Jason Edwards

Certified - CCSP Audio Course

The Certified Cloud Security Professional (CCSP) Audio Course is your comprehensive, audio-first companion for mastering the (ISC)² CCSP certification—the global standard for cloud security expertise. Designed for professionals who learn best on the go, this Audio Course transforms the official exam domains into structured, accessible, and engaging lessons you can absorb anywhere. Each episode dives deep into the essential knowledge areas—covering cloud concepts, architecture, design, data security, platform and infrastructure security, application security, operations, and legal and complianc...

Author

Jason Edwards

Category

Education

Podcast website

baremetalcyber.com

Latest episode

Oct 14, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 51 — Logging Foundations: Control Plane and Data Plane Telemetry 08.09.2025

Logging is one of the most critical enablers of visibility in the cloud, yet it is often misunderstood or underutilized. In this episode, we begin by distinguishing between control plane logs, which capture administrative and management actions, and data plane logs, which reflect the actual use of cloud services and resources. Both layers are indispensable for monitoring and forensic readiness, an...

Episode 50 — Software Supply Chain: Provenance, SBOMs and Signing 08.09.2025

Supply chain security has become one of the most urgent issues in cloud and IT. This episode explores how software provenance, Software Bills of Materials (SBOMs), and code-signing ensure integrity in what organizations deploy. We discuss high-profile supply chain compromises to illustrate why this topic has global attention. The exam may frame supply chain questions around verifying authenticity,...

Episode 49 — Infrastructure as Code: Secure Templates and Policy Guardrails 08.09.2025

Infrastructure as Code (IaC) makes cloud environments reproducible and scalable, but insecure templates can replicate vulnerabilities at speed. This episode explains how to secure IaC through validated templates, automated scans, and embedded guardrails. IaC represents both opportunity and risk, making it a high-value topic for the exam. We discuss how organizations enforce governance by treating...

Episode 48 — Secrets Management: Vaulting and Rotation for Infrastructure 08.09.2025

Secrets such as passwords, tokens, and keys are among the most sensitive assets in cloud infrastructure. This episode examines best practices for managing secrets, including vaulting solutions, automated rotation, and strict access controls. We explain why embedding secrets in code or scripts is a critical vulnerability and how to avoid it. We also highlight how secrets management integrates with...

Episode 47 — Identity Integration: Federated Access to Cloud Control Planes 08.09.2025

Identity is the new perimeter in cloud, and integrating it correctly is critical. This episode explores federated identity, single sign-on, and the use of identity providers to manage access to cloud control planes. We highlight why strong authentication, minimal privileges, and centralized oversight are essential for reducing risk. The CCSP exam often tests identity integration through questions...

Episode 46 — Network Controls: Segmentation, Firewalls and Microsegmentation 08.09.2025

Cloud networks are virtual, but the principles of segmentation remain as important as ever. In this episode, we cover traditional controls such as firewalls alongside modern practices like microsegmentation, which allow for granular isolation between workloads. These techniques reduce the blast radius of an attack and limit lateral movement inside the environment. We also explain how cloud provide...

Episode 45 — Serverless Platforms: Event Models and Security Controls 08.09.2025

Serverless computing abstracts away servers, but it does not remove security responsibilities. In this episode, we explain how serverless platforms work through event-driven models and highlight the unique risks they present, including event injection, dependency vulnerabilities, and monitoring gaps. Security for serverless is about rethinking controls—focusing on permissions, code integrity, and...

Episode 44 — Container Platforms: Orchestrator and Container Hardening 08.09.2025

Containers have transformed application delivery by making software portable and efficient, but they introduce unique risks. This episode explores container platforms in depth, focusing on orchestrators like Kubernetes and the hardening measures needed to secure both containers and the platforms that run them. Misconfigurations, excessive privileges, and unpatched images are common threats that mu...

Episode 43 — Compute Workloads: Baselines, Patching and Golden Images 08.09.2025

When deploying workloads in the cloud, consistency and control are vital. This episode examines the use of security baselines, patch management, and golden images as techniques for building strong compute environments. Baselines define the minimum acceptable configuration, while golden images allow organizations to replicate secure states at scale. Together, these practices reduce variability and...

Episode 42 — Virtualization Stack: Hypervisors, VM Security and Hardening 08.09.2025

Virtualization is the foundation of cloud computing, and understanding its stack is essential for both exam readiness and real-world practice. In this episode, we explore how hypervisors create isolated environments, the differences between Type 1 and Type 2 designs, and why isolation is the cornerstone of multi-tenant cloud platforms. Virtual machines rely on these layers to ensure that workloads...

Episode 41 — Domain 3 Overview: Cloud Platform & Infrastructure Security 08.09.2025

Domain 3 of the CCSP exam takes us into the technical backbone of the cloud: platforms and infrastructure. In this episode, we establish the scope of the domain, including compute, storage, networking, virtualization, and the critical controls that protect them. Unlike higher-level governance or data-centric domains, Domain 3 is hands-on and deeply rooted in technical decision-making. It requires...

Episode 40 — E-Discovery & Legal Holds: Cloud Storage Implications 08.09.2025

E-Discovery and legal holds present unique challenges in the cloud, where data may be distributed across services and regions. This episode explains how organizations must preserve, collect, and produce digital evidence when faced with litigation or investigation. We highlight the technical and contractual measures required to ensure compliance. Exam scenarios may test your understanding of how e-...

Episode 39 — Privacy by Design: Minimization, Consent and DPIAs 08.09.2025

Privacy by design integrates data protection principles into every stage of system development. This episode covers key practices such as data minimization, consent management, and Data Protection Impact Assessments (DPIAs). These concepts are central to global privacy frameworks like GDPR and are increasingly expected in cloud solutions. On the exam, privacy by design may appear in questions that...

Episode 38 — Data Sovereignty: Residency, Localization and Transfer Controls 08.09.2025

Where data resides can be just as important as how it is secured. This episode explores sovereignty issues, including residency requirements, localization mandates, and cross-border transfer controls. Cloud adoption often raises complex legal and regulatory challenges that go beyond technical defenses. We also explain how exam questions may present sovereignty as a compliance constraint, requiring...

Episode 37 — Secure Data Deletion: Sanitization and Crypto-Erase in Cloud 08.09.2025

Secure deletion is essential to prevent residual data exposure when storage is repurposed or decommissioned. This episode explains sanitization methods, from overwriting and degaussing to crypto-erase, where encryption keys are destroyed to render data unreadable. We highlight why crypto-erase is often the preferred method in cloud environments. Exam scenarios may ask you to choose the correct del...

Episode 36 — Data Retention: Backup, Archival and Versioning in Cloud 08.09.2025

Retention policies dictate how long data must be preserved and in what form. This episode covers how cloud platforms implement backup, archival storage, and versioning features to meet these requirements. We highlight the security implications of each, from protecting against ransomware to ensuring regulatory compliance. We also explain how the exam uses data retention as a cross-domain topic, com...

Episode 35 — Data Loss Prevention: Patterns, Policies and Tuning 08.09.2025

Data Loss Prevention (DLP) systems help prevent sensitive information from leaving controlled environments. In this episode, we describe how DLP works through pattern recognition, policy enforcement, and user education. We also explore tuning strategies, since overly aggressive DLP can disrupt legitimate workflows. The CCSP exam often tests whether you understand not only what DLP is but how it sh...

Episode 34 — Tokenization & Masking: Protecting Sensitive Fields 08.09.2025

Tokenization and masking are techniques for reducing risk by substituting sensitive values with safe alternatives. This episode explains how tokenization preserves format for data such as credit card numbers, while masking ensures only partial information is visible. Both techniques reduce exposure while still supporting business processes. We explore real-world examples like payment systems, test...

Episode 33 — Access to Data: ABAC, RBAC and Least Privilege Enforcement 08.09.2025

Controlling access to data is as important as protecting it. This episode introduces Attribute-Based Access Control (ABAC), Role-Based Access Control (RBAC), and the principle of least privilege as applied in cloud contexts. We explore how these models work, how policies are defined, and how to prevent excessive entitlements. Exam questions frequently test your ability to apply the right access mo...

Episode 32 — Key Management: KMS, HSM, BYOK and HYOK Considerations 08.09.2025

Effective key management is critical to making encryption usable and trustworthy. In this episode, we dive into concepts such as Key Management Systems (KMS), Hardware Security Modules (HSMs), Bring Your Own Key (BYOK), and Hold Your Own Key (HYOK). We explain how each approach balances control, convenience, and responsibility across providers and customers. The exam often challenges you to distin...

Episode 31 — Encryption in Use: Confidential Computing and Memory Protections 08.09.2025

Encryption isn’t only about data at rest or in transit—today’s cloud technologies also secure data while it is being processed. This episode explains the emerging field of confidential computing, where workloads run inside secure enclaves that shield memory from unauthorized access, even by the host system. You’ll learn how trusted execution environments, hardware-assisted protections, and special...

Episode 30 — Data Protection: Encryption at Rest and In Transit 08.09.2025

Encryption is one of the strongest defenses in the cloud, and the CCSP exam devotes significant focus to it. In this episode, we explore encryption at rest and in transit, explaining how different algorithms, key lengths, and protocols protect data across contexts. We also discuss where encryption is applied automatically by providers and where customer configuration is essential. We then connect...

Episode 29 — Data Classification: Sensitivity Labels and Handling Rules 08.09.2025

Classification assigns value and handling requirements to data, and it’s central to both exam content and real-world practice. This episode explains the different levels of sensitivity, from public to highly confidential, and how organizations apply rules for storage, sharing, and protection. Classification provides the foundation for encryption, access control, and retention strategies. We also l...

Episode 28 — Data Discovery: Catalogs and Classification at Scale 08.09.2025

Data discovery is a critical step in understanding what information you hold and where it resides. In this episode, we discuss how discovery tools and catalogs are used to map data across complex cloud environments. Classification depends on this visibility, and without it, security controls are often misapplied. We also explain how the exam tests understanding of discovery methods, such as automa...

Episode 27 — Data Lifecycle: Create, Store, Use, Share, Archive and Destroy 08.09.2025

Understanding the data lifecycle is fundamental to managing information securely in the cloud. This episode walks through each stage—creation, storage, usage, sharing, archival, and destruction—explaining the security measures that apply at every step. We emphasize how lifecycle thinking helps ensure no data is left unprotected or retained longer than necessary. We also connect lifecycle stages to...

Listen to the Certified - CCSP Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.