Explore every episode of the podcast Certified: The CISSP Audio Course
| Title | Pub. Date | Duration | |
|---|---|---|---|
| Episode 1: What Is the CISSP and Why It Matters | 22 Jun 2025 | 00:13:37 | |
In this foundational episode, we introduce the Certified Information Systems Security Professional—better known as the CISSP. You’ll learn what the certification represents, who it’s designed for, and why it continues to be considered the gold standard for cybersecurity professionals around the world. We explore how the CISSP stands apart from other security credentials, what it proves about your skills, and how it fits into the broader cybersecurity career ecosystem. Whether you’re pursuing technical leadership, governance, or executive-level roles, understanding the CISSP’s value is the first step toward strategic career development. | |||
| Episode 2: CISSP vs. Other Certifications: Which One’s Right for You? | 22 Jun 2025 | 00:17:23 | |
Choosing the right cybersecurity certification can shape your career for years to come. In this episode, we compare the CISSP to other well-known certifications including CompTIA Security+, CISM, CRISC, and CEH. We examine how these credentials differ in focus, experience level, and strategic alignment—helping you understand which path fits your background and goals. Whether you're looking for a technical launchpad or a management-level credential, this discussion highlights where the CISSP stands in the broader certification landscape and how it fits into a layered learning and professional development plan. | |||
| Episode 11: Risk Response and Risk Appetite | 22 Jun 2025 | 00:16:08 | |
Once a risk is identified and assessed, the next critical step is determining how to respond. In this episode, we examine the four primary risk response strategies: risk avoidance, risk mitigation, risk transference, and risk acceptance. We also clarify the concepts of risk appetite and risk tolerance, and how organizations use these to shape their security policies and control decisions. You'll learn how business objectives, regulatory pressure, and operational needs influence how much risk an organization is willing to take. Understanding these principles enables security professionals to align cybersecurity decisions with broader business goals. | |||
| Episode 101: Daily Operations: Procedures, Monitoring, Checklists | 23 Jun 2025 | 00:12:05 | |
Security operations are built on consistency, structure, and clear documentation. In this episode, we explore the daily tasks that keep cybersecurity programs running—such as log reviews, system checks, user access reviews, and patch verification. We explain how operational procedures and checklists reduce errors, promote accountability, and streamline incident response. You’ll also learn how to align these routines with compliance requirements and best practices. CISSPs are expected to understand how standard operating procedures (SOPs) and continuous monitoring form the backbone of an effective and auditable security operations center (SOC). | |||
| Episode 102: Logging, Event Correlation, and SIEM | 23 Jun 2025 | 00:10:46 | |
Capturing events is only the beginning—making sense of them is where the real value lies. This episode covers how organizations collect, normalize, and correlate logs from various systems and devices using Security Information and Event Management (SIEM) platforms. We discuss the components of a SIEM, alert tuning, and the use of correlation rules to detect complex threat patterns. You'll learn how SIEMs enhance visibility, speed up investigations, and support compliance with standards like HIPAA and PCI DSS. CISSPs must understand how to use logging and SIEM tools to build proactive and resilient detection capabilities. | |||
| Episode 103: Incident Management: Preparation and Response | 23 Jun 2025 | 00:12:19 | |
Incidents are inevitable, and how you respond can determine the scale of impact. In this episode, we walk through the phases of incident management—preparation, identification, containment, eradication, recovery, and lessons learned. We explain how to build an incident response plan, assemble a response team, and establish escalation protocols. You’ll also learn how to coordinate with legal, PR, and law enforcement when necessary. Incident management is a high-priority domain for CISSPs because it brings together technical expertise, process discipline, and communication under pressure. | |||
| Episode 104: Digital Forensics and Chain of Custody | 23 Jun 2025 | 00:12:20 | |
Preserving and analyzing digital evidence requires precision, consistency, and legal awareness. This episode explores the fundamentals of digital forensics—from identifying and collecting evidence to maintaining a documented chain of custody. We discuss volatile data acquisition, imaging tools, hashing for integrity verification, and timeline reconstruction. You’ll also learn about legal standards that govern admissibility and the responsibilities of forensic investigators. CISSPs don’t have to be deep forensic experts, but they must understand how to support investigations and preserve evidence in a defensible manner. | |||
| Episode 105: Evidence Acquisition and Preservation | 23 Jun 2025 | 00:11:29 | |
The reliability of evidence hinges on how it’s handled. In this episode, we dive deeper into the principles and techniques for acquiring and preserving digital evidence. Topics include imaging storage media, capturing memory dumps, recording live sessions, and documenting every step in the collection process. We also address how to avoid contamination, preserve timestamps, and ensure repeatability for court presentation. CISSPs must ensure that any evidence collected during investigations—whether by internal teams or third-party experts—is done with integrity and according to accepted forensic procedures. | |||
| Episode 106: Disaster Recovery Planning: RTO, RPO | 23 Jun 2025 | 00:13:19 | |
When disaster strikes, organizations must restore operations quickly—and with minimal data loss. This episode focuses on Disaster Recovery Planning (DRP), particularly the metrics used to guide recovery strategies: Recovery Time Objective (RTO) and Recovery Point Objective (RPO). We explain how to define recovery priorities, select appropriate backup and failover solutions, and develop DR plans that meet business expectations. You’ll also learn about recovery site options, communication planning, and regular testing. CISSPs must understand DRP as part of a broader resilience strategy tied to business continuity. | |||
| Episode 107: Business Continuity Testing and Tabletop Exercises | 23 Jun 2025 | 00:12:09 | |
Plans are only useful if they’re tested. In this episode, we explore the various methods for testing business continuity and disaster recovery plans—including walkthroughs, simulations, functional tests, and tabletop exercises. We discuss how to design tests, involve key stakeholders, and evaluate performance without disrupting operations. You’ll learn how testing helps uncover weaknesses in coordination, communication, and recovery capabilities. For CISSPs, facilitating and analyzing these exercises is crucial to strengthening organizational resilience and ensuring plans work under real-world conditions. | |||
| Episode 108: Patch Management and Configuration Control | 23 Jun 2025 | 00:10:42 | |
Unpatched systems are one of the leading causes of successful cyberattacks. In this episode, we explore the role of patch management and configuration control in maintaining secure and reliable systems. We explain how to evaluate patches, schedule deployments, and monitor success. You'll also learn how to track configuration baselines, control changes, and enforce consistent settings across environments. CISSPs must ensure that vulnerabilities are addressed promptly and that unauthorized changes are detected and corrected before they become security issues. | |||
| Episode 109: Change Control and Approval Processes | 23 Jun 2025 | 00:10:50 | |
Security isn’t just about stopping bad changes—it’s about managing all changes effectively. In this episode, we examine the formal process of change control: how to submit change requests, perform impact assessments, obtain approvals, test in controlled environments, and document results. We also cover the importance of change advisory boards (CABs), rollback planning, and post-implementation review. For CISSPs, understanding change control is key to maintaining operational stability, preventing unauthorized modifications, and aligning IT operations with regulatory and security frameworks. | |||
| Episode 110: Secure Disposal and Media Sanitization | 23 Jun 2025 | 00:11:14 | |
Data doesn’t disappear just because you delete it. In this episode, we focus on how to securely dispose of media and sanitize storage devices to prevent data recovery. We cover techniques such as overwriting, degaussing, cryptographic erasure, and physical destruction, as well as when and how to apply each. You’ll also learn about documentation requirements, chain of custody for retired media, and applicable standards like NIST SP 800-88. CISSPs must ensure that end-of-life processes are consistent, auditable, and aligned with regulatory and organizational data protection obligations. | |||
| Episode 12: Business Continuity Planning (BCP) Fundamentals | 22 Jun 2025 | 00:15:01 | |
Business Continuity Planning, or BCP, is essential for maintaining operations during unexpected disruptions. This episode explores the key elements of a successful BCP strategy, including risk identification, business impact analysis, and recovery planning. We discuss how organizations determine critical functions, establish recovery priorities, and ensure that people, systems, and processes can recover efficiently. You’ll also learn the difference between BCP and disaster recovery, and why both are necessary for resilience. Mastering BCP concepts not only prepares you for the CISSP exam but helps you contribute to real-world continuity efforts. | |||
| Episode 111: Endpoint Detection and Response (EDR) | 23 Jun 2025 | 00:10:58 | |
Endpoints remain a primary target for cyberattacks, and protecting them requires more than traditional antivirus solutions. This episode explores Endpoint Detection and Response (EDR), a modern approach to securing laptops, desktops, servers, and mobile devices. We explain how EDR tools provide real-time monitoring, behavioral analysis, threat hunting, and automated response capabilities. You'll learn how EDR integrates with SIEM platforms, supports forensic investigations, and helps contain lateral movement during incidents. CISSPs must understand how to evaluate, deploy, and tune EDR solutions to protect the front lines of enterprise environments. | |||
| Episode 112: Insider Threat Identification and Mitigation | 23 Jun 2025 | 00:11:53 | |
Not all threats come from the outside. Insider threats—whether malicious or accidental—pose a significant risk to organizational security. In this episode, we examine how to identify, monitor, and respond to threats from employees, contractors, or partners with legitimate access. We discuss behavioral indicators, user activity monitoring, data loss prevention (DLP), and privacy considerations. You'll also learn how to balance detection efforts with employee trust and legal requirements. CISSPs must be able to design and enforce insider threat programs that protect assets without undermining culture or morale. | |||
| Episode 113: Malware Analysis and Containment | 23 Jun 2025 | 00:12:18 | |
Understanding malware is essential for effective defense. This episode explores how security teams analyze and contain malicious software, including viruses, worms, ransomware, and trojans. We break down static and dynamic analysis techniques, sandboxing environments, signature development, and reverse engineering basics. You'll also learn how to contain outbreaks, remove malware safely, and update detection tools. CISSPs may not perform deep malware analysis themselves, but they must understand how malware spreads, how it's investigated, and how to manage risk during outbreaks. | |||
| Episode 114: Physical Security Operations: Locks, Guards, Cameras | 23 Jun 2025 | 00:11:55 | |
Cybersecurity extends into the physical world, where threats like unauthorized access, theft, and sabotage can bypass digital defenses. In this episode, we explore physical security operations, including the use of barriers, locks, access control systems, security guards, surveillance cameras, and visitor management. We also cover how physical security integrates with IT through badges, biometrics, and monitoring. CISSPs must understand how to assess facility risks, implement layered physical defenses, and coordinate between IT and facilities teams to protect critical assets from physical compromise. | |||
| Episode 115: Personnel Security Controls and Separation of Duties | 23 Jun 2025 | 00:10:52 | |
People are at the heart of every security program—and also one of its greatest vulnerabilities. In this episode, we examine personnel security controls that mitigate human-based risks. Topics include background checks, onboarding protocols, security training, acceptable use policies, and ongoing behavior monitoring. We also explore separation of duties, job rotation, and least privilege principles that reduce fraud and error. CISSPs must be able to design and enforce personnel policies that protect the organization while supporting a strong security culture and clear accountability. | |||
| Episode 116: Security Operations Center (SOC) Best Practices | 23 Jun 2025 | 00:11:14 | |
The Security Operations Center (SOC) is the nerve center of cybersecurity monitoring and incident response. In this episode, we explore SOC roles, responsibilities, staffing models, tools, and key performance indicators. We discuss shift scheduling, escalation paths, use cases, and integration with threat intelligence feeds. You'll also learn about SOC maturity models and how to evolve from reactive operations to proactive threat hunting. CISSPs must understand how to structure, support, and evaluate SOCs to ensure they deliver measurable protection and business value. | |||
| Episode 117: Software Development Lifecycle (SDLC) Models | 23 Jun 2025 | 00:11:09 | |
Secure software doesn’t happen by accident—it’s the result of disciplined development practices. This episode explores common Software Development Lifecycle (SDLC) models, including waterfall, spiral, and V-model, and how they structure phases such as requirements, design, coding, testing, deployment, and maintenance. We also discuss where and how security should be integrated into each phase. CISSPs must understand SDLC frameworks to support secure software planning, ensure oversight of third-party development, and implement governance for both agile and traditional projects. | |||
| Episode 118: Waterfall vs. Agile vs. DevOps Approaches | 23 Jun 2025 | 00:10:18 | |
Development methodologies have a direct impact on how security is integrated into software projects. This episode compares three major approaches—Waterfall, Agile, and DevOps—and how each handles risk, testing, and control. You'll learn the strengths and challenges of each model, including change management, documentation, and time-to-delivery. We also explore how DevSecOps brings security into the CI/CD pipeline. CISSPs must be familiar with these approaches to advise development teams, align controls with process realities, and adapt governance to fast-moving development environments. | |||
| Episode 119: Secure Design and Secure Coding Guidelines | 23 Jun 2025 | 00:11:03 | |
Secure applications start with secure design. In this episode, we explore how to incorporate security into architecture and code from the very beginning. Topics include threat modeling, input validation, secure defaults, and fail-safe mechanisms. We also cover secure coding practices that prevent common vulnerabilities such as injection, buffer overflows, and improper error handling. CISSPs must understand the principles of secure design so they can set expectations, evaluate vendor software, and collaborate effectively with developers to reduce risks before code is ever deployed. | |||
| Episode 120: Input Validation and Output Encoding | 23 Jun 2025 | 00:11:15 | |
User input is one of the most common vectors for exploitation in modern applications. In this episode, we focus on two critical programming techniques: input validation and output encoding. We explain how to validate input to ensure it meets expected formats and prevents attacks like SQL injection and cross-site scripting (XSS). We also explore how to encode output for different contexts—such as HTML, JavaScript, or SQL—to avoid executing untrusted data. CISSPs may not write code, but they must understand these defenses to reduce software vulnerabilities and enforce security requirements in development projects. | |||
| Episode 13: Disaster Recovery Planning (DRP) and Continuity of Operations | 22 Jun 2025 | 00:12:49 | |
Disaster Recovery Planning is a focused component of business continuity that addresses the rapid restoration of IT infrastructure and systems. In this episode, we explore how DRP helps organizations bounce back after major incidents such as natural disasters, cyberattacks, or system failures. You'll learn about recovery time objectives (RTOs), recovery point objectives (RPOs), and different recovery site strategies like hot, warm, and cold sites. We also explain how DRP integrates with continuity of operations to ensure both technology and essential services remain functional. This episode equips you with tools for designing robust recovery capabilities. | |||
| Episode 121: OWASP Top 10 Threats and Controls | 23 Jun 2025 | 00:25:44 | |
The OWASP Top 10 is a widely recognized list of the most critical security risks to web applications. In this episode, we walk through each entry—from injection and broken authentication to cross-site scripting, insecure deserialization, and insufficient logging. You'll learn how these vulnerabilities occur, the business impact they can have, and the recommended controls to prevent or mitigate them. We also discuss how developers and security professionals can use the OWASP Top 10 as a baseline for secure coding practices. CISSPs must understand these threats to assess application risk and implement effective defense strategies. | |||
| Episode 122: Buffer Overflows, SQL Injection, and Common Flaws | 23 Jun 2025 | 00:13:14 | |
Many devastating cyberattacks originate from well-known coding flaws. This episode examines classic vulnerabilities including buffer overflows, SQL injection, and other input-related attacks. We explain how these issues arise, what they allow attackers to do, and how to defend against them using secure coding, bounds checking, input validation, and runtime protections like DEP and ASLR. You'll also learn about real-world incidents that exploited these flaws. For CISSPs, understanding common software weaknesses is critical for conducting risk assessments, reviewing software, and advising development teams. | |||
| Episode 123: Security Testing: SAST, DAST, IAST | 23 Jun 2025 | 00:11:13 | |
Security testing helps ensure software behaves as intended under hostile conditions. In this episode, we explore different application security testing methodologies, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Interactive Application Security Testing (IAST). We explain how each method works, their strengths and limitations, and when to use them during the software development lifecycle. You’ll also learn how these tools integrate with DevOps workflows and how to interpret test results. CISSPs must be able to recommend and evaluate testing strategies to support secure software delivery. | |||
| Episode 124: Code Repositories and Access Controls | 23 Jun 2025 | 00:12:39 | |
Source code repositories are central to modern software development—and to software security. This episode covers the security considerations for using platforms like GitHub, GitLab, Bitbucket, and internal repositories. We examine access control policies, branching strategies, commit tracking, and how to detect malicious code changes. You’ll learn about secrets scanning, signed commits, and repository hardening. CISSPs must understand how to secure the development pipeline and enforce controls that protect intellectual property and prevent code tampering at its source. | |||
| Episode 125: Configuration Management and CI/CD Pipelines | 23 Jun 2025 | 00:14:24 | |
Secure development doesn't stop at writing code—it includes how that code is built, tested, and deployed. In this episode, we explore configuration management and continuous integration/continuous delivery (CI/CD) pipelines. We discuss how insecure configurations, exposed secrets, and unmonitored automation can lead to compromise. Topics include infrastructure as code (IaC), environment hardening, automated security gates, and rollback procedures. CISSPs must know how to assess CI/CD pipeline security and ensure that automation enhances, rather than undermines, control over software deployment. | |||
| Episode 126: Version Control and Code Integrity | 23 Jun 2025 | 00:13:17 | |
Version control systems track changes to code—but they also need to be protected themselves. This episode explores how tools like Git help enforce code integrity, collaboration, and traceability across development teams. We cover commit histories, branching strategies, and how to detect unauthorized or malicious changes. You’ll learn about tagging, rollbacks, signed commits, and hash verification to ensure that what gets deployed is what was intended. For CISSPs, maintaining code integrity across distributed teams and tools is key to supporting trustworthy software development practices. | |||
| Episode 127: Application Whitelisting and Sandboxing | 23 Jun 2025 | 00:14:52 | |
Not all applications should be allowed to run in your environment. This episode explores application control mechanisms like whitelisting and sandboxing. You'll learn how whitelisting enforces control by allowing only approved executables, and how sandboxing isolates applications to prevent them from affecting system integrity. We also discuss implementation strategies, policy management, and how to handle exceptions. These controls are especially valuable in high-security or highly regulated environments. CISSPs must understand how to limit application behavior to reduce attack surfaces and contain potential damage. | |||
| Episode 128: Mobile Application Security and Reverse Engineering | 23 Jun 2025 | 00:14:46 | |
Mobile apps introduce unique risks due to their widespread use, diverse platforms, and limited control over user devices. In this episode, we explore mobile app security concerns, including insecure storage, weak authentication, exposed APIs, and code tampering. We also introduce reverse engineering concepts—how attackers decompile apps to uncover secrets or modify behavior. You’ll learn mitigation strategies such as code obfuscation, secure storage APIs, and runtime protections. CISSPs must understand how to assess mobile application threats and ensure that mobile deployments align with organizational security standards. | |||
| Episode 129: Secure APIs and Service Integration | 23 Jun 2025 | 00:14:59 | |
APIs enable system integration but can expose your infrastructure to serious vulnerabilities if not secured properly. This episode focuses on how to design and manage secure APIs. We cover authentication methods (API keys, OAuth), input validation, rate limiting, logging, and error handling. You’ll also learn about common API security issues like broken object-level authorization and excessive data exposure. Secure API development is essential for any modern digital service, and CISSPs must ensure that APIs are managed with the same rigor as traditional application interfaces. | |||
| Episode 130: DevSecOps Culture and Continuous Assurance | 23 Jun 2025 | 00:15:39 | |
DevSecOps is not just a toolset—it’s a culture that integrates security into every phase of the software development lifecycle. In this episode, we explore how DevSecOps breaks down silos between development, operations, and security teams. Topics include automated security testing, continuous compliance checks, secure coding training, and real-time feedback loops. You’ll learn how to embed security into CI/CD pipelines and enforce policy-as-code principles. For CISSPs, fostering a DevSecOps culture means shifting security left, enabling rapid innovation while maintaining rigorous standards for protection and assurance. | |||
| Episode 14: Security Policies, Standards, Procedures, and Guidelines | 22 Jun 2025 | 00:13:47 | |
A strong cybersecurity program is built on clear and well-documented policies. In this episode, we break down the four foundational types of documentation: policies, standards, procedures, and guidelines. You'll learn how each plays a role in setting expectations, enforcing controls, and guiding behavior. We also explain who creates these documents, how they’re maintained, and why they matter for regulatory compliance and security culture. Understanding this documentation hierarchy is crucial for exam success and for implementing effective, enforceable cybersecurity programs in any organization. | |||
| Episode 131: Top 10 Hardest CISSP Concepts Demystified | 23 Jun 2025 | 00:09:31 | |
Some CISSP topics consistently challenge even experienced professionals. In this episode, we break down ten of the most difficult concepts on the exam—ranging from cryptographic key lifecycle and security models to risk calculations and legal frameworks. We clarify the nuances, provide examples, and share memory aids to help you master these areas. Whether you’re struggling with asset valuation formulas, access control methodologies, or cloud governance, this review will sharpen your understanding. CISSPs must be confident in these complex subjects to handle exam scenarios and real-world leadership challenges. | |||
| Episode 135: Memory Tricks and Mnemonics for the CISSP | 23 Jun 2025 | 00:10:05 | |
With so much material to retain, memory tools are a CISSP candidate’s secret weapon. In this episode, we provide proven mnemonics, visual associations, and acronym expansions to help you remember everything from the OSI model and CIA triad to the phases of incident response and risk treatment options. You’ll also learn strategies for reducing cognitive overload and improving recall under exam pressure. These techniques are designed to make memorization more efficient and retention more reliable—especially when you're balancing study time with professional responsibilities. | |||
| Episode 136: How to Deconstruct CISSP Questions | 23 Jun 2025 | 00:11:29 | |
CISSP exam questions are known for being complex, layered, and sometimes intentionally confusing. In this episode, we teach you how to break questions apart to find the real point being tested. You'll learn how to identify the scenario, isolate the question stem, and evaluate answer choices using elimination strategies. We also discuss common distractors, keywords like “best,” “first,” and “most likely,” and how to avoid overthinking. CISSPs must be able to think critically, quickly, and clearly—this episode helps you build the habits to do just that. | |||
| Episode 137: Understanding "Best", "First", and "Most Likely" Wording | 23 Jun 2025 | 00:09:51 | |
CISSP exam questions often hinge on a single word that changes everything. In this episode, we examine how to interpret qualifiers like “best,” “first,” “most appropriate,” and “least likely.” We explain what each prompt is asking you to consider—whether it’s prioritization, sequencing, or judgment—and how to choose the answer that aligns with ISC2's expected mindset. You'll hear examples and practice strategies that train you to read between the lines. CISSPs must be precise thinkers, and this episode ensures you don't miss points over semantics. | |||
| Episode 138: Adaptive Testing Tips and Time Management | 23 Jun 2025 | 00:11:25 | |
The CISSP exam uses Computerized Adaptive Testing (CAT), which means question difficulty and test length vary based on your performance. In this episode, we demystify the CAT format, explain how scoring works, and share strategies to manage your time across the exam. You’ll learn when to move quickly, when to slow down, and how to pace yourself under pressure. We also provide techniques for staying focused during long test sessions and avoiding mental fatigue. CISSP candidates who understand CAT mechanics have a clear advantage in approaching the exam with confidence and control. | |||
| Episode 139: What Comes After the CISSP: Career and Certification Roadmap | 23 Jun 2025 | 00:08:01 | |
Earning your CISSP opens new doors—but where you go next depends on your goals. In this episode, we explore the post-CISSP landscape, including leadership roles like CISO, and technical specializations like cloud security and digital forensics. We also review advanced certifications such as CCSP, CISM, CRISC, and the CISSP concentrations in architecture, engineering, and management. You’ll learn how to use your CISSP as a launchpad for continuous professional development. CISSPs are expected to lead—this episode shows you how to build a career path that’s secure, strategic, and sustainable. | |||
| Episode 140: What to Do If You Fail the CISSP | 23 Jun 2025 | 00:07:22 | |
Not everyone passes on the first try—but failure doesn’t define your journey. In this episode, we guide you through a structured plan for recovery if you don’t pass the CISSP exam. We cover how to interpret your exam feedback, identify weak domains, revise your study strategy, and rebuild confidence. You’ll also learn how to maintain momentum and avoid burnout during your next round of preparation. CISSPs are persistent by nature, and this episode helps you turn setbacks into setups for future success—because your path forward is still wide open. | |||
| Episode 15: Personnel Security: Background Checks, Policies, Termination | 22 Jun 2025 | 00:15:08 | |
People are often the weakest link in cybersecurity, and managing personnel risk is a critical responsibility. In this episode, we discuss best practices for pre-employment screening, including background checks and reference validation. We also explore how organizations use security policies to govern employee behavior and set expectations for acceptable use, confidentiality, and compliance. Finally, we walk through secure termination processes that include revoking access, conducting exit interviews, and managing offboarding. Understanding the human side of cybersecurity is essential for risk reduction, especially in enterprise environments. | |||
| Episode 16: Security Awareness and Training Programs | 22 Jun 2025 | 00:12:52 | |
Even the best technical defenses can fail if employees don’t understand their security responsibilities. This episode focuses on the development and delivery of effective security awareness and training programs. We explore how to tailor content for different roles, choose the right delivery formats, and measure effectiveness through assessments and behavioral monitoring. You’ll also learn how awareness programs support compliance and reduce risks such as phishing, social engineering, and insider threats. CISSP professionals must not only understand awareness programs but often play a key role in designing and leading them. | |||
| Episode 17: Third-Party Risk Management | 22 Jun 2025 | 00:13:44 | |
Today’s organizations rely heavily on vendors, contractors, and service providers—but each relationship introduces potential risks. In this episode, we cover the principles of third-party risk management, including due diligence, contractual controls, and ongoing monitoring. You’ll learn how to assess a vendor’s security posture, enforce security requirements through service-level agreements (SLAs), and respond when third-party weaknesses are discovered. This topic is increasingly important as supply chain attacks and vendor-based breaches become more common. Managing third-party risk is a core responsibility for any CISSP-certified leader. | |||
| Episode 18: Supply Chain Risk and Due Diligence | 22 Jun 2025 | 00:13:01 | |
Supply chains extend far beyond traditional logistics—they now include digital components, cloud providers, software dependencies, and more. This episode explores how cyber threats enter through the supply chain and what due diligence processes are needed to prevent compromise. We discuss methods for evaluating supply chain partners, setting clear security expectations, and responding to incidents that originate outside your direct control. By understanding the dynamics of modern supply chain risk, CISSP candidates will be better prepared to assess and secure the full ecosystem surrounding their organization’s operations. | |||
| Episode 19: Privacy Principles and Data Protection (GDPR, CCPA) | 22 Jun 2025 | 00:13:31 | |
Protecting personal data is not just a compliance requirement—it’s a trust imperative. In this episode, we dive into key privacy principles such as data minimization, purpose limitation, and transparency. You’ll learn how regulations like the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) define privacy obligations and empower individuals with rights over their data. We also cover how organizations can embed privacy by design into their systems and policies. A solid grasp of privacy principles is vital for anyone working in security governance, policy, or legal alignment roles. | |||
| Episode 20: Intellectual Property and Licensing Laws | 22 Jun 2025 | 00:13:15 | |
Cybersecurity professionals must understand how to protect not only data but also intellectual property. This episode unpacks the key types of intellectual property—copyrights, trademarks, patents, and trade secrets—and how they apply in the digital world. We also examine licensing models for software and content, including open-source and proprietary agreements. Understanding the legal landscape helps prevent accidental infringement and supports secure software procurement, asset management, and contract design. CISSPs are often called upon to advise on or enforce policies around intellectual property and licensing compliance. | |||
| Episode 3: Career Impact of the CISSP: Roles, Salaries, Growth | 22 Jun 2025 | 00:19:02 | |
The CISSP isn’t just a certification—it’s a powerful career accelerator. This episode breaks down how earning your CISSP can open doors to high-level roles, raise your earning potential, and give you access to new leadership opportunities in the cybersecurity field. We cover the types of positions typically held by CISSP-certified professionals, explore industry data on salary trends, and discuss how employers view this credential during the hiring process. If you're wondering whether the CISSP is worth the investment, this episode lays out the tangible career benefits that come with certification. | |||