
Sign up to save your podcasts
Or


Security testing requires careful control over both the test environment and the data used within it. In this episode, we explore how to create and manage dedicated testing environments that accurately simulate production systems without risking real assets. We cover the importance of data masking, synthetic data generation, and environment segmentation. You'll also learn how to prevent test environments from becoming security liabilities. CISSPs must understand how to manage test data in compliance with privacy regulations while ensuring integrity and realism in the testing process.
Code is a frequent source of vulnerabilities, and reviewing it is essential for secure software development. In this episode, we discuss secure code review techniques—both manual and tool-assisted. We explain how static application security testing (SAST) scans source code before runtime, while dynamic application security testing (DAST) analyzes behavior during execution. You’ll also learn about interactive testing, false positives, secure development lifecycles, and DevSecOps integration. CISSPs don’t have to write code, but they do need to understand how to validate its security and guide development practices.
Security controls are only effective if they’re working as designed. In this episode, we explore how to test those controls using both manual and automated methods. We compare control validation techniques such as checklists, code reviews, synthetic transactions, vulnerability scanners, and red team exercises. You’ll learn when human judgment is needed, when automation scales better, and how to combine the two for comprehensive testing. As a CISSP, knowing how to assess the effectiveness of physical, technical, and administrative controls is key to maintaining a secure and compliant environment.
Security assessments must be planned thoroughly to be effective, safe, and actionable. This episode walks through the planning phase of an assessment project, including goal setting, scope definition, timeline management, and stakeholder communication. We explain how to assess organizational readiness, gain necessary approvals, and avoid disrupting operations. You’ll also learn about risk categorization, asset selection, test environment configuration, and the importance of documentation. CISSPs often serve as project leads or advisors for assessments, making this planning knowledge essential for both technical and governance roles.
Security assessments come in many forms—each with a specific purpose. In this episode, we compare and contrast vulnerability scanning, penetration testing, and formal security audits. We cover the methodologies, tools, scope definitions, and reporting standards associated with each type. You’ll learn how to select the right assessment based on business goals, risk tolerance, and compliance requirements. We also examine legal considerations and rules of engagement for ethical hacking. For CISSPs, choosing and interpreting assessment results is key to effective security governance.
Identity systems are high-value targets, and attackers use increasingly sophisticated techniques to exploit them. This episode examines key IAM-related attack vectors, including replay attacks, pass-the-hash, credential stuffing, brute-force, and phishing-based compromise. We explain how these attacks work, the conditions that enable them, and the defenses needed to detect and prevent them. Controls discussed include session binding, MFA, rate limiting, password hygiene, and advanced behavioral analytics. CISSPs must understand not just how to build IAM systems, but how to defend them against persistent and evolving threats.
Controlling user sessions is a critical part of maintaining secure access. In this episode, we examine how session tokens are issued, maintained, and terminated—along with techniques to prevent hijacking and session fixation attacks. We explore timeout policies, inactivity limits, reauthentication triggers, and secure logout practices. You’ll learn how session management differs across web applications, VPNs, and enterprise software. By enforcing proper session controls, CISSPs can prevent unauthorized reuse, detect anomalies, and strengthen overall authentication posture.
Access permissions tend to accumulate over time, creating a significant security risk if not reviewed regularly. This episode focuses on access recertification—the process of periodically validating that users still need the permissions they’ve been granted. We explain how to plan, automate, and document access reviews, and how to manage exceptions and approvals. You’ll also learn how access governance tools integrate with identity platforms to support audits and compliance. CISSPs play a vital role in ensuring that the principle of least privilege is continuously enforced across dynamic environments.
Access control mechanisms determine who can access what—and how. In this episode, we compare two classic models: Access Control Lists (ACLs) and capability tables. ACLs associate permissions with objects, while capability tables associate them with subjects. We examine their strengths, limitations, and real-world implementations in file systems, network devices, and operating systems. You’ll also learn about how these mechanisms enforce discretionary and mandatory access controls, and how they can be extended using role or attribute-based models. Understanding these concepts is essential for effective system authorization design.
Managing credentials securely is critical to preventing unauthorized access and ensuring business continuity. This episode explores techniques for secure credential issuance, storage, expiration, and revocation. We discuss the lifecycle of credentials across devices, users, and systems, including integration with password managers, key vaults, and enterprise authentication platforms. You'll also learn about secure recovery mechanisms such as self-service portals, identity proofing, and multi-step revalidation. CISSPs must understand how to enforce strong credential management policies while balancing usability, privacy, and administrative efficiency.
From the publisher's feed