AAISM study plan: pass in 6 weeks

Updated September 20, 2026

Six weeks at 6–8 hours a week. This plan assumes you hold CISM or CISSP — you must, to certify — and therefore that security management methodology is already yours. What you are learning is how it changes when the asset is a model.

The plan is deliberately weighted toward the technologies domain. It is 38% of the exam, the largest of the three, and the one experienced managers consistently underprepare.

Week 1: AI governance and programme management (31%), part one

  • Stakeholder considerations: who has a say in AI adoption, and what each of them needs from you.
  • Industry frameworks and regulatory requirements for AI, and what they consistently ask for — inventories, impact assessments, human oversight, documentation.
  • AI-related strategies, policies and procedures: what an AI acceptable-use policy or model approval policy actually contains.

Week 2: governance, part two

  • AI asset and data lifecycle management. Treat training data and models as assets: identification, classification, provenance, retention, disposal.
  • AI security programme development and management — building the programme, not just the policy.
  • Business continuity and incident response for AI systems: what an AI incident looks like, who is notified, what rollback means when behaviour comes from data.

Week 3: AI risk management (31%)

  • Risk assessment, thresholds and treatment for AI. The methodology is yours already; the sources of risk are new.
  • Threat and vulnerability management for AI: poisoning, extraction, inversion, evasion, prompt injection, and the lifecycle stage each one targets.
  • Vendor and supply chain management: pretrained models, third-party datasets, model APIs, and what due diligence on a model provider should cover.

Weeks 4 and 5: AI technologies and controls (38%)

Two weeks, because it is the largest domain and the least familiar.

Week 4 — architecture and lifecycle:

  • AI security architecture and design: where controls sit around a model, isolation, trust boundaries.
  • The AI lifecycle: model selection, training, validation — and the security decision at each step.
  • Data management controls: provenance, integrity, minimisation, segregation.

Week 5 — protection and assurance:

  • Privacy controls for AI, including what model outputs can leak.
  • Ethical, trust and safety controls, expressed as things you implement and evidence.
  • Security controls and monitoring: what to log for an AI system, and what normal looks like so you can see abnormal.

Week 6: practice and repair

  • Take a full practice exam under real conditions.
  • Sort every mistake by domain and, more usefully, by question type — a BEST question you got wrong is a different problem from a knowledge gap.
  • Rebuild the weakest domain, then sit a second practice exam.

Where the hours go

WeekFocusDomain weightHours
1–2Governance and programme management31%12–16
3Risk management31%6–8
4–5Technologies and controls38%12–16
6Practice and repair6–8

Practising the question style

If you hold CISM you already know this, but it bears repeating: ISACA questions are decided by the qualifier. BEST, FIRST, MOST — usually capitalised, always load-bearing. Several options will be reasonable actions; one is the right one for the priority stated.

Two habits that convert knowledge into marks:

  • Identify the role you are playing. ISACA questions are almost always asked from the perspective of the accountable manager, not the engineer. The answer is usually a decision, an assessment or an escalation rather than a configuration.
  • Read for what has already happened. “FIRST” questions often hinge on a step the scenario has skipped. If no risk assessment has been done, the first action is rarely to implement a control.

If time runs short, cut week 1, not week 5. Governance content you can reason toward from CISM; the technologies domain you cannot.