GenAI systems in the cloud create new trust boundaries around models, agents, tools, and data. This course builds a practical security view of hosted and self-managed deployments, from threat modeling and prompt injection to identity, authorization, monitoring, incident response, and governance. It is aimed at practitioners who need to secure production GenAI workloads without losing sight of cloud ownership, evidence, and residual risk. By the end, the reader can reason about security controls for LLM and agent applications across the full deployment lifecycle.
The course covers GenAI trust boundaries, LLM and agent threat modeling, prompt injection, RAG permission mirroring, and vector-data isolation. It also addresses workload identity, short-lived credentials, tool authorization, secure deployment for managed APIs and self-hosted weights, runtime monitoring, incident response for data exposure, and governance mapped to engineering controls.