
Sign up to save your podcasts
Or


Identity-as-a-Service (IDaaS) provides centralized identity and access management capabilities from the cloud. In this episode, we explore the architecture and benefits of IDaaS solutions, including scalability, simplified administration, and integration with cloud-native applications. You’ll learn how IDaaS supports federated identity, multi-factor authentication, and compliance through managed platforms. We also cover risks such as vendor lock-in, data privacy concerns, and API exposure. CISSPs must be prepared to evaluate IDaaS providers, configure identity governance, and ensure secure, policy-driven access in hybrid environments.
Multi-Factor Authentication (MFA) significantly strengthens identity verification by requiring more than one authentication factor. In this episode, we break down the different types of factors—something you know, have, are, do, or where you are—and how they’re combined for robust protection. We explore methods such as SMS codes, authenticator apps, smart cards, biometrics, and physical tokens. You’ll also learn how to implement MFA in various environments, manage usability challenges, and respond to bypass attempts. For CISSPs, mastering MFA is critical to securing both cloud and on-premise access paths.
Directory services are centralized databases that store and manage user credentials, permissions, and group memberships. In this episode, we explore how Lightweight Directory Access Protocol (LDAP) and Microsoft Active Directory (AD) function as the backbone of identity infrastructure. Topics include directory hierarchies, schema design, authentication flows, and integration with Kerberos. We also discuss common attacks on directories—like privilege escalation and replication abuse—and how to defend against them. For CISSPs, understanding directory services is essential for building scalable, secure access management systems.
Privileged accounts have elevated access and are among the most targeted assets in any organization. In this episode, we examine Privileged Access Management (PAM) solutions, including vaulting, session recording, just-in-time provisioning, and approval workflows. We explain how PAM helps enforce least privilege, reduce insider threats, and meet compliance obligations. You'll also learn how to monitor, audit, and respond to anomalous privileged activity. Managing administrative access is critical to defending your environment, and CISSPs must know how to control the power that comes with privileged credentials.
Federated identity systems allow users to authenticate across multiple platforms using a single identity, often enabling Single Sign-On (SSO). In this episode, we explain how standards like SAML, OAuth 2.0, and OpenID Connect enable cross-domain authentication. You’ll learn the difference between authentication and authorization, how token exchanges work, and what security concerns arise with federated systems. These technologies reduce friction, improve user experience, and centralize control—but only when implemented correctly. CISSPs must understand how to secure identity federation for enterprise and cloud environments.
Biometric authentication uses unique physical or behavioral traits—like fingerprints, facial features, or voice—to verify identity. In this episode, we explore how biometrics work, including the concepts of enrollment, matching algorithms, false acceptance rates (FAR), false rejection rates (FRR), and spoofing resistance. We also examine the strengths and weaknesses of different biometric systems, their privacy implications, and where they’re most effectively deployed. As biometric technologies continue to evolve and gain adoption, CISSPs must understand how to assess, implement, and monitor them securely and ethically.
Passwords remain one of the most widely used—but frequently abused—authentication methods. In this episode, we explore how to design and manage effective password policies that balance usability with security. We cover best practices like minimum complexity, reuse prevention, expiration cycles, and password vaulting. You’ll also learn about modern recommendations from NIST that challenge older practices like frequent forced changes. CISSPs must understand how password policies impact behavior, system integration, and the broader security landscape, especially in hybrid and cloud environments.
Identity and Access Management (IAM) is not just about technology—it’s a continuous lifecycle that requires strong governance. This episode walks through each stage of the IAM lifecycle: provisioning, access management, auditing, revalidation, and deprovisioning. We also examine governance frameworks that ensure IAM aligns with policy, risk appetite, and regulatory standards. From role design and separation of duties to periodic access reviews and exception handling, we explain how to maintain control and accountability over digital identities. A strong IAM governance model is essential for CISSPs managing access at scale.
Once a user’s identity is authenticated, the system must decide what they are allowed to do. This episode focuses on common authorization models: Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), Mandatory Access Control (MAC), and Discretionary Access Control (DAC). We explore the rules and policies that govern each model, along with their strengths, weaknesses, and appropriate use cases. You'll learn how to align authorization mechanisms with security policies and compliance requirements. For the CISSP exam and real-world implementation, these models form the core of secure resource management.
Before you can authenticate someone, you must first establish their identity through a process called identity proofing. In this episode, we cover how identity proofing works—from in-person validation and biometric capture to document verification and knowledge-based authentication. We explain how organizations perform registration, bind credentials, and manage onboarding securely. These processes form the foundation of digital identity and trust. Whether you're issuing smart cards for physical access or provisioning accounts for a cloud service, CISSPs must understand the lifecycle of identity creation and assurance.
From the publisher's feed