Absolutely! For CISSP holders, making a transition into AI governance is not only a viable option but a necessary one for all security professionals to stay current with AI technology and the AI threat landscape.
AI is becoming increasingly integrated into business processes and since CISSP professionals can effectively design, implement and manage an Information Security Management System (ISMS) cybersecurity program, they can leverage their training in building and supporting an AI governance program, focusing on ethical, fair, transparent and secure AI implementation practices.
CISSPs have foundational cybersecurity training across multiple areas, which will be valuable in developing AI-related documentation and ensuring AI compliance with relevant laws and regulations like GDPR. With their ability to effectively identify and mitigate risks, they can ensure that AI is implemented securely and ethically.
Security teams working closely with legal and compliance functions may also benefit from the AI Law & Compliance Professional certification
A CISSP’s primary responsibility is to protect information and provide a secure environment for conducting business practices. For example, if AI awareness is absent among an organization’s staff members, the use of unvetted AI applications creates new categories of risks, potential compliance violations and possible exposure to data confidentiality, integrity and availability; another reason why a transition into AI governance is paramount where businesses leverage AI applications into their processes. Risk management oversight will also be more comprehensive, including documented non-conformities and opportunities for improvements related to AIMS audits.
AI systems inherently include unique security and privacy challenges that CISSP professionals, through their training, can address and mitigate these challenges effectively. They bring valuable expertise in producing policies, standards, procedures, and guidelines to support the cybersecurity framework.
The ISO/IEC 27001 framework for creating an ISMS is similar to the ISO/IEC 42001 framework, just specific to an AIMS; making the move to AI governance transparent.
Professionals who want to apply these principles in practice can build implementation skills through the ISO/IEC 42001 Lead Implementer course.

