Certified: The CISSP Audio Course

Certified: The CISSP Audio Course

By Dr. Jason EdwardsTechnologyEducationCourses
Download on the App Store

Certified: The CISSP Audio Course episodes

  • Episode 101: Daily Operations: Procedures, Monitoring, Checklists

    Security operations are built on consistency, structure, and clear documentation. In this episode, we explore the daily tasks that keep cybersecurity programs running—such as log reviews, system checks, user access reviews, and patch verification. We explain how operational procedures and checklists reduce errors, promote accountability, and streamline incident response. You’ll also learn how to align these routines with compliance requirements and best practices. CISSPs are expected to understand how standard operating procedures (SOPs) and continuous monitoring form the backbone of an effective and auditable security operations center (SOC).

    13 min
  • Episode 100: Assessing Third-Party and Vendor Risk

    Vendors and service providers often have privileged access to your data and systems—making them a potential weak link. This episode focuses on third-party risk management, including how to evaluate a vendor's security posture before and after engagement. We cover due diligence checklists, contract clauses, security questionnaires, and ongoing monitoring practices. You'll also learn about shared responsibility models and how to manage risks across cloud, SaaS, and supply chain relationships. CISSPs must ensure that third-party access is governed with the same rigor as internal controls.

    17 min
  • Episode 99: Continuous Monitoring and Feedback Loops

    Security is not a one-time event—it’s a continuous process. In this episode, we explore how continuous monitoring helps organizations detect changes, uncover risks, and maintain compliance in dynamic environments. We discuss how to implement automated data collection, baseline comparison, and event correlation across networks, endpoints, cloud services, and applications. You'll also learn how feedback loops from incidents, audits, and testing drive program maturity. CISSPs must understand how to design, scale, and sustain continuous monitoring efforts that support real-time decision-making and operational resilience.

    15 min
  • Episode 98: Metrics and KPIs for Security Performance

    What gets measured gets managed—and security is no exception. This episode focuses on security metrics and key performance indicators (KPIs) that help organizations evaluate the effectiveness of their controls and programs. We cover types of metrics (operational, compliance, risk-based), how to design meaningful KPIs, and how to avoid common pitfalls like vanity metrics. You'll also learn how to tie metrics to business objectives and use them in dashboards and reports. CISSPs must understand how to measure what matters and use those insights to drive continuous improvement.

    14 min
  • Episode 97: Reporting Assessment Results Effectively

    The value of a security assessment is only realized when the results are communicated clearly. In this episode, we discuss how to structure, write, and deliver effective reports for vulnerability scans, penetration tests, audits, and more. You'll learn how to prioritize findings by risk, provide context for business stakeholders, and recommend actionable remediation. We also explore visualizations, executive summaries, and post-report follow-ups. Strong reporting bridges the gap between technical detail and strategic decision-making—a vital skill for CISSPs responsible for communicating risk.

    13 min
  • Episode 96: Threat Hunting and Red Team Exercises

    Proactive threat hunting involves searching for signs of compromise that automated tools may miss. In this episode, we explain how threat hunters use hypothesis-driven analysis, threat intelligence, and behavioral indicators to uncover hidden risks. We also explore red team exercises—simulated attacks designed to test detection and response capabilities. You'll learn about attack frameworks like MITRE ATT&CK and how to coordinate purple teaming to maximize value. These offensive techniques, when used ethically, provide deep insight into real-world readiness and resilience—essential knowledge for CISSP professionals.

    17 min
  • Episode 95: Log Analysis for Forensics and Compliance

    Logs are a goldmine of insight—but only if you know how to analyze them effectively. This episode dives into log collection, normalization, and correlation to support both forensic investigations and compliance reporting. We cover log sources such as firewalls, IDS/IPS, servers, applications, and cloud services, as well as how to identify anomalies, detect patterns, and preserve evidence. We also discuss the use of SIEM tools and log retention policies. CISSPs must understand how to leverage log data to validate events, investigate incidents, and meet audit requirements.

    14 min
  • Episode 94: Compliance Auditing and Evidence Collection

    Audits provide assurance that an organization is following its security policies and regulatory obligations. In this episode, we explore how compliance audits are structured, conducted, and evaluated. You’ll learn how to collect evidence, prepare audit trails, manage interviews, and handle audit scope creep. We also cover the role of internal vs. external auditors and discuss popular frameworks like ISO 27001, SOC 2, and PCI DSS. For CISSPs, knowing how to support audits with accurate records and professional communication is essential to demonstrating due diligence and regulatory alignment.

    16 min
  • Episode 93: Risk Assessment and Gap Analysis

    Risk assessments help prioritize security controls by identifying vulnerabilities, evaluating threats, and estimating potential impacts. In this episode, we break down how to conduct both qualitative and quantitative assessments, including risk matrix construction, asset valuation, and likelihood estimation. We also explain gap analysis—comparing current security posture against frameworks, regulations, or internal standards to find missing controls. CISSPs must be able to interpret these assessments, communicate their implications to stakeholders, and use them to justify security investments and policy changes.

    17 min
  • Episode 92: Test Coverage and Measurement

    How do you know your security testing is thorough? In this episode, we examine test coverage metrics and how they help evaluate the effectiveness and completeness of assessments. We explain different forms of coverage—such as code path coverage, requirement coverage, and risk-based coverage—and how to map test cases to threat models and control objectives. You'll also learn how to interpret results and identify coverage gaps. Effective measurement allows CISSPs to ensure that testing efforts align with business risks and produce actionable insights for continuous improvement.

    15 min

About Certified: The CISSP Audio Course

From the publisher's feed

Welcome to The Bare Metal Cyber CISSP Audio Course—your comprehensive companion for mastering the Certified Information Systems Security Professional (CISSP) certification. Built for serious cybersecurity professionals and aspiring leaders alike, this Audio Course transforms the eight domains of the CISSP Common Body of Knowledge into clear, structured, and engaging lessons you can learn anytime, anywhere. Each episode blends real-world context, expert insight, and exam-focused explanations to help you understand not just what to study, but how to think like a security professional. Whether you’re commuting, exercising, or studying after work, this series provides the clarity and direction you need to stay motivated and on track.