Dr Jason Edwards

Certified: The CCISO Audio Course

Education EN ↓ 71 episodes

The Bare Metal Cyber CCISO Audio Course is your complete, executive-level training companion for mastering the Certified Chief Information Security Officer (CCISO) certification. Built for experienced cybersecurity professionals and strategic leaders, this Audio Course delivers over seventy focused episodes covering every domain, concept, and competency area tested on the official EC-Council exam. From governance, risk, and compliance to strategic planning, vendor oversight, and technical control management, each episode provides structured, exam-aligned instruction that bridges theory with re...

Author

Dr Jason Edwards

Category

Education

Podcast website

baremetalcyber.com

Latest episode

Oct 14, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 21: Introduction to Security Controls 06.07.2025

This episode introduces the foundational concept of security controls and explains their critical role in any enterprise cybersecurity program. You’ll learn how controls are used to mitigate risk, enforce policy, and align security with business needs. We walk through the three primary categories of controls—preventive, detective, and corrective—and explore real-world examples of each, from firewa...

Episode 20: Third-Party and Vendor Risk Management 06.07.2025

Vendors can introduce significant security risks into your organization—and in this episode, we explain how CISOs assess, monitor, and manage those risks at scale. You’ll learn about the due diligence process, the importance of security questionnaires, and how to evaluate vendors based on data access, processing activities, regulatory exposure, and contractual obligations. From cloud service provi...

Episode 19: Auditing Security Governance 06.07.2025

Audit plays a vital role in validating that security governance structures are functioning as intended—and this episode teaches you how to prepare for, support, and learn from internal and external audits. You’ll learn how governance controls are evaluated, how auditors assess risk management practices, and how findings should be categorized and escalated. As a CISO, it’s your responsibility to en...

Episode 18: Framework Alignment Strategies 06.07.2025

In this strategy-focused episode, we guide you through aligning your security program with one or more established control frameworks. Whether your organization uses NIST CSF, ISO 27001, COBIT, CIS Controls, or a hybrid approach, you’ll need to understand how to map internal policies and procedures to external standards. We explain why framework alignment matters—not only for audit readiness, but...

Episode 17: Information Security Policy Development 06.07.2025

Effective policy is the backbone of a sound security governance program. In this episode, we break down the entire lifecycle of policy development—from initial scoping and stakeholder input to review, approval, communication, and enforcement. You’ll learn what makes policies successful in practice, not just on paper, and how executive sponsorship and cross-functional buy-in are essential to drivin...

Episode 16: GDPR Essentials for CISOs 06.07.2025

This episode focuses on the General Data Protection Regulation (GDPR) and what CISOs must understand about it to lead global privacy programs effectively. We explore the regulation’s core principles—lawfulness, transparency, data minimization, purpose limitation, and accountability—and how they translate into policy and control requirements. You’ll also learn about the roles of Data Controllers an...

Episode 15: Legal and Regulatory Requirements 06.07.2025

In this episode, we explore the legal landscape that CISOs must navigate when managing information security programs. You’ll learn about the growing body of national and international laws that shape data protection, breach notification, privacy obligations, and due diligence. We explain how executive leaders must interpret legal language, communicate implications to the board, and ensure policies...

Episode 14: Compliance Essentials for CISOs 06.07.2025

Compliance is more than just following rules—it’s about designing sustainable programs that meet regulatory expectations while supporting business objectives. In this episode, we break down the core responsibilities CISOs face when leading compliance initiatives across multiple domains. From industry-specific requirements like HIPAA and PCI DSS to broad frameworks like SOX and GLBA, we explain wha...

Episode 13: FAIR Quantitative Risk Management Overview 06.07.2025

Quantifying risk in financial terms is a vital executive skill, and this episode introduces the FAIR (Factor Analysis of Information Risk) framework to help you build that capability. We explain how FAIR enables CISOs to evaluate risk in dollars and probabilities, allowing for clearer prioritization and investment justification. You’ll learn how to distinguish between loss event frequency and prob...

Episode 12: NIST RMF Essentials for Executives 06.07.2025

This episode introduces the NIST Risk Management Framework (RMF) from an executive perspective, highlighting how it applies to both federal and private sector environments. We walk through the six core steps of the RMF—categorize, select, implement, assess, authorize, and monitor—and show how they translate into strategic planning, resource allocation, and compliance oversight. You’ll learn how to...

Episode 11: ISO 27005 Risk Assessment Essentials 06.07.2025

In this episode, we explore ISO/IEC 27005, the international standard that provides guidelines for information security risk management. You'll learn how ISO 27005 complements the broader ISO/IEC 27001 framework and how it guides organizations through identifying, analyzing, evaluating, and treating information security risks. We unpack each phase of the ISO risk assessment lifecycle and explain h...

Episode 10: Risk Management Fundamentals 06.07.2025
Episode 9: Information Security Roles and Responsibilities 06.07.2025

Who does what in the security hierarchy—and how do those roles contribute to governance, risk, and compliance outcomes? This episode answers that question by mapping the key roles involved in information security management, from security analysts to C-suite executives. We examine the functional responsibilities of the CISO, deputy CISO, security architects, compliance officers, and other critical...

Episode 8: Organizational Structures in Information Security 06.07.2025

In this episode, we analyze how information security is positioned within different organizational structures and why that matters to the CCISO role. We discuss the various models—centralized, decentralized, matrixed—and the unique strengths and weaknesses of each. You’ll hear how reporting lines, departmental independence, and influence over business strategy can directly affect a CISO’s authorit...

Episode 7: Information Security Governance Basics 06.07.2025

This episode marks the beginning of Domain 1, and we start with the fundamental principles of information security governance. You’ll learn what governance actually means in an enterprise context, why it’s different from management, and how CISOs use governance frameworks to align security initiatives with organizational objectives. We explore how formal governance structures enable oversight, acc...

Episode 6: Proven Exam-Day Tips and Time Management Strategies 06.07.2025

In this high-impact episode, we focus on strategies that can make or break your CCISO exam performance. It’s not just about what you know—it’s about how you manage your time, your confidence, and your cognitive stamina under pressure. We walk you through techniques for breaking down complex questions, flagging uncertain items for review, and pacing yourself to avoid running out of time in the fina...

Episode 5: Key Acronyms and Terminology for the CCISO Exam 06.07.2025

Before diving into heavy strategy and technical content, this episode gives you a valuable head start by covering the most critical acronyms, standards, and terms that will appear throughout the CCISO curriculum and the exam itself. From NIST and ISO to PCI, GDPR, and beyond, we introduce the terminology you need to recognize instantly and accurately under pressure. This foundational vocabulary wi...

Episode 4: CCISO Exam Registration, Scheduling, and Costs 06.07.2025

In this logistical but essential episode, we walk you through the full process of registering for the CCISO exam. From choosing your exam track and submitting your eligibility documentation to scheduling your proctored session and paying your fees, every step is explained in plain language. We discuss the different costs involved depending on whether you’re pursuing the exam via training or experi...

Episode 3: CCISO Exam Eligibility and Experience Requirements 06.07.2025

Before registering for the CCISO exam, it’s crucial to understand EC-Council’s eligibility rules—and in this episode, we walk you through every requirement. The CCISO isn’t a certification you can simply purchase and attempt. It’s designed for experienced professionals who have spent years working in key areas of security leadership. We clarify the two pathways to eligibility: the formal training...

Episode 2: CCISO Exam Structure, Domains, and Cognitive Levels 06.07.2025

This episode takes a deep dive into the anatomy of the CCISO exam itself. We explain how the exam is structured, how many questions you’ll encounter, what format those questions take, and how EC-Council assesses the executive-level thinking required for certification. We explore the five domains that make up the CCISO blueprint, and more importantly, the real-world challenges each domain reflects....

Episode 1: Welcome to the CISA Certification 06.07.2025

In this opening episode of The Bare Metal Cyber CCISO Prepcast , we lay the foundation for your journey to becoming a Certified Chief Information Security Officer. The CCISO certification isn’t just another technical credential—it’s a strategic leadership designation tailored for those responsible for aligning security with business goals, managing risk at the enterprise level, and overseeing secu...

Listen to the Certified: The CCISO Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.