Dr. Jason Edwards

Certified: The CRISC Audio Course

Education EN ↓ 94 episodes

The Bare Metal Cyber CRISC Audio Course is your complete, exam-focused companion for mastering the Certified in Risk and Information Systems Control (CRISC) certification. Built for IT and cybersecurity professionals, this Audio Course transforms ISACA’s CRISC domains into clear, structured, and practical lessons that make complex risk concepts approachable and actionable. Each episode covers essential areas such as risk governance, IT risk assessment, risk response and reporting, and control monitoring—delivering the insight and structure you need to succeed. Whether you’re studying on the go...

Author

Dr. Jason Edwards

Category

Education

Podcast website

baremetalcyber.com

Latest episode

Oct 14, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Welcome to the ISACA CRISC 14.10.2025

Dive into a fast, no-fluff overview of what this podcast delivers, who it’s for, and how each episode helps you level up with practical, real-world takeaways. In this trailer, you’ll hear the show’s promise, the format you can expect, and a sneak peek at the kinds of stories, tips, and expert insights coming your way. Hit follow to get new episodes as they drop and start listening smarter from day...

Episode 93: Evaluating Business Practices Alignment with Risk Management and Security Frameworks 05.07.2025

Alignment is the final step toward risk maturity. In this capstone episode, we explore how to evaluate whether business practices support or undermine formal risk management and information security frameworks. You’ll learn how to detect misalignments, recommend improvements, and support compliance initiatives. This topic is a favorite for comprehensive exam questions that blend governance, securi...

Episode 92: Reporting Control Information and Supporting Risk-Based Decisions 05.07.2025

Controls are only valuable if their performance is understood. This episode focuses on how to report control-related data—such as testing results, KCI trends, and implementation updates—to support decision-making. You’ll learn how to interpret control reporting in context and how it influences risk posture and treatment adjustments. Expect to apply this knowledge in exam items involving dashboards...

Episode 91: Reporting Risk Information to Stakeholders 05.07.2025

Clear, timely risk reporting supports informed decision-making at every level. In this episode, we explain how to tailor risk reports for different audiences, from executive boards to process owners. You’ll learn best practices for content clarity, escalation protocols, and aligning reports with organizational priorities. These skills are often tested in CRISC scenarios that evaluate your ability...

Episode 90: Reviewing Control Assessments for Effectiveness and Maturity 05.07.2025

Mature organizations regularly review their control environment. In this episode, we cover how CRISC professionals assess whether controls are effective, scalable, and aligned with enterprise goals. You’ll learn about assessment techniques, maturity models, and reporting strategies. This material directly supports your ability to analyze real-world scenarios on the exam where continuous improvemen...

Episode 89: Monitoring and Analyzing KPIs and KCIs 05.07.2025

Once performance and control indicators are established, continuous monitoring is essential. This episode explains how to track KPI and KCI trends, detect anomalies, and report on performance across business units. You’ll also learn how these metrics support strategic decision-making. Expect to use this material when answering questions that focus on performance management and control effectivenes...

Episode 88: Collaborating with Control Owners on KPIs and KCIs Identification 05.07.2025

Key Performance Indicators and Key Control Indicators help measure the health of processes and controls. In this episode, we discuss how CRISC professionals work with control owners to define metrics that reflect performance, resilience, and reliability. These indicators are often referenced in exam questions that test your ability to select appropriate metrics and interpret control data effective...

Episode 87: Monitoring and Analyzing Key Risk Indicators (KRIs) 05.07.2025

KRIs are only useful when monitored and interpreted correctly. This episode walks through how to track, evaluate, and act on risk indicator trends. You’ll also learn how to detect deviations from risk appetite and escalate appropriately. Mastering KRI interpretation is essential for Domain 3 and 4 questions that test your ability to manage emerging threats and assess residual risk conditions.   Re...

Episode 86: Defining and Establishing Key Risk Indicators (KRIs) 05.07.2025

Key Risk Indicators help detect emerging risks before they escalate. In this episode, you’ll learn how to define KRIs that are specific, measurable, and aligned to business impact. We’ll explore how to select thresholds, determine data sources, and connect KRIs to strategic objectives. Expect to use this knowledge in CRISC exam questions that test proactive monitoring and early-warning capabilitie...

Episode 85: Validating Execution of Risk Responses Against Risk Treatment Plans 05.07.2025

Risk response without verification is a recipe for gaps. This episode teaches you how to validate that risk treatment plans have been carried out as intended. You’ll explore evidence-gathering techniques, stakeholder coordination, and response monitoring—skills needed to close the loop between risk identification and risk mitigation. This topic is especially important for scenario-based exam items...

Episode 84: Collaborating with Control Owners: Control Implementation and Maintenance 05.07.2025

A strong design isn’t enough—controls must be implemented and sustained. This episode shows how to support control owners through implementation, ongoing operations, documentation, and updates. You'll also learn how to monitor control lifecycles and assess when adjustments are needed. This is essential for mastering questions related to control maturity, continuous improvement, and treatment effec...

Episode 83: Collaborating with Control Owners: Control Selection and Design 05.07.2025

Designing effective controls is a team effort. In this episode, we focus on how to work with control owners to select appropriate control types and design them to fit operational needs. You’ll learn how business context, system complexity, and risk level influence control design—an area frequently tested in Domain 3 and 4 questions involving technical decision-making and control architecture.   Re...

Episode 82: Collaborating with Risk Owners: Developing Risk Treatment Plans 05.07.2025

Risk treatment plans must reflect ownership, accountability, and alignment with the organization's overall strategy. This episode walks through how CRISC professionals collaborate with risk owners to define actions, timelines, and success metrics. You’ll learn how treatment plans transition from planning to execution—an essential skill tested in questions about follow-through and control accountab...

Episode 81: Facilitating Stakeholder Selection of Recommended Risk Responses 05.07.2025

Stakeholder engagement is critical when selecting the most appropriate response to a risk. In this episode, we explore how CRISC professionals guide decision-makers through treatment options, balancing risk appetite, resource constraints, and business goals. You’ll learn how to structure these conversations and document decisions. This topic supports your ability to answer questions about governan...

Episode 80: Reviewing Risk and Control Analysis for Gaps Assessment 05.07.2025

After controls and risks have been analyzed, gaps become clear. This episode focuses on reviewing results to identify missing safeguards, ineffective responses, and misalignments with business needs. You’ll learn how to translate analysis into practical insights, and how CRISC expects you to use this knowledge to recommend action or escalate issues. These judgment calls are key to many exam questi...

Episode 79: Identifying and Evaluating Effectiveness of Existing Controls 05.07.2025

Controls are only valuable if they work. In this episode, we explain how to identify current controls across systems and processes and how to evaluate their design and operational effectiveness. You'll also learn techniques to identify gaps, overlaps, and redundancies—skills you'll need to analyze real-world scenarios and propose improvements. This is a core capability on the CRISC exam.   Ready t...

Episode 78: Conducting a Comprehensive IT Risk Assessment 05.07.2025

Risk assessments must be structured, repeatable, and aligned with business needs. This episode walks through how to conduct a comprehensive assessment, including risk identification, impact analysis, likelihood estimation, and prioritization. You’ll learn how to connect all the components into a cohesive evaluation that feeds into treatment planning—exactly what ISACA tests in Domain 2 and 3.   Re...

Episode 77: Promoting a Risk-Aware Culture through Security Awareness Training 05.07.2025

Culture shapes risk behavior. In this episode, we look at how CRISC professionals help promote a risk-aware culture by supporting training programs and awareness campaigns. You'll learn how these efforts reduce human error, improve policy compliance, and reinforce security behaviors. This topic supports both Domain 1 and 4 content and is often tested through organizational behavior scenarios.   Re...

Episode 76: Facilitating Identification of Risk Appetite and Tolerance 05.07.2025

This episode focuses on helping stakeholders define and document risk appetite and tolerance—core elements of strategic alignment. You’ll learn how to facilitate discussions that clarify how much risk the organization is willing to accept and under what conditions. These concepts appear frequently in questions that test your ability to translate strategic intent into operational limits and treatme...

Episode 75: Establishing and Maintaining the IT Risk Register 05.07.2025

The risk register is a living document that tracks an organization’s risk exposure. In this episode, we explore how to build and maintain a complete, dynamic risk register. You’ll learn to define attributes like likelihood, impact, ownership, and treatment status—and how CRISC uses the register to tie together governance, assessment, and reporting practices across all domains.   Ready to start you...

Episode 74: Establishing Accountability Through Risk and Control Ownership 05.07.2025

Without clear ownership, risk management breaks down. This episode shows you how to assign responsibility for risks and controls within the organization, ensuring accountability and follow-through. You'll learn how ownership affects governance, reporting, and response—and how ISACA expects you to spot accountability gaps in exam scenarios. This topic bridges governance and operational execution.  ...

Episode 73: Evaluating Threats, Vulnerabilities, and Risks to Develop IT Risk Scenarios 05.07.2025

Risk scenarios make risks measurable and actionable. This episode explains how to build effective scenarios using threat and vulnerability information, asset dependencies, and business objectives. You’ll learn the structure of a strong risk scenario, and how CRISC expects you to apply them to risk registers and assessments. Expect to see this tested heavily in practical, real-world question format...

Episode 72: Identifying Threats and Vulnerabilities to People, Processes, and Technology 05.07.2025

Threats and vulnerabilities are the building blocks of risk—and CRISC candidates must assess all three layers: people, processes, and technology. This episode walks through methods to identify common risk sources and how to prioritize them. You'll gain the skills to interpret threat vectors and weak points within the organization, essential for scenario-based questions in risk identification and a...

Episode 71: Identifying Potential or Realized Impacts of IT Risk 05.07.2025

Understanding how IT risks impact business objectives is central to the CRISC exam. In this episode, we explore how to recognize both potential and actual consequences of risk events. You’ll learn to evaluate impacts across financial, operational, reputational, and compliance dimensions. This topic shows up frequently in questions that require interpreting risk scenarios and estimating business co...

Episode 70: Collecting and Reviewing Organization’s Business and IT Information 05.07.2025

This supporting task is foundational: you can’t manage risk without understanding your environment. In this episode, you’ll learn how to gather and evaluate information about business processes, IT systems, and organizational context. We walk through techniques for mapping assets, identifying dependencies, and building a full picture of the risk landscape—a crucial skill area for all CRISC domains...

Listen to the Certified: The CRISC Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.