137 episodes
- CompTIA SecAI+ (CY0-001) — Domain 4.3: The Impact of Compliance on AI Domain 4.0 (AI Governance, Risk, and Compliance) is 19% of the exam, and objective 4.3 is where governance meets the real world: the laws, standards, and internal policies that decide how your organization is allowed to build and use AI. In this session we break down the major frameworks in plain English and show you how CompTIA tests them — usually as "which framework/policy applies to this scenario?" questions rather than memorization. What's covered: EU AI Act — the first comprehensive AI law, its risk-based tiers, transparency/labeling rules, and why its reach extends beyond Europe OECD AI Principles — the values-based standards (human-centered, transparent, accountable) that shaped many national policies ISO AI standards — ISO/IEC 42001:2023, the "AI management system" standard (think ISO 27001 for AI) NIST AI Risk Management Framework (AI RMF) — the voluntary U.S. framework and its Govern / Map / Measure / Manage functions Corporate policies — sanctioned vs. unsanctioned AI (shadow AI), private vs. public models, and sensitive data governance Third-party compliance evaluations — validating vendors and external AI providers Data sovereignty — why where your data lives determines which laws apply Exam angle: know what each framework is for and who it applies to. Binding law (EU AI Act) vs. voluntary framework (NIST AI RMF) vs. certifiable standard (ISO 42001) is a distinction the exam loves to test.
- Domain 4 is 19% of the SecAI+ exam — and it's the part most security people skip because it "isn't technical." That's a mistake. Governance is the control above all the other controls. In this live session we break down:
4.1 — Governance structures: AI Center of Excellence, AI policies & procedures, and all 10 AI-related roles (data scientist, AI architect, ML engineer, platform engineer, MLOps engineer, AI security architect, AI governance engineer, AI risk analyst, AI auditor, data engineer)
4.2 — AI risks: the 10 Responsible AI principles, the 6 named risks (bias, data leakage, reputational loss, model accuracy, IP risk, autonomous systems), and Shadow IT → Shadow AI Differential privacy — and why it is NOT the same thing as encryption or anonymization
4.3 — Compliance: EU AI Act, NIST AI RMF, ISO/IEC 42001, OECD, data sovereignty #CompTIA #SecAIPlus #CY0001 #AISecurity #AIGovernance #Cybersecurity #CyberCertification - 3.2 Explain how AI enables or enhances attack vectors. ▪ AI-generated content (deepfake) • Impersonation • Misinformation • Disinformation ▪ Adversarial networks ▪ Reconnaissance ▪ Social engineering ▪ Obfuscation ▪ Automated data correlation ▪ Automated attack generation • Attack vector discovery • Payloads • Malware • Honeypot • Distributed denial of service (DDoS)
More Education podcasts
Trending Education podcasts
About ConvoCourses
Cyber Security Compliance and IT Jobs
Podcast websiteListen to ConvoCourses, IMO with Michelle Obama and Craig Robinson and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


ConvoCourses
Scan code,
download the app,
start listening.
download the app,
start listening.
ConvoCourses: Podcasts in Family

























