Microsoft

Risk and Security Strategy

Microsoft

Risk and Security Strategy

 Microsoft

Instructor: Microsoft

Included with Coursera PlusLearn more

Ask Coursera

Gain insight into a topic and learn the fundamentals.
Intermediate level

Recommended experience

1 week to complete
at 10 hours a week
Flexible schedule
Learn at your own pace
Gain insight into a topic and learn the fundamentals.
Intermediate level

Recommended experience

1 week to complete
at 10 hours a week
Flexible schedule
Learn at your own pace

What you'll learn

  • Apply the NIST AI RMF to classify and populate a risk register with data, model, and usage risks.

  • Analyze likelihood-impact scores to prioritize risks and evaluate residual risk after control deployment.

  • Apply FAIR methodology to quantify monetary exposure and analyze cyber-insurance gaps.

  • Apply STRIDE threat modeling to AI inference endpoints and evaluate alignment of the AI security roadmap.

Details to know

Shareable certificate

Add to your LinkedIn profile

Assessments

25 assignments¹

AI Graded see disclaimer
Taught in English

See how employees at top companies are mastering in-demand skills

 logos of Petrobras, TATA, Danone, Capgemini, P&G and L'Oreal

Build your Security expertise

This course is part of the Microsoft Enterprise AI Governance, Ethics & Security Professional Certificate
When you enroll in this course, you'll also be enrolled in this Professional Certificate.
  • Learn new concepts from industry experts
  • Gain a foundational understanding of a subject or tool
  • Develop job-relevant skills with hands-on projects
  • Earn a shareable career certificate from Microsoft

There are 12 modules in this course

This module introduces the NIST AI RMF (National Institute of Standards and Technology Artificial Intelligence Risk Management Framework) and its four functions, a practical working taxonomy (data, model, usage) for fast risk triage, and the crosswalk that maps each working category to its authoritative NIST AI 600-1 category. Learners build the conceptual foundation needed to recognize and classify AI risks before populating a register in the next module.

What's included

3 videos1 reading1 assignment

This module moves from classification to artifact production. Learners populate an AI risk register for a voice-bot project, assigning categories, owners, and initial scores, and recording the NIST AI 600-1 mapping for each entry, producing a governance artifact (referred to in this course as a portfolio-ready artifact—this is course terminology, not an official NIST designation) aligned to the NIST AI RMF.

What's included

2 videos1 reading3 assignments

This module turns a populated risk register into a sequenced treatment plan. Learners analyze Likelihood–Impact scores, factor in qualitative considerations beyond raw scores, and identify the top five AI risks that warrant mitigation workshops. The "top five" is the output of this analysis, not a predefined list.

What's included

3 videos1 reading2 assignments

This module addresses the "what now" question after mitigation. Learners rescore risks post-control, evaluate residual exposure against organizational tolerance, and draft a recommendation memo defending acceptance for low-residual items and further treatment for the rest.

What's included

1 video1 reading3 assignments

This module gives learners a working command of FAIR methodology—the variables, the math, and the calculator workflow—to estimate annualized loss expectancy for an AI data-leak scenario and add the figure to the risk register.

What's included

3 videos1 reading2 assignments

This module turns cyber-insurance policy wording into a control checklist that AI governance leaders can defend. Learners compare a sample cyber-insurance policy against current AI controls, identify the unmet requirements that could trigger exclusions or void coverage, and produce a gap briefing for the security manager.

What's included

2 videos2 readings3 assignments

This module builds the conceptual foundation for AI endpoint threat modeling. Learners map the six STRIDE threat categories to AI inference endpoint attack surfaces—from prompt injection at the API edge to model extraction at the inference layer—building the analytical command they'll need to produce mitigations and an ADR (an Architecture Decision Record, a structured document that captures a significant architectural decision).

What's included

3 videos1 reading1 assignment

This module turns identified threats into engineered mitigations and a defensible Architecture Decision Record. Learners pair threats with mitigation choices, weigh trade-offs (cost, performance, completeness), and produce a complete ADR (An Architecture Decision Record is a structured document that captures a significant architectural decision) ready for upload to an architecture repository.

What's included

2 videos1 reading3 assignments

This module builds the analytical foundation for roadmap-to-strategy alignment work. Learners study corporate security strategy structure and AI security roadmap structure, then use a provided alignment matrix to map each AI security initiative to one or more strategy pillars, surfacing both misaligned initiatives and coverage gaps.

What's included

3 videos1 reading2 assignments

This module moves from alignment analysis to executive-facing recommendation. Learners study course correction options for misaligned initiatives and coverage gaps, then present and defend a recommendation to a CISO-level audience in a Coach Role Play, practicing the upward communication skill that determines whether course corrections actually happen.

What's included

3 videos1 reading2 assignments

Lead on GenAI use in AI governance work rather than being surprised by it. This module gives CB3 governance professionals a working command of how generative AI tools accelerate risk register population, STRIDE threat enumeration, and alignment analysis, and the verification patterns that protect against hallucinations, confidentiality leakage, and audit trail gaps. You'll produce a portfolio-ready GenAI-assisted analysis with an annotated evaluation that demonstrates the human-in-the-loop oversight that makes GenAI use defensible at the governance level. Cross-platform applicability: This module teaches GenAI governance using Microsoft's enterprise AI stack (Azure OpenAI, Microsoft Purview, Azure AI Content Safety) because that is the credential's anchor ecosystem and where the enterprise data protection conversation lands most clearly for CB3 learners. Learners working in non-Microsoft environments can map the same concepts to equivalent enterprise stacks—AWS Bedrock + Macie + Guardrails, GCP Vertex AI + Sensitive Data Protection + Model Armor, or comparable—without losing the underlying skill. The Microsoft anchor is the canonical example; the governance pattern transfers.

What's included

2 videos2 readings2 assignments

Integrate everything you've built into a single executive-facing AI Risk and Security Strategy Report. You'll produce a portfolio-ready report for a new GenAI initiative that combines a populated risk register, prioritization analysis, a FAIR-quantified exposure scenario, a STRIDE threat model with ADR-documented mitigations, and a roadmap alignment commentary, the kind of integrated deliverable a CB3 AI governance leader is expected to produce ahead of an executive go/no-go decision.

What's included

1 video2 readings1 assignment

Earn a career certificate

Add this credential to your LinkedIn profile, resume, or CV. Share it on social media and in your performance review.

Instructor

 Microsoft
408 Courses2,743,738 learners

Offered by

Microsoft

Why people choose Coursera for their career

Felipe M.

Learner since 2018
"To be able to take courses at my own pace and rhythm has been an amazing experience. I can learn whenever it fits my schedule and mood."

Jennifer J.

Learner since 2020
"I directly applied the concepts and skills I learned from my courses to an exciting new project at work."

Larry W.

Learner since 2021
"When I need courses on topics that my university doesn't offer, Coursera is one of the best places to go."

Chaitanya A.

"Learning isn't just about being better at your job: it's so much more than that. Coursera allows me to learn without limits."

Frequently asked questions

¹ Some assignments in this course are AI-graded. For these assignments, your data will be used in accordance with Coursera's Privacy Notice.