Certified: The CISSP Audio Course

Certified: The CISSP Audio Course

By Dr. Jason EdwardsTechnologyEducationCourses
Download on the App Store

Certified: The CISSP Audio Course episodes

  • Episode 41: Virtualization and Cloud Infrastructure Considerations

    Virtualization and cloud computing are cornerstones of modern IT, but they also introduce unique security challenges. In this episode, we examine the architecture and risks associated with virtual machines, hypervisors, containers, and cloud platforms. You’ll learn how virtual environments increase complexity and expand the attack surface, and what controls are necessary to mitigate these risks. We also explore the shared responsibility model, virtualization sprawl, tenant isolation, and the importance of secure provisioning. Understanding these technologies is critical for designing secure, scalable, and compliant IT environments.

    14 min
  • Episode 40: Secure Hardware Architecture and TPM

    Security isn’t only about software—hardware matters too. This episode introduces key elements of secure hardware architecture, including trusted computing bases, secure boot processes, and hardware root of trust. We also dive into the Trusted Platform Module (TPM), a hardware chip that provides cryptographic key storage, platform integrity checks, and secure identity verification. You’ll learn how TPMs support secure encryption, authentication, and remote attestation. CISSP candidates must understand how hardware-based protections contribute to a system’s overall security posture—especially in high-assurance or regulated environments.

    19 min
  • Episode 39: Architecture Layers: OSI, System, Application

    Security must be applied across all layers of a system, from the physical infrastructure to the application interface. In this episode, we explore the layered nature of system architecture—starting with the OSI model’s seven layers, then expanding into how security is applied at the hardware, system, and application levels. You’ll learn how to align controls with each layer’s function, recognize common threats at each level, and understand how layered defenses provide coverage across the stack. This foundational knowledge helps you design and evaluate more secure system architectures.

    19 min
  • Episode 38: Security Models: Bell-LaPadula, Biba, Clark-Wilson

    Security models are theoretical frameworks that help define how systems enforce access control, integrity, and confidentiality. In this episode, we review the three classic models: Bell-LaPadula (focused on confidentiality), Biba (focused on integrity), and Clark-Wilson (focused on well-formed transactions and separation of duties). We explain the core rules behind each model—like “no read up” and “no write down”—and discuss where each is applied in government, commercial, and financial systems. Understanding these models gives you a structured way to think about how systems enforce security.

    19 min
  • Episode 37: Secure Design Principles: Defense in Depth, Least Privilege

    Designing secure systems isn’t just about applying tools—it’s about embedding principles. This episode introduces two foundational security design concepts: defense in depth and least privilege. Defense in depth layers multiple controls to prevent, detect, and contain threats, while least privilege ensures users and systems operate with the minimum access necessary. We explain how these principles apply to networks, applications, and user environments, and how they reduce risk from both internal and external threats. Understanding and applying these design principles is critical for both the CISSP exam and real-world implementation.

    18 min
  • Episode 36: Logging, Monitoring, and Metadata Retention for Assets

    Without visibility, security is just guesswork. In this episode, we explore how logging and monitoring give security teams the information they need to detect, investigate, and respond to incidents. We discuss log types (system, application, network), retention policies, log integrity, and secure storage. Metadata, such as timestamps, source IPs, and user actions, adds context to every alert and event. You'll also learn about regulatory and legal considerations for log retention, especially in forensic investigations. Monitoring is the heartbeat of any security program—this episode shows you how to keep it strong.

    18 min
  • Episode 35: Handling of Sensitive Systems and High-Value Assets

    Some systems and data are too critical to treat like everything else. This episode focuses on how organizations identify, secure, and manage sensitive systems and high-value assets (HVAs), such as financial databases, intellectual property repositories, and industrial control systems. We discuss segmentation, access control, system hardening, monitoring, and tailored incident response plans for these resources. You’ll also learn how to align asset protection with business impact, risk appetite, and regulatory requirements. CISSP candidates must understand how to prioritize protections for the assets that matter most.

    20 min
  • Episode 34: Backup Controls and Data Recovery

    Backup and recovery plans are your insurance against data loss. In this episode, we explore the critical controls necessary to ensure backups are available, secure, and usable when needed. We discuss types of backups (full, incremental, differential), retention policies, storage locations (on-site vs. off-site), and encryption strategies. You’ll also learn about recovery objectives like RTO (Recovery Time Objective) and RPO (Recovery Point Objective), and how to test your backup system effectively. An untested backup is a false sense of security—this episode equips you to build reliable data recovery capabilities.

    18 min
  • Episode 33: Secure Use of Cloud Storage and Shared Resources

    Cloud services offer scalability and convenience, but they also introduce unique security risks—especially when sharing infrastructure with other tenants. In this episode, we cover best practices for securely using cloud storage, virtualized environments, and shared computing platforms. Topics include encryption, access control, tenant isolation, identity federation, and logging. We also discuss the shared responsibility model, where both provider and customer have distinct obligations. If you’re working with SaaS, IaaS, or hybrid cloud models, you need to know how to safeguard data, workloads, and services in dynamic cloud environments.

    17 min
  • Episode 32: Data Sovereignty and Jurisdictional Control

    In a global digital economy, where your data resides can determine which laws apply to it. This episode explains data sovereignty—the principle that data is subject to the laws of the country in which it’s stored—and how jurisdictional control affects compliance, privacy, and access. We examine common challenges organizations face when storing or processing data across borders, such as conflicting legal obligations or data transfer restrictions. We also explore strategies to manage these complexities, including data localization, cloud region selection, and contractual controls. CISSPs must understand how legal geography impacts cybersecurity.

    18 min

About Certified: The CISSP Audio Course

From the publisher's feed

Welcome to The Bare Metal Cyber CISSP Audio Course—your comprehensive companion for mastering the Certified Information Systems Security Professional (CISSP) certification. Built for serious cybersecurity professionals and aspiring leaders alike, this Audio Course transforms the eight domains of the CISSP Common Body of Knowledge into clear, structured, and engaging lessons you can learn anytime, anywhere. Each episode blends real-world context, expert insight, and exam-focused explanations to help you understand not just what to study, but how to think like a security professional. Whether you’re commuting, exercising, or studying after work, this series provides the clarity and direction you need to stay motivated and on track.