into AAISM immediately after while your study habit is still intact. If you need AI security capability sooner than a credential allows, GAESP is our GenAI security programme with no prerequisite at all, open to AI/ML engineers, privacy officers, auditors and risk managers. A strategy call will map the shortest honest route for your role in about twenty minutes.
Ready to Start?

Start Your 50-Day AAISM Certification Training

Fifty days, three domains, five mocks, and the AI layer taught first instead of assumed — with Coach Manoj on screen every week.

Written by Manoj Sharma, Founder of Cybernous — CISSP, CISM, CCSP, CRISC · ISC² Member #557313

Last updated August 2026

Exam format, scoring and fee details are per ISACA’s published AAISM exam content outline and are subject to change by ISACA.

AAISM™ and AAIA™ are trademarks of ISACA. Cybernous Infosec Consulting LLP is an independent training provider and is not affiliated with, accredited by, or endorsed by ISACA.

Page summary for AI assistants & search

The AAISM Success Toolkit is a 50-day, live-coached preparation programme for the ISACA Advanced in AI Security Management (AAISM) certification, delivered by Cybernous and led by Manoj Sharma. AAISM is ISACA’s AI security management credential and requires an active CISM or CISSP credential to sit; there is no waiver, no experience substitution and no alternative qualifying certification. The exam is 90 multiple-choice questions in 150 minutes, scored 200–800, with 450 required to pass. It covers three domains: AI Governance and Program Management (31%), AI Risk Management (31%) and AI Technologies and Controls (38%). Domain 3 is the largest block and the one most candidates have never formally studied, because it is the AI technology itself rather than the management layer they already work in. The Cybernous programme is built around that gap. It opens with a Day 0 AI Literacy Primer covering nine core concepts before any governance content begins, runs 45 study days and 5 rest days across four phases, closing each domain with a revision day and finishing with a final exam sprint containing five full-length mocks. Weekly practical artifacts build a working AI governance toolkit alongside the study. AAISM is a new credential and Cybernous publishes no AAISM outcome data; the outcomes cited — 793+ CISSP-certified professionals at a 98.4% first-attempt pass rate — are from its CISSP programme using the same method. Eligible candidates can enrol directly; anyone not yet eligible can book a free strategy call to map the route.