
Sign up to save your podcasts
Or


Security boundaries are essential for creating logical separations between systems, users, and data flows. In this episode, we explore how boundaries are defined and enforced, using both physical and logical mechanisms. You’ll learn about concepts like trust zones, network segmentation, VLANs, virtualization, and sandboxing. We also discuss isolation techniques that prevent lateral movement, contain breaches, and ensure critical assets remain protected. Proper use of boundaries and isolation helps reduce attack surfaces, enforce policy, and support compliance. These principles are vital for scalable and secure infrastructure design.
Security evaluations provide assurance that systems meet defined security requirements. In this episode, we examine key evaluation frameworks including Common Criteria (CC), the NIST Risk Management Framework (RMF), and the ISO/IEC 27000 series. You'll learn how these models define evaluation assurance levels, categorize controls, and guide secure system development. We also discuss how evaluation results support procurement, risk analysis, and compliance audits. For CISSP candidates and practitioners, understanding security evaluation frameworks is essential for aligning technical design with governance expectations.
No cryptographic system is immune to attack, and CISSPs must understand the methods used to break or weaken them. In this episode, we explore cryptanalysis techniques including brute-force, dictionary attacks, chosen plaintext attacks, and side-channel analysis. We explain how poor implementation, weak keys, and outdated algorithms create vulnerabilities, and how to mitigate those risks through proper design and monitoring. Understanding these threats enables security professionals to assess crypto deployments with a critical eye and defend against evolving attack strategies.
Public Key Infrastructure (PKI) is essential for enabling secure communication and verifying digital identities. This episode breaks down how PKI works, including the roles of certificate authorities (CAs), registration authorities (RAs), and digital certificates. You’ll learn about certificate chaining, revocation, validation protocols like OCSP and CRL, and how trust is established in both hierarchical and web-of-trust models. From SSL/TLS to code signing and user authentication, PKI is everywhere—and CISSPs need to know how to deploy and troubleshoot it securely.
Cryptographic systems are only as secure as the keys they use—and how those keys are managed. In this episode, we delve into key management principles, including generation, storage, distribution, rotation, and destruction. We also explore key escrow, where a third party securely stores encryption keys for legal or recovery purposes. You’ll learn about hardware security modules (HSMs), key management systems (KMS), and the challenges of managing keys in cloud environments. Whether protecting secrets or ensuring regulatory compliance, strong key management is non-negotiable for any CISSP.
Hashing ensures that data remains unchanged during storage or transmission—a core requirement for integrity. In this episode, we explore how cryptographic hash functions like SHA-256 and SHA-3 are used to detect tampering, generate digital signatures, and verify file authenticity. We discuss key properties such as collision resistance, pre-image resistance, and determinism. You'll also learn the difference between hashing and encryption, and how tools like checksums, MACs, and digital signatures work together to protect data. This is foundational knowledge for building secure applications and validating system outputs.
Cryptographic tools aren’t set-and-forget solutions—they require lifecycle management. This episode explores how organizations select, deploy, and eventually retire cryptographic algorithms. We examine how algorithm strength is determined, the impact of key length, and the risks posed by deprecated or broken ciphers like MD5 and SHA-1. You’ll learn how to stay ahead of threats by monitoring crypto standards and planning for migration to newer algorithms. From algorithm selection to end-of-life planning, this topic helps CISSPs build cryptographic systems that remain secure over time.
Cryptography is the backbone of digital security, and understanding its core principles is essential. In this episode, we explain the difference between symmetric and asymmetric encryption, along with their real-world applications. You’ll learn how symmetric encryption uses a single key for both encryption and decryption, while asymmetric encryption relies on key pairs for secure key exchange, digital signatures, and more. We also discuss algorithm examples like AES, RSA, and ECC. Grasping these concepts enables you to evaluate the strength, use cases, and implementation considerations of cryptographic solutions.
Flawed architecture is one of the most serious vulnerabilities in any system. In this episode, we explore common architectural security weaknesses, including insecure defaults, lack of isolation, poor trust boundaries, and insufficient input validation. We explain how these flaws emerge during design and how they can be exploited by attackers. You’ll also learn how to apply secure design principles to avoid introducing systemic weaknesses in new systems. Whether you're evaluating an existing architecture or designing one from scratch, recognizing and addressing architectural flaws is a must-have skill for CISSPs.
Systems don’t stay secure by accident—they stay secure through consistent configuration and control. In this episode, we cover the concepts of secure baselining and configuration management. You’ll learn how to establish security baselines, enforce configuration standards, and use automation tools to detect and remediate drift. We also discuss patching, change control, and the role of configuration management databases (CMDBs). These practices ensure your systems remain hardened, predictable, and auditable—critical for minimizing attack surfaces, meeting compliance obligations, and maintaining operational stability.
From the publisher's feed