
Sign up to save your podcasts
Or


Virtualization and cloud computing are cornerstones of modern IT, but they also introduce unique security challenges. In this episode, we examine the architecture and risks associated with virtual machines, hypervisors, containers, and cloud platforms. You’ll learn how virtual environments increase complexity and expand the attack surface, and what controls are necessary to mitigate these risks. We also explore the shared responsibility model, virtualization sprawl, tenant isolation, and the importance of secure provisioning. Understanding these technologies is critical for designing secure, scalable, and compliant IT environments.
Security isn’t only about software—hardware matters too. This episode introduces key elements of secure hardware architecture, including trusted computing bases, secure boot processes, and hardware root of trust. We also dive into the Trusted Platform Module (TPM), a hardware chip that provides cryptographic key storage, platform integrity checks, and secure identity verification. You’ll learn how TPMs support secure encryption, authentication, and remote attestation. CISSP candidates must understand how hardware-based protections contribute to a system’s overall security posture—especially in high-assurance or regulated environments.
Security must be applied across all layers of a system, from the physical infrastructure to the application interface. In this episode, we explore the layered nature of system architecture—starting with the OSI model’s seven layers, then expanding into how security is applied at the hardware, system, and application levels. You’ll learn how to align controls with each layer’s function, recognize common threats at each level, and understand how layered defenses provide coverage across the stack. This foundational knowledge helps you design and evaluate more secure system architectures.
Security models are theoretical frameworks that help define how systems enforce access control, integrity, and confidentiality. In this episode, we review the three classic models: Bell-LaPadula (focused on confidentiality), Biba (focused on integrity), and Clark-Wilson (focused on well-formed transactions and separation of duties). We explain the core rules behind each model—like “no read up” and “no write down”—and discuss where each is applied in government, commercial, and financial systems. Understanding these models gives you a structured way to think about how systems enforce security.
Designing secure systems isn’t just about applying tools—it’s about embedding principles. This episode introduces two foundational security design concepts: defense in depth and least privilege. Defense in depth layers multiple controls to prevent, detect, and contain threats, while least privilege ensures users and systems operate with the minimum access necessary. We explain how these principles apply to networks, applications, and user environments, and how they reduce risk from both internal and external threats. Understanding and applying these design principles is critical for both the CISSP exam and real-world implementation.
Without visibility, security is just guesswork. In this episode, we explore how logging and monitoring give security teams the information they need to detect, investigate, and respond to incidents. We discuss log types (system, application, network), retention policies, log integrity, and secure storage. Metadata, such as timestamps, source IPs, and user actions, adds context to every alert and event. You'll also learn about regulatory and legal considerations for log retention, especially in forensic investigations. Monitoring is the heartbeat of any security program—this episode shows you how to keep it strong.
Some systems and data are too critical to treat like everything else. This episode focuses on how organizations identify, secure, and manage sensitive systems and high-value assets (HVAs), such as financial databases, intellectual property repositories, and industrial control systems. We discuss segmentation, access control, system hardening, monitoring, and tailored incident response plans for these resources. You’ll also learn how to align asset protection with business impact, risk appetite, and regulatory requirements. CISSP candidates must understand how to prioritize protections for the assets that matter most.
Backup and recovery plans are your insurance against data loss. In this episode, we explore the critical controls necessary to ensure backups are available, secure, and usable when needed. We discuss types of backups (full, incremental, differential), retention policies, storage locations (on-site vs. off-site), and encryption strategies. You’ll also learn about recovery objectives like RTO (Recovery Time Objective) and RPO (Recovery Point Objective), and how to test your backup system effectively. An untested backup is a false sense of security—this episode equips you to build reliable data recovery capabilities.
Cloud services offer scalability and convenience, but they also introduce unique security risks—especially when sharing infrastructure with other tenants. In this episode, we cover best practices for securely using cloud storage, virtualized environments, and shared computing platforms. Topics include encryption, access control, tenant isolation, identity federation, and logging. We also discuss the shared responsibility model, where both provider and customer have distinct obligations. If you’re working with SaaS, IaaS, or hybrid cloud models, you need to know how to safeguard data, workloads, and services in dynamic cloud environments.
In a global digital economy, where your data resides can determine which laws apply to it. This episode explains data sovereignty—the principle that data is subject to the laws of the country in which it’s stored—and how jurisdictional control affects compliance, privacy, and access. We examine common challenges organizations face when storing or processing data across borders, such as conflicting legal obligations or data transfer restrictions. We also explore strategies to manage these complexities, including data localization, cloud region selection, and contractual controls. CISSPs must understand how legal geography impacts cybersecurity.
From the publisher's feed