Dr. Jason Edwards
Certified: The CISSP Audio Course
Welcome to The Bare Metal Cyber CISSP Audio Course—your comprehensive companion for mastering the Certified Information Systems Security Professional (CISSP) certification. Built for serious cybersecurity professionals and aspiring leaders alike, this Audio Course transforms the eight domains of the CISSP Common Body of Knowledge into clear, structured, and engaging lessons you can learn anytime, anywhere. Each episode blends real-world context, expert insight, and exam-focused explanations to help you understand not just what to study, but how to think like a security professional. Whether yo...
Author
Dr. Jason Edwards
Category
Podcast website
Latest episode
Jan 17, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 41: Virtualization and Cloud Infrastructure Considerations 23.06.2025 13:05
Virtualization and cloud computing are cornerstones of modern IT, but they also introduce unique security challenges. In this episode, we examine the architecture and risks associated with virtual machines, hypervisors, containers, and cloud platforms. You’ll learn how virtual environments increase complexity and expand the attack surface, and what controls are necessary to mitigate these risks. W...
Episode 40: Secure Hardware Architecture and TPM 23.06.2025 18:26
Security isn’t only about software—hardware matters too. This episode introduces key elements of secure hardware architecture, including trusted computing bases, secure boot processes, and hardware root of trust. We also dive into the Trusted Platform Module (TPM), a hardware chip that provides cryptographic key storage, platform integrity checks, and secure identity verification. You’ll learn how...
Episode 39: Architecture Layers: OSI, System, Application 23.06.2025 18:59
Security must be applied across all layers of a system, from the physical infrastructure to the application interface. In this episode, we explore the layered nature of system architecture—starting with the OSI model’s seven layers, then expanding into how security is applied at the hardware, system, and application levels. You’ll learn how to align controls with each layer’s function, recognize c...
Episode 38: Security Models: Bell-LaPadula, Biba, Clark-Wilson 23.06.2025 18:26
Security models are theoretical frameworks that help define how systems enforce access control, integrity, and confidentiality. In this episode, we review the three classic models: Bell-LaPadula (focused on confidentiality), Biba (focused on integrity), and Clark-Wilson (focused on well-formed transactions and separation of duties). We explain the core rules behind each model—like “no read up” and...
Episode 37: Secure Design Principles: Defense in Depth, Least Privilege 23.06.2025 17:14
Designing secure systems isn’t just about applying tools—it’s about embedding principles. This episode introduces two foundational security design concepts: defense in depth and least privilege. Defense in depth layers multiple controls to prevent, detect, and contain threats, while least privilege ensures users and systems operate with the minimum access necessary. We explain how these principles...
Episode 36: Logging, Monitoring, and Metadata Retention for Assets 22.06.2025 17:55
Without visibility, security is just guesswork. In this episode, we explore how logging and monitoring give security teams the information they need to detect, investigate, and respond to incidents. We discuss log types (system, application, network), retention policies, log integrity, and secure storage. Metadata, such as timestamps, source IPs, and user actions, adds context to every alert and e...
Episode 35: Handling of Sensitive Systems and High-Value Assets 22.06.2025 19:44
Some systems and data are too critical to treat like everything else. This episode focuses on how organizations identify, secure, and manage sensitive systems and high-value assets (HVAs), such as financial databases, intellectual property repositories, and industrial control systems. We discuss segmentation, access control, system hardening, monitoring, and tailored incident response plans for th...
Episode 34: Backup Controls and Data Recovery 22.06.2025 17:34
Backup and recovery plans are your insurance against data loss. In this episode, we explore the critical controls necessary to ensure backups are available, secure, and usable when needed. We discuss types of backups (full, incremental, differential), retention policies, storage locations (on-site vs. off-site), and encryption strategies. You’ll also learn about recovery objectives like RTO (Recov...
Episode 33: Secure Use of Cloud Storage and Shared Resources 22.06.2025 16:50
Cloud services offer scalability and convenience, but they also introduce unique security risks—especially when sharing infrastructure with other tenants. In this episode, we cover best practices for securely using cloud storage, virtualized environments, and shared computing platforms. Topics include encryption, access control, tenant isolation, identity federation, and logging. We also discuss t...
Episode 32: Data Sovereignty and Jurisdictional Control 22.06.2025 17:13
In a global digital economy, where your data resides can determine which laws apply to it. This episode explains data sovereignty—the principle that data is subject to the laws of the country in which it’s stored—and how jurisdictional control affects compliance, privacy, and access. We examine common challenges organizations face when storing or processing data across borders, such as conflicting...
Episode 31: Asset Inventory Management 22.06.2025 15:30
You can’t protect what you don’t know you have. In this episode, we focus on the importance of maintaining a comprehensive and accurate inventory of all information assets—hardware, software, data, and even personnel. Asset inventory management supports effective risk assessments, helps identify gaps in coverage, and is a foundational requirement for many compliance standards. We explore asset cla...
Episode 30: Media Storage and Sanitization Methods 22.06.2025 10:52
Digital media—whether it’s a hard drive, USB stick, or backup tape—requires special handling to ensure data remains protected throughout its lifecycle. This episode explores how to securely store, track, and sanitize various types of storage media. We discuss media classification, physical protections, encryption, and environmental controls for storage, as well as different sanitization techniques...
Episode 29: Secure Data Handling in Transit and at Rest 22.06.2025 12:45
Data is constantly on the move—or waiting to be accessed—and must be protected in both states. In this episode, we examine the best practices for securing data at rest (stored on disk or cloud) and data in transit (moving across networks). You'll learn about encryption methods, key management practices, access controls, and monitoring techniques. We also address compliance requirements that demand...
Episode 28: Data Remanence and Secure Disposal Techniques 22.06.2025 11:23
Even when you delete a file, remnants can linger—posing serious security risks. This episode delves into the concept of data remanence and the techniques used to ensure secure data disposal. You'll learn about data wiping, degaussing, shredding, cryptographic erasure, and the standards that guide their use, such as NIST SP 800-88. We also cover the importance of disposal audits, chain of custody f...
Episode 27: Privacy Protection and PII Handling 22.06.2025 11:04
Personally Identifiable Information (PII) is one of the most regulated and targeted types of data in cybersecurity. This episode focuses on how organizations identify, handle, and protect PII throughout its lifecycle. We explain what qualifies as PII, the risks associated with its misuse, and the controls needed to ensure confidentiality, integrity, and lawful processing. From consent management a...
Episode 26: Data Retention and Archival Strategies 22.06.2025 12:02
Keeping data longer than necessary can increase your risk exposure, but disposing of it too early can create legal and operational gaps. This episode addresses how to build effective data retention and archival strategies that meet legal, regulatory, and business needs. You’ll learn how to define retention periods, implement secure storage solutions for inactive data, and manage transitions into a...
Episode 25: Ownership and Stewardship Responsibilities 22.06.2025 12:22
Every piece of information in an organization should have an assigned owner and one or more stewards. In this episode, we define what it means to be a data owner—someone accountable for the data’s use, classification, and protection. We also explore the role of stewards—those responsible for managing data quality and integrity on a day-to-day basis. Clarifying these roles strengthens governance, s...
Episode 24: Data Sensitivity and Labeling Requirements 22.06.2025 11:29
Labeling data according to its sensitivity is one of the most overlooked but powerful techniques in cybersecurity. In this episode, we explore what it means for data to be considered sensitive, how that sensitivity is determined, and how labels communicate handling requirements to users and systems. We also cover how to implement labeling technologies and ensure compliance with both organizational...
Episode 23: Information Lifecycle and Data Classification 22.06.2025 13:30
Understanding how data flows through its lifecycle is essential for protecting it appropriately. This episode walks through the phases of the information lifecycle: creation, storage, usage, transmission, archival, and disposal. We then examine data classification schemes—such as public, internal, confidential, and restricted—and how classification drives the application of controls. You'll learn...
Episode 22: Security Documentation and Governance Metrics 22.06.2025 12:01
Effective security governance depends on clear documentation and measurable performance. This episode explains the structure and function of security documentation—including policies, standards, guidelines, and procedures—as well as how to manage these documents over time. We also explore key performance indicators (KPIs) and metrics used to assess the effectiveness of security controls and govern...
Episode 21: Legal Systems and Cybercrime Laws Globally 22.06.2025 12:59
Cybersecurity professionals operate in a legal landscape that spans continents, jurisdictions, and regulatory systems. In this episode, we examine the major types of legal systems—common law, civil law, religious law, and customary law—and how each influences how cybersecurity is enforced. We also explore global cybercrime laws and treaties, including the Budapest Convention, and review how intern...
Episode 20: Intellectual Property and Licensing Laws 22.06.2025 13:15
Cybersecurity professionals must understand how to protect not only data but also intellectual property. This episode unpacks the key types of intellectual property—copyrights, trademarks, patents, and trade secrets—and how they apply in the digital world. We also examine licensing models for software and content, including open-source and proprietary agreements. Understanding the legal landscape...
Episode 19: Privacy Principles and Data Protection (GDPR, CCPA) 22.06.2025 13:31
Protecting personal data is not just a compliance requirement—it’s a trust imperative. In this episode, we dive into key privacy principles such as data minimization, purpose limitation, and transparency. You’ll learn how regulations like the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) define privacy obligations and empower individuals with rights over...
Episode 18: Supply Chain Risk and Due Diligence 22.06.2025 13:01
Supply chains extend far beyond traditional logistics—they now include digital components, cloud providers, software dependencies, and more. This episode explores how cyber threats enter through the supply chain and what due diligence processes are needed to prevent compromise. We discuss methods for evaluating supply chain partners, setting clear security expectations, and responding to incidents...
Episode 17: Third-Party Risk Management 22.06.2025 13:44
Today’s organizations rely heavily on vendors, contractors, and service providers—but each relationship introduces potential risks. In this episode, we cover the principles of third-party risk management, including due diligence, contractual controls, and ongoing monitoring. You’ll learn how to assess a vendor’s security posture, enforce security requirements through service-level agreements (SLAs...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.