
Sign up to save your podcasts
Or


Cybersecurity professionals operate in a legal landscape that spans continents, jurisdictions, and regulatory systems. In this episode, we examine the major types of legal systems—common law, civil law, religious law, and customary law—and how each influences how cybersecurity is enforced. We also explore global cybercrime laws and treaties, including the Budapest Convention, and review how international cooperation is achieved in cyber investigations. Understanding the legal frameworks that govern data, privacy, and technology helps CISSPs ensure compliance, support law enforcement, and avoid conflicts across borders.
Cybersecurity professionals must understand how to protect not only data but also intellectual property. This episode unpacks the key types of intellectual property—copyrights, trademarks, patents, and trade secrets—and how they apply in the digital world. We also examine licensing models for software and content, including open-source and proprietary agreements. Understanding the legal landscape helps prevent accidental infringement and supports secure software procurement, asset management, and contract design. CISSPs are often called upon to advise on or enforce policies around intellectual property and licensing compliance.
Protecting personal data is not just a compliance requirement—it’s a trust imperative. In this episode, we dive into key privacy principles such as data minimization, purpose limitation, and transparency. You’ll learn how regulations like the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) define privacy obligations and empower individuals with rights over their data. We also cover how organizations can embed privacy by design into their systems and policies. A solid grasp of privacy principles is vital for anyone working in security governance, policy, or legal alignment roles.
Supply chains extend far beyond traditional logistics—they now include digital components, cloud providers, software dependencies, and more. This episode explores how cyber threats enter through the supply chain and what due diligence processes are needed to prevent compromise. We discuss methods for evaluating supply chain partners, setting clear security expectations, and responding to incidents that originate outside your direct control. By understanding the dynamics of modern supply chain risk, CISSP candidates will be better prepared to assess and secure the full ecosystem surrounding their organization’s operations.
Today’s organizations rely heavily on vendors, contractors, and service providers—but each relationship introduces potential risks. In this episode, we cover the principles of third-party risk management, including due diligence, contractual controls, and ongoing monitoring. You’ll learn how to assess a vendor’s security posture, enforce security requirements through service-level agreements (SLAs), and respond when third-party weaknesses are discovered. This topic is increasingly important as supply chain attacks and vendor-based breaches become more common. Managing third-party risk is a core responsibility for any CISSP-certified leader.
Even the best technical defenses can fail if employees don’t understand their security responsibilities. This episode focuses on the development and delivery of effective security awareness and training programs. We explore how to tailor content for different roles, choose the right delivery formats, and measure effectiveness through assessments and behavioral monitoring. You’ll also learn how awareness programs support compliance and reduce risks such as phishing, social engineering, and insider threats. CISSP professionals must not only understand awareness programs but often play a key role in designing and leading them.
People are often the weakest link in cybersecurity, and managing personnel risk is a critical responsibility. In this episode, we discuss best practices for pre-employment screening, including background checks and reference validation. We also explore how organizations use security policies to govern employee behavior and set expectations for acceptable use, confidentiality, and compliance. Finally, we walk through secure termination processes that include revoking access, conducting exit interviews, and managing offboarding. Understanding the human side of cybersecurity is essential for risk reduction, especially in enterprise environments.
A strong cybersecurity program is built on clear and well-documented policies. In this episode, we break down the four foundational types of documentation: policies, standards, procedures, and guidelines. You'll learn how each plays a role in setting expectations, enforcing controls, and guiding behavior. We also explain who creates these documents, how they’re maintained, and why they matter for regulatory compliance and security culture. Understanding this documentation hierarchy is crucial for exam success and for implementing effective, enforceable cybersecurity programs in any organization.
Disaster Recovery Planning is a focused component of business continuity that addresses the rapid restoration of IT infrastructure and systems. In this episode, we explore how DRP helps organizations bounce back after major incidents such as natural disasters, cyberattacks, or system failures. You'll learn about recovery time objectives (RTOs), recovery point objectives (RPOs), and different recovery site strategies like hot, warm, and cold sites. We also explain how DRP integrates with continuity of operations to ensure both technology and essential services remain functional. This episode equips you with tools for designing robust recovery capabilities.
Business Continuity Planning, or BCP, is essential for maintaining operations during unexpected disruptions. This episode explores the key elements of a successful BCP strategy, including risk identification, business impact analysis, and recovery planning. We discuss how organizations determine critical functions, establish recovery priorities, and ensure that people, systems, and processes can recover efficiently. You’ll also learn the difference between BCP and disaster recovery, and why both are necessary for resilience. Mastering BCP concepts not only prepares you for the CISSP exam but helps you contribute to real-world continuity efforts.
From the publisher's feed