Certified: The CISSP Audio Course

Certified: The CISSP Audio Course

By Dr. Jason EdwardsTechnologyEducationCourses
Download on the App Store

Certified: The CISSP Audio Course episodes

  • Episode 31: Asset Inventory Management

    You can’t protect what you don’t know you have. In this episode, we focus on the importance of maintaining a comprehensive and accurate inventory of all information assets—hardware, software, data, and even personnel. Asset inventory management supports effective risk assessments, helps identify gaps in coverage, and is a foundational requirement for many compliance standards. We explore asset classification, ownership, tracking methods, and how asset data feeds into broader security operations. Without a solid inventory process, security controls can’t be properly scoped, prioritized, or audited—making this topic essential for every CISSP candidate.

    16 min
  • Episode 30: Media Storage and Sanitization Methods

    Digital media—whether it’s a hard drive, USB stick, or backup tape—requires special handling to ensure data remains protected throughout its lifecycle. This episode explores how to securely store, track, and sanitize various types of storage media. We discuss media classification, physical protections, encryption, and environmental controls for storage, as well as different sanitization techniques including clearing, purging, and destruction. You’ll also learn how to enforce policy compliance using checklists, audits, and disposal logs. This topic reinforces your understanding of data confidentiality and end-of-life security.

    11 min
  • Episode 29: Secure Data Handling in Transit and at Rest

    Data is constantly on the move—or waiting to be accessed—and must be protected in both states. In this episode, we examine the best practices for securing data at rest (stored on disk or cloud) and data in transit (moving across networks). You'll learn about encryption methods, key management practices, access controls, and monitoring techniques. We also address compliance requirements that demand specific protections for data in these states. Protecting data wherever it resides or flows is a foundational concept every CISSP candidate must master.

    13 min
  • Episode 28: Data Remanence and Secure Disposal Techniques

    Even when you delete a file, remnants can linger—posing serious security risks. This episode delves into the concept of data remanence and the techniques used to ensure secure data disposal. You'll learn about data wiping, degaussing, shredding, cryptographic erasure, and the standards that guide their use, such as NIST SP 800-88. We also cover the importance of disposal audits, chain of custody for media, and the role of policy in enforcing proper end-of-life procedures. Secure disposal is a small step with massive implications for data confidentiality.

    12 min
  • Episode 27: Privacy Protection and PII Handling

    Personally Identifiable Information (PII) is one of the most regulated and targeted types of data in cybersecurity. This episode focuses on how organizations identify, handle, and protect PII throughout its lifecycle. We explain what qualifies as PII, the risks associated with its misuse, and the controls needed to ensure confidentiality, integrity, and lawful processing. From consent management and access restrictions to anonymization techniques and breach response plans, you’ll gain a comprehensive view of how to build strong privacy protections into your security program.

    12 min
  • Episode 26: Data Retention and Archival Strategies

    Keeping data longer than necessary can increase your risk exposure, but disposing of it too early can create legal and operational gaps. This episode addresses how to build effective data retention and archival strategies that meet legal, regulatory, and business needs. You’ll learn how to define retention periods, implement secure storage solutions for inactive data, and manage transitions into archives. We also discuss how to ensure accessibility for audit and legal discovery without compromising security. These practices are essential for managing digital clutter while protecting valuable records.

    13 min
  • Episode 25: Ownership and Stewardship Responsibilities

    Every piece of information in an organization should have an assigned owner and one or more stewards. In this episode, we define what it means to be a data owner—someone accountable for the data’s use, classification, and protection. We also explore the role of stewards—those responsible for managing data quality and integrity on a day-to-day basis. Clarifying these roles strengthens governance, supports compliance, and streamlines incident response. Understanding how to define, document, and enforce ownership is essential for ensuring security accountability across the enterprise.

    13 min
  • Episode 24: Data Sensitivity and Labeling Requirements

    Labeling data according to its sensitivity is one of the most overlooked but powerful techniques in cybersecurity. In this episode, we explore what it means for data to be considered sensitive, how that sensitivity is determined, and how labels communicate handling requirements to users and systems. We also cover how to implement labeling technologies and ensure compliance with both organizational policies and regulatory requirements. Properly labeling data not only supports access control and encryption but also reinforces accountability and transparency throughout the information lifecycle.

    12 min
  • Episode 23: Information Lifecycle and Data Classification

    Understanding how data flows through its lifecycle is essential for protecting it appropriately. This episode walks through the phases of the information lifecycle: creation, storage, usage, transmission, archival, and disposal. We then examine data classification schemes—such as public, internal, confidential, and restricted—and how classification drives the application of controls. You'll learn how to create classification policies, apply labels, and ensure data is treated consistently according to its value and sensitivity. This foundation is critical for managing risk and enforcing security policies across diverse data environments.

    14 min
  • Episode 22: Security Documentation and Governance Metrics

    Effective security governance depends on clear documentation and measurable performance. This episode explains the structure and function of security documentation—including policies, standards, guidelines, and procedures—as well as how to manage these documents over time. We also explore key performance indicators (KPIs) and metrics used to assess the effectiveness of security controls and governance practices. You'll learn how to track compliance, measure risk reduction, and communicate results to stakeholders. These practices are essential for demonstrating due diligence and maintaining alignment with organizational objectives.

    13 min

About Certified: The CISSP Audio Course

From the publisher's feed

Welcome to The Bare Metal Cyber CISSP Audio Course—your comprehensive companion for mastering the Certified Information Systems Security Professional (CISSP) certification. Built for serious cybersecurity professionals and aspiring leaders alike, this Audio Course transforms the eight domains of the CISSP Common Body of Knowledge into clear, structured, and engaging lessons you can learn anytime, anywhere. Each episode blends real-world context, expert insight, and exam-focused explanations to help you understand not just what to study, but how to think like a security professional. Whether you’re commuting, exercising, or studying after work, this series provides the clarity and direction you need to stay motivated and on track.