Certified: The CISSP Audio Course

Certified: The CISSP Audio Course

By Dr. Jason EdwardsTechnologyEducationCourses
Download on the App Store

Certified: The CISSP Audio Course episodes

  • Episode 121: OWASP Top 10 Threats and Controls

    The OWASP Top 10 is a widely recognized list of the most critical security risks to web applications. In this episode, we walk through each entry—from injection and broken authentication to cross-site scripting, insecure deserialization, and insufficient logging. You'll learn how these vulnerabilities occur, the business impact they can have, and the recommended controls to prevent or mitigate them. We also discuss how developers and security professionals can use the OWASP Top 10 as a baseline for secure coding practices. CISSPs must understand these threats to assess application risk and implement effective defense strategies.

    26 min
  • Episode 120: Input Validation and Output Encoding

    User input is one of the most common vectors for exploitation in modern applications. In this episode, we focus on two critical programming techniques: input validation and output encoding. We explain how to validate input to ensure it meets expected formats and prevents attacks like SQL injection and cross-site scripting (XSS). We also explore how to encode output for different contexts—such as HTML, JavaScript, or SQL—to avoid executing untrusted data. CISSPs may not write code, but they must understand these defenses to reduce software vulnerabilities and enforce security requirements in development projects.

    12 min
  • Episode 119: Secure Design and Secure Coding Guidelines

    Secure applications start with secure design. In this episode, we explore how to incorporate security into architecture and code from the very beginning. Topics include threat modeling, input validation, secure defaults, and fail-safe mechanisms. We also cover secure coding practices that prevent common vulnerabilities such as injection, buffer overflows, and improper error handling. CISSPs must understand the principles of secure design so they can set expectations, evaluate vendor software, and collaborate effectively with developers to reduce risks before code is ever deployed.

    12 min
  • Episode 118: Waterfall vs. Agile vs. DevOps Approaches

    Development methodologies have a direct impact on how security is integrated into software projects. This episode compares three major approaches—Waterfall, Agile, and DevOps—and how each handles risk, testing, and control. You'll learn the strengths and challenges of each model, including change management, documentation, and time-to-delivery. We also explore how DevSecOps brings security into the CI/CD pipeline. CISSPs must be familiar with these approaches to advise development teams, align controls with process realities, and adapt governance to fast-moving development environments.

    11 min
  • Episode 117: Software Development Lifecycle (SDLC) Models

    Secure software doesn’t happen by accident—it’s the result of disciplined development practices. This episode explores common Software Development Lifecycle (SDLC) models, including waterfall, spiral, and V-model, and how they structure phases such as requirements, design, coding, testing, deployment, and maintenance. We also discuss where and how security should be integrated into each phase. CISSPs must understand SDLC frameworks to support secure software planning, ensure oversight of third-party development, and implement governance for both agile and traditional projects.

    12 min
  • Episode 116: Security Operations Center (SOC) Best Practices

    The Security Operations Center (SOC) is the nerve center of cybersecurity monitoring and incident response. In this episode, we explore SOC roles, responsibilities, staffing models, tools, and key performance indicators. We discuss shift scheduling, escalation paths, use cases, and integration with threat intelligence feeds. You'll also learn about SOC maturity models and how to evolve from reactive operations to proactive threat hunting. CISSPs must understand how to structure, support, and evaluate SOCs to ensure they deliver measurable protection and business value.

    12 min
  • Episode 115: Personnel Security Controls and Separation of Duties

    People are at the heart of every security program—and also one of its greatest vulnerabilities. In this episode, we examine personnel security controls that mitigate human-based risks. Topics include background checks, onboarding protocols, security training, acceptable use policies, and ongoing behavior monitoring. We also explore separation of duties, job rotation, and least privilege principles that reduce fraud and error. CISSPs must be able to design and enforce personnel policies that protect the organization while supporting a strong security culture and clear accountability.

    11 min
  • Episode 114: Physical Security Operations: Locks, Guards, Cameras

    Cybersecurity extends into the physical world, where threats like unauthorized access, theft, and sabotage can bypass digital defenses. In this episode, we explore physical security operations, including the use of barriers, locks, access control systems, security guards, surveillance cameras, and visitor management. We also cover how physical security integrates with IT through badges, biometrics, and monitoring. CISSPs must understand how to assess facility risks, implement layered physical defenses, and coordinate between IT and facilities teams to protect critical assets from physical compromise.

    12 min
  • Episode 113: Malware Analysis and Containment

    Understanding malware is essential for effective defense. This episode explores how security teams analyze and contain malicious software, including viruses, worms, ransomware, and trojans. We break down static and dynamic analysis techniques, sandboxing environments, signature development, and reverse engineering basics. You'll also learn how to contain outbreaks, remove malware safely, and update detection tools. CISSPs may not perform deep malware analysis themselves, but they must understand how malware spreads, how it's investigated, and how to manage risk during outbreaks.

    13 min
  • Episode 112: Insider Threat Identification and Mitigation

    Not all threats come from the outside. Insider threats—whether malicious or accidental—pose a significant risk to organizational security. In this episode, we examine how to identify, monitor, and respond to threats from employees, contractors, or partners with legitimate access. We discuss behavioral indicators, user activity monitoring, data loss prevention (DLP), and privacy considerations. You'll also learn how to balance detection efforts with employee trust and legal requirements. CISSPs must be able to design and enforce insider threat programs that protect assets without undermining culture or morale.

    12 min

About Certified: The CISSP Audio Course

From the publisher's feed

Welcome to The Bare Metal Cyber CISSP Audio Course—your comprehensive companion for mastering the Certified Information Systems Security Professional (CISSP) certification. Built for serious cybersecurity professionals and aspiring leaders alike, this Audio Course transforms the eight domains of the CISSP Common Body of Knowledge into clear, structured, and engaging lessons you can learn anytime, anywhere. Each episode blends real-world context, expert insight, and exam-focused explanations to help you understand not just what to study, but how to think like a security professional. Whether you’re commuting, exercising, or studying after work, this series provides the clarity and direction you need to stay motivated and on track.