Dr. Jason Edwards
Certified: The CISSP Audio Course
Welcome to The Bare Metal Cyber CISSP Audio Course—your comprehensive companion for mastering the Certified Information Systems Security Professional (CISSP) certification. Built for serious cybersecurity professionals and aspiring leaders alike, this Audio Course transforms the eight domains of the CISSP Common Body of Knowledge into clear, structured, and engaging lessons you can learn anytime, anywhere. Each episode blends real-world context, expert insight, and exam-focused explanations to help you understand not just what to study, but how to think like a security professional. Whether yo...
Author
Dr. Jason Edwards
Category
Podcast website
Latest episode
Jan 17, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 91: Security Test Data and Environment Management 23.06.2025 12:20
Security testing requires careful control over both the test environment and the data used within it. In this episode, we explore how to create and manage dedicated testing environments that accurately simulate production systems without risking real assets. We cover the importance of data masking, synthetic data generation, and environment segmentation. You'll also learn how to prevent test envir...
Episode 90: Code Review and Static/Dynamic Testing 23.06.2025 12:13
Code is a frequent source of vulnerabilities, and reviewing it is essential for secure software development. In this episode, we discuss secure code review techniques—both manual and tool-assisted. We explain how static application security testing (SAST) scans source code before runtime, while dynamic application security testing (DAST) analyzes behavior during execution. You’ll also learn about...
Episode 89: Security Control Testing: Manual vs. Automated 23.06.2025 11:50
Security controls are only effective if they’re working as designed. In this episode, we explore how to test those controls using both manual and automated methods. We compare control validation techniques such as checklists, code reviews, synthetic transactions, vulnerability scanners, and red team exercises. You’ll learn when human judgment is needed, when automation scales better, and how to co...
Episode 88: Planning a Security Assessment 23.06.2025 13:03
Security assessments must be planned thoroughly to be effective, safe, and actionable. This episode walks through the planning phase of an assessment project, including goal setting, scope definition, timeline management, and stakeholder communication. We explain how to assess organizational readiness, gain necessary approvals, and avoid disrupting operations. You’ll also learn about risk categori...
Episode 87: Assessment Types: Vulnerability Scans, Pen Testing, Audits 23.06.2025 12:19
Security assessments come in many forms—each with a specific purpose. In this episode, we compare and contrast vulnerability scanning, penetration testing, and formal security audits. We cover the methodologies, tools, scope definitions, and reporting standards associated with each type. You’ll learn how to select the right assessment based on business goals, risk tolerance, and compliance require...
Episode 86: Threats to IAM: Replay, Pass-the-Hash, Credential Stuffing 23.06.2025 13:26
Identity systems are high-value targets, and attackers use increasingly sophisticated techniques to exploit them. This episode examines key IAM-related attack vectors, including replay attacks, pass-the-hash, credential stuffing, brute-force, and phishing-based compromise. We explain how these attacks work, the conditions that enable them, and the defenses needed to detect and prevent them. Contro...
Episode 85: Session Management and Timeout Policies 23.06.2025 13:39
Controlling user sessions is a critical part of maintaining secure access. In this episode, we examine how session tokens are issued, maintained, and terminated—along with techniques to prevent hijacking and session fixation attacks. We explore timeout policies, inactivity limits, reauthentication triggers, and secure logout practices. You’ll learn how session management differs across web applica...
Episode 84: Access Recertification and Review 23.06.2025 12:59
Access permissions tend to accumulate over time, creating a significant security risk if not reviewed regularly. This episode focuses on access recertification—the process of periodically validating that users still need the permissions they’ve been granted. We explain how to plan, automate, and document access reviews, and how to manage exceptions and approvals. You’ll also learn how access gover...
Episode 83: Access Control Lists and Capability Tables 23.06.2025 14:13
Access control mechanisms determine who can access what—and how. In this episode, we compare two classic models: Access Control Lists (ACLs) and capability tables. ACLs associate permissions with objects, while capability tables associate them with subjects. We examine their strengths, limitations, and real-world implementations in file systems, network devices, and operating systems. You’ll also...
Episode 82: Credential Management and Recovery 23.06.2025 13:25
Managing credentials securely is critical to preventing unauthorized access and ensuring business continuity. This episode explores techniques for secure credential issuance, storage, expiration, and revocation. We discuss the lifecycle of credentials across devices, users, and systems, including integration with password managers, key vaults, and enterprise authentication platforms. You'll also l...
Episode 81: Identity-as-a-Service (IDaaS) and Cloud IAM 23.06.2025 13:37
Identity-as-a-Service (IDaaS) provides centralized identity and access management capabilities from the cloud. In this episode, we explore the architecture and benefits of IDaaS solutions, including scalability, simplified administration, and integration with cloud-native applications. You’ll learn how IDaaS supports federated identity, multi-factor authentication, and compliance through managed p...
Episode 80: Multi-Factor Authentication and Implementation 23.06.2025 13:16
Multi-Factor Authentication (MFA) significantly strengthens identity verification by requiring more than one authentication factor. In this episode, we break down the different types of factors—something you know, have, are, do, or where you are—and how they’re combined for robust protection. We explore methods such as SMS codes, authenticator apps, smart cards, biometrics, and physical tokens. Yo...
Episode 79: Directory Services: LDAP, Active Directory 23.06.2025 15:48
Directory services are centralized databases that store and manage user credentials, permissions, and group memberships. In this episode, we explore how Lightweight Directory Access Protocol (LDAP) and Microsoft Active Directory (AD) function as the backbone of identity infrastructure. Topics include directory hierarchies, schema design, authentication flows, and integration with Kerberos. We also...
Episode 78: Privileged Access Management (PAM) 23.06.2025 13:26
Privileged accounts have elevated access and are among the most targeted assets in any organization. In this episode, we examine Privileged Access Management (PAM) solutions, including vaulting, session recording, just-in-time provisioning, and approval workflows. We explain how PAM helps enforce least privilege, reduce insider threats, and meet compliance obligations. You'll also learn how to mon...
Episode 77: Federation and SSO: SAML, OAuth, OpenID 23.06.2025 13:07
Federated identity systems allow users to authenticate across multiple platforms using a single identity, often enabling Single Sign-On (SSO). In this episode, we explain how standards like SAML, OAuth 2.0, and OpenID Connect enable cross-domain authentication. You’ll learn the difference between authentication and authorization, how token exchanges work, and what security concerns arise with fede...
Episode 76: Biometric Authentication Strengths and Weaknesses 23.06.2025 14:22
Biometric authentication uses unique physical or behavioral traits—like fingerprints, facial features, or voice—to verify identity. In this episode, we explore how biometrics work, including the concepts of enrollment, matching algorithms, false acceptance rates (FAR), false rejection rates (FRR), and spoofing resistance. We also examine the strengths and weaknesses of different biometric systems,...
Episode 75: Password Policy Design and Management 23.06.2025 14:46
Passwords remain one of the most widely used—but frequently abused—authentication methods. In this episode, we explore how to design and manage effective password policies that balance usability with security. We cover best practices like minimum complexity, reuse prevention, expiration cycles, and password vaulting. You’ll also learn about modern recommendations from NIST that challenge older pra...
Episode 74: IAM Lifecycle and Governance 23.06.2025 14:44
Identity and Access Management (IAM) is not just about technology—it’s a continuous lifecycle that requires strong governance. This episode walks through each stage of the IAM lifecycle: provisioning, access management, auditing, revalidation, and deprovisioning. We also examine governance frameworks that ensure IAM aligns with policy, risk appetite, and regulatory standards. From role design and...
Episode 73: Authorization Techniques: RBAC, ABAC, MAC, DAC 23.06.2025 13:30
Once a user’s identity is authenticated, the system must decide what they are allowed to do. This episode focuses on common authorization models: Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), Mandatory Access Control (MAC), and Discretionary Access Control (DAC). We explore the rules and policies that govern each model, along with their strengths, weaknesses, and appropr...
Episode 72: Identity Proofing and Registration Processes 23.06.2025 14:40
Before you can authenticate someone, you must first establish their identity through a process called identity proofing. In this episode, we cover how identity proofing works—from in-person validation and biometric capture to document verification and knowledge-based authentication. We explain how organizations perform registration, bind credentials, and manage onboarding securely. These processes...
Episode 71: Authentication Factors and Methods 23.06.2025 16:08
Authentication is the process of verifying identity, and it forms the first line of defense in access control. In this episode, we explore the different authentication factors: something you know (passwords, PINs), something you have (tokens, smart cards), something you are (biometrics), somewhere you are (location), and something you do (behavioral patterns). We also examine common authentication...
Episode 70: DDoS Protection and High Availability Networks 23.06.2025 18:27
Distributed Denial of Service (DDoS) attacks are designed to overwhelm systems and take down critical services. In this episode, we explain how these attacks work—volumetric, protocol, and application-layer—and the techniques used to defend against them. You’ll learn about scrubbing centers, rate limiting, traffic shaping, and the role of content delivery networks in mitigation. We also explore ho...
Episode 69: Cloud Network Security (CASB, SASE, Virtual Firewalls) 23.06.2025 18:34
As more organizations move to the cloud, network security must evolve. This episode focuses on cloud-native controls including Cloud Access Security Brokers (CASB), Secure Access Service Edge (SASE), and virtual firewalls. You’ll learn how these tools provide visibility, policy enforcement, data loss prevention, and threat protection across hybrid and multi-cloud environments. We also cover identi...
Episode 68: Content Delivery Networks and Edge Security 23.06.2025 18:05
Content Delivery Networks (CDNs) accelerate access to web content by distributing it across global edge nodes, but they also introduce new attack surfaces. In this episode, we discuss how CDNs work, their role in performance optimization, and the security challenges they present, such as cache poisoning, misconfigured access controls, and DDoS targeting. We also explore edge computing security—pro...
Episode 67: Zero Trust and Software-Defined Networking (SDN) 23.06.2025 17:21
Zero Trust has emerged as a powerful model for modern cybersecurity, shifting the focus from perimeter defenses to granular, identity-centric control. In this episode, we explain the principles of Zero Trust—never trust, always verify—and how it’s implemented using continuous authentication, microsegmentation, and least privilege access. We also explore Software-Defined Networking (SDN), a framewo...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.