Dr. Jason Edwards
Certified: The CompTIA Security+ Audio Course
Certified - Security+ 701 is your completely free audio companion for mastering the CompTIA Security+ SY0-701 certification exam. Developed by BareMetalCyber.com, this immersive Audio Course transforms every domain of the official exam objectives into clear, practical, and exam-ready lessons you can learn anywhere—whether commuting, exercising, or studying at home. Each episode delivers focused explanations, real-world examples, and proven study strategies designed to build confidence and help you pass on your first attempt. Structured for busy professionals and new learners alike, the series...
Author
Dr. Jason Edwards
Category
Podcast website
Latest episode
Apr 28, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 198: Vendor Risk and Supply Chain Considerations (Domain 5) 16.06.2025 19:11
A growing portion of cybersecurity risk now comes from outside the organization—specifically, through third-party vendors, suppliers, and service providers. In this episode, we examine how to assess and manage vendor risk across the full lifecycle, starting with due diligence during procurement and continuing through onboarding, monitoring, and offboarding. We explore how to evaluate vendors based...
Episode 197: Mean Time Metrics and System Resilience (Domain 5) 16.06.2025 20:03
System resilience depends not only on planning but on measurable performance—and in this episode, we explore four key metrics that define how systems behave under failure: Mean Time to Repair (MTTR), Mean Time Between Failures (MTBF), Mean Time to Detect (MTTD), and Mean Time to Respond (MTTR—the other one). MTTR (repair) reflects how long it takes to fix a failed system, while MTBF gives insight...
Episode 196: Understanding Recovery Objectives (Domain 5) 16.06.2025 17:48
Recovery objectives define how quickly and how completely a system must return to functionality after a disruption—and in this episode, we explore two of the most critical metrics: Recovery Time Objective (RTO) and Recovery Point Objective (RPO). RTO sets the maximum allowable downtime before business operations suffer unacceptable consequences, while RPO defines how much data loss an organization...
Episode 195: Business Impact Analysis (Domain 5) 16.06.2025 20:14
Business Impact Analysis (BIA) is the foundation of business continuity and disaster recovery planning, helping organizations understand which processes matter most and how downtime affects operations. In this episode, we break down how BIAs identify critical systems, estimate recovery time objectives (RTOs) and recovery point objectives (RPOs), and assess financial, operational, and reputational...
Episode 194: Risk Reporting and Communication (Domain 5) 16.06.2025 19:23
Risk is meaningless if it isn’t communicated effectively—and in this episode, we focus on how risk reporting bridges the gap between technical findings and business leadership. We explore how to craft reports that align with the audience: dashboards and trend lines for executives, technical remediation plans for IT, and regulatory compliance summaries for auditors. Effective risk communication tra...
Episode 193: Risk Management Strategies (Domain 5) 16.06.2025 20:03
Once risks are identified and analyzed, organizations must decide how to respond—and in this episode, we examine the five primary risk management strategies: mitigate, transfer, accept, avoid, and exempt. Mitigation involves applying controls to reduce risk impact or likelihood, such as enabling MFA or installing endpoint protection. Transferring risk often involves insurance or outsourcing functi...
Episode 192: Risk Appetite, Tolerance, and Thresholds (Domain 5) 16.06.2025 19:12
Every organization must decide how much risk it is willing to accept in pursuit of its goals—and this decision informs every security investment, policy, and control. In this episode, we break down the concepts of risk appetite (what you’re willing to pursue), risk tolerance (what you’re willing to withstand), and risk thresholds (the hard lines that should not be crossed). We explore how these va...
Episode 191: Risk Registers and Key Risk Indicators (Domain 5) 16.06.2025 19:42
Managing risk at scale requires tools that provide structure and visibility, and in this episode, we examine two of the most important: risk registers and key risk indicators (KRIs). A risk register is a living document that catalogs identified risks, their likelihood, potential impact, status, ownership, and mitigation plans. It enables organizations to prioritize action, track accountability, an...
Episode 190: Risk Analysis and Scoring (Domain 5) 16.06.2025 19:38
After risks are identified, they need to be analyzed and prioritized—and that’s where risk scoring comes in. In this episode, we break down both qualitative methods (like high/medium/low ratings and heat maps) and quantitative techniques (like Single Loss Expectancy, Annualized Loss Expectancy, and Annualized Rate of Occurrence). We explain how these models help translate risk into business impact...
Episode 189: Conducting Risk Assessments (Domain 5) 16.06.2025 20:00
Risk assessments provide the data organizations need to make informed security decisions, and in this episode, we explore the different types of assessments and how they’re conducted. We start by comparing ad hoc, recurring, one-time, and continuous assessments, each of which serves different operational or compliance needs. We explain how to scope an assessment, identify stakeholders, gather data...
Episode 188: Risk Management Fundamentals (Domain 5) 16.06.2025 22:13
Risk management is the engine that drives strategic decision-making in security, helping organizations focus their efforts on what matters most. In this episode, we explain how to identify risks, evaluate their likelihood and impact, and decide whether to accept, avoid, mitigate, or transfer them. We cover key concepts like threat, vulnerability, asset, and exposure, as well as tools such as risk...
Episode 187: Governance Structures and Roles (Part 2) (Domain 5) 16.06.2025 20:53
Having a governance structure is only the beginning—the real value comes from clearly defining roles and responsibilities within that structure. In this episode, we examine the key roles involved in managing data and systems securely, including data owners, custodians, stewards, processors, and controllers. Data owners are responsible for setting classification levels and defining access policies,...
Episode 186: Governance Structures and Roles (Part 1) (Domain 5) 16.06.2025 20:36
Security governance relies on a clear structure that defines how decisions are made, who enforces them, and how oversight is maintained. In this episode, we explore governance structures such as boards, steering committees, and cross-functional security councils, each playing a role in shaping strategy, prioritizing risks, and allocating resources. These structures help align security goals with b...
Episode 185: Monitoring and Revising Governance Policies (Domain 5) 16.06.2025 21:02
Security policies must evolve with technology, threat landscapes, and business goals—and that’s why continuous monitoring and revision are essential. In this episode, we explore how organizations maintain governance effectiveness by regularly reviewing policies, tracking their implementation, and auditing their relevance. We cover methods like policy health checks, control performance metrics, sta...
Episode 184: External Security Governance Considerations (Domain 5) 16.06.2025 20:59
Security doesn't operate in a vacuum—organizations must navigate a complex web of external considerations that shape how security is governed. In this episode, we explore regulatory requirements (like GDPR, HIPAA, and PCI-DSS), industry standards, and legal obligations that influence security architecture, policies, and practices. We also cover how government agencies, professional associations, a...
Episode 183: Procedures and Playbooks (Domain 5) 16.06.2025 21:31
Procedures and playbooks are the operational backbone of a mature security program—translating policy into detailed, repeatable steps for responding to specific threats or performing security tasks. In this episode, we explain the difference between general procedures (e.g., user onboarding or access review) and incident-specific playbooks (e.g., malware containment or phishing investigation). Pla...
Episode 182: Security Standards and Physical Controls (Domain 5) 16.06.2025 21:25
Standards and controls turn high-level policy into actionable, enforceable security, and in this episode, we explore how physical controls and documented standards create consistent, measurable protection. We discuss the value of security standards like password complexity requirements, encryption levels, and access review intervals that ensure systems operate within secure and compliant configura...
Episode 181: Incident Response Policies and Procedures (Domain 5) 16.06.2025 22:32
An effective incident response program starts with well-defined policies and procedures that guide every action, role, and escalation during a security event. In this episode, we explore the components of an incident response policy—covering scope, roles, definitions, response timelines, and classification levels. We then break down procedures into practical, step-by-step actions that teams follow...
Episode 180: Key Security Policies and Standards (Domain 5) 16.06.2025 22:40
Policies and standards are the written expression of an organization’s security expectations—and in this episode, we explore how they’re developed, communicated, and enforced. We cover essential policies such as Acceptable Use Policies (AUPs), information security policies, disaster recovery policies, and software development lifecycle (SDLC) standards, explaining how each one sets the tone for se...
Episode 179: Introduction to Security Governance (Domain 5) 16.06.2025 22:31
Security governance is the blueprint for how an organization manages its security strategy, aligns it with business goals, and ensures accountability across all levels of operation. In this episode, we introduce the core elements of effective governance, including the development of security policies, acceptable use standards, change management procedures, and incident response planning. Governanc...
Episode 178: Introduction to Domain Five — Security Program Management and Oversight 16.06.2025 24:12
Cybersecurity isn’t just about blocking attacks and managing firewalls. It’s also about building policies, assessing risk, managing vendors, and aligning security with the overall goals of the business. That’s the focus of Domain Five: Security Program Management and Oversight. This domain gives you the big-picture understanding of how security fits into the way organizations function. It teaches...
Episode 177: Packet Captures in Investigations (Domain 4) 16.06.2025 22:43
Packet captures are the most detailed and revealing form of network data available to defenders—showing not just what happened, but exactly how it happened, byte by byte. In this episode, we explain how tools like Wireshark and tcpdump allow analysts to capture and inspect network packets for signs of malicious activity, protocol abuse, data leakage, and command-and-control traffic. We explore how...
Episode 176: Dashboards and Visualization Tools (Domain 4) 16.06.2025 22:10
A well-designed dashboard can turn complex security data into fast, actionable insight—and in this episode, we explore how visualization tools help analysts, engineers, and executives understand the health of their security environments at a glance. We discuss how dashboards consolidate metrics like open vulnerabilities, login anomalies, firewall events, and endpoint alerts into tiles, graphs, and...
Episode 175: Vulnerability Scan Data and Automated Reporting (Domain 4) 16.06.2025 20:48
Vulnerability scan data is only useful when it’s collected, organized, and presented in a way that drives action—and this episode explains how automated reporting transforms raw scan results into operational intelligence. We begin by examining the structure of scan output: severity levels, CVSS scores, affected assets, and remediation recommendations. From there, we explore how automated reporting...
Episode 174: Leveraging Log Data (Part 2) (Domain 4) 16.06.2025 23:29
In this continuation of our log analysis discussion, we shift from collection to interpretation—examining how different data sources support threat detection, forensic investigation, and compliance reporting. We explore how packet capture tools, vulnerability scanners, dashboards, and automated reports enrich raw logs with context, allowing for faster triage and incident understanding. Tools like...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.