GAICC AI Conference & Awards 2026 "Governing the Future – Building Responsible, Safe and Human-centric AI"

CISSP to AI Governance - Allen Balasa

Can CISSP Holders Move Into AI Governance?

Absolutely! For CISSP holders, making a transition into AI governance is not only a viable option but a necessary one for all security professionals to stay current with AI technology and the AI threat landscape.

AI is becoming increasingly integrated into business processes and since CISSP professionals can effectively design, implement and manage an Information Security Management System (ISMS) cybersecurity program, they can leverage their training in building and supporting an AI governance program, focusing on ethical, fair, transparent and secure AI implementation practices.

CISSPs have foundational cybersecurity training across multiple areas, which will be valuable in developing AI-related documentation and ensuring AI compliance with relevant laws and regulations like GDPR. With their ability to effectively identify and mitigate risks, they can ensure that AI is implemented securely and ethically.

Security teams working closely with legal and compliance functions may also benefit from the AI Law & Compliance Professional certification

A CISSP’s primary responsibility is to protect information and provide a secure environment for conducting business practices. For example, if AI awareness is absent among an organization’s staff members, the use of unvetted AI applications creates new categories of risks, potential compliance violations and possible exposure to data confidentiality, integrity and availability; another reason why a transition into AI governance is paramount where businesses leverage AI applications into their processes. Risk management oversight will also be more comprehensive, including documented non-conformities and opportunities for improvements related to AIMS audits.

AI systems inherently include unique security and privacy challenges that CISSP professionals, through their training, can address and mitigate these challenges effectively. They bring valuable expertise in producing policies, standards, procedures, and guidelines to support the cybersecurity framework.

The ISO/IEC 27001 framework for creating an ISMS is similar to the ISO/IEC 42001 framework, just specific to an AIMS; making the move to AI governance transparent.

Professionals who want to apply these principles in practice can build implementation skills through the ISO/IEC 42001 Lead Implementer course.

Share it :
About the Author

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

A globally certified instructor in ISO/IEC, PMI®, TOGAF®, SAFe®, and Scrum.org disciplines. With over three years’ hands-on experience in ISO/IEC 42001 AI governance, he delivers training and consulting across New Zealand, Australia, Malaysia, the Philippines, and the UAE, combining high-end credentials with practical, real-world expertise and global reach.

About the Author
Allen Balasa

Allen Balasa

Cybersecurity, Risk and Compliance Professional

I’m a highly certified cybersecurity and compliance professional with over 19 years of experience in the GRC space across multiple verticals. My diverse experience provides strategic and tactical solutions and controls in optimizing cybersecurity processes, creating organizational security cultures, and practices in compliance and risk management. The CISSP certification started my journey into Information Security and Risk Management.

Start Your ISO/IEC 42001 Lead Implementer Training Today

4.8 / 5.0 Rating

Recent Post