Jason Edwards

Certified: The GIAC GCCC Audio Course

GCCC is a control-first security course built for busy professionals who want practical mastery of the CIS Controls v8 and the real-world workflows that make them stick. You’ll learn how to inventory assets and software with confidence, harden configurations without breaking operations, manage vulnerabilities with proof-based closure, and turn logging into outcomes through centralized collection, correlation, and sustainable alerting. The course also covers malware defense as layered prevention plus rapid containment, data protection through classification, access boundaries, and safe retentio...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 9, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Welcome to the GIAC GCCC Audio Course 09.02.2026

If you build, run, or defend systems for a living, you already know the truth: security isn’t one thing you do. It’s a chain of decisions—design, build, deploy, operate, recover—under real constraints. This 90-second trailer is for an audio course that treats cybersecurity like an operational discipline, not a buzzword. You’ll learn how to set recovery objectives that match business reality, prote...

Episode 59 — Validate resilience after fixes with retesting and durable closure evidence 09.02.2026

This final episode focuses on validating resilience after fixes, emphasizing retesting and durable closure evidence so improvements persist beyond a single remediation sprint. You’ll define retesting as confirming that exploited paths are no longer feasible and that compensating controls work as intended, then connect it to exam expectations about verification, continuous control validation, and d...

Episode 58 — Translate pen test findings into remediation priorities and measurable control improvements 09.02.2026

This episode focuses on turning penetration test findings into remediation priorities and measurable improvements, because the real value of testing is how it strengthens controls and reduces future risk. You’ll define the difference between findings that show a specific vulnerability and findings that reveal systemic control gaps, then connect this to exam logic about prioritization, ownership, a...

Episode 57 — Plan penetration tests safely: scope control, rules of engagement, and reporting clarity 09.02.2026

This episode teaches how to plan penetration tests safely and effectively, focusing on scope control, rules of engagement, and reporting clarity that protect operations while producing useful results. You’ll define a penetration test as an authorized simulation of adversary techniques to evaluate controls, not a chaotic “hack everything” exercise, and connect this to exam questions that test gover...

Episode 56 — Improve response capability with lessons learned and continuous program refinement 09.02.2026

This episode explains how to improve incident response capability using lessons learned, because the exam often expects you to treat response as a program that matures through evidence-based refinement. You’ll define lessons learned as a structured review that identifies what happened, what worked, what failed, and what must change in people, process, and technology, without turning into blame. We...

Episode 55 — Execute incident response under pressure: detection, containment, and evidence handling 09.02.2026

This episode focuses on executing incident response under pressure, emphasizing detection confirmation, rapid containment, and careful evidence handling so actions are defensible and effective. You’ll define the early response objectives: stop the bleeding, understand scope, preserve proof, and maintain business operations where possible, which maps directly to exam scenarios that ask for the best...

Episode 54 — Build incident response readiness with roles, playbooks, and communications discipline 09.02.2026

This episode builds incident response readiness as a structured capability that can be executed under stress, which aligns with exam questions that test process clarity and role accountability. You’ll define readiness as having named roles, clear decision rights, and documented playbooks that cover common incident types, while ensuring evidence handling and containment steps are not improvised. We...

Episode 53 — Reinforce skills over time with role-based focus, coaching, and timely feedback 09.02.2026

This episode focuses on reinforcement, because durable security improvement requires repeated practice, coaching, and timely feedback rather than one-time annual training. You’ll define reinforcement as the cycle of reminding, practicing, observing, and correcting, and connect it to exam logic where ongoing validation and continuous improvement matter more than policies alone. We’ll cover role-bas...

Episode 52 — Measure training effectiveness with metrics tied to real risk reduction outcomes 09.02.2026

This episode teaches how to measure security training effectiveness in ways that connect to real risk reduction, which is what exam scenarios often want when they ask how to prove a control is working. You’ll define meaningful metrics that go beyond attendance, such as phishing report rates, reduction in repeated policy violations, faster incident reporting, fewer risky credential behaviors, and i...

Episode 51 — Build awareness programs that change behavior, not just complete training requirements 09.02.2026

This episode focuses on designing security awareness programs that produce measurable behavior change, which is often the underlying goal behind exam questions that reference “training” as a control. You’ll define awareness as building recognition and safer decision-making, and training as developing specific skills, then explain why check-the-box completion rates rarely reduce phishing success, d...

Episode 50 — Monitor third-party risk continuously with signals, assessments, and escalation triggers 09.02.2026

This episode focuses on continuous third-party risk monitoring, because provider posture can change quickly due to acquisitions, new products, outages, or security incidents. You’ll define continuous monitoring as maintaining ongoing visibility into provider risk signals and control performance rather than relying on annual questionnaires. We’ll cover monitoring inputs such as periodic reassessmen...

Episode 49 — Enforce provider accountability through contracts, controls, and ongoing assurance reviews 09.02.2026

This episode explains how to enforce service provider accountability after selection, because third-party risk management fails when controls exist only during onboarding. You’ll define accountability mechanisms such as contractual requirements, security addenda, right-to-audit clauses, breach notification timelines, subcontractor disclosures, and clear responsibility boundaries for shared control...

Episode 48 — Evaluate service providers with due diligence that matches risk and criticality 09.02.2026

This episode teaches third-party due diligence as a risk-matching exercise, because the exam often tests whether you can scale scrutiny based on the provider’s access, data sensitivity, and operational criticality. You’ll define service provider evaluation as assessing security posture, reliability, and governance before onboarding, then connect it to practical questions like what evidence is reas...

Episode 47 — Detect and remediate weaknesses with testing evidence, prioritization, and closure proof 09.02.2026

This episode explains application and system weakness management as a lifecycle that depends on testing evidence, risk-based prioritization, and verified closure rather than optimistic ticket updates. You’ll define weakness detection methods such as static analysis, dynamic testing, dependency scanning, configuration testing, and manual review, and you’ll connect these to exam questions that test...

Episode 46 — Reduce application risk by managing dependencies and patching weak components quickly 09.02.2026

This episode focuses on dependency risk because modern applications rely on third-party libraries, frameworks, containers, and services that can introduce critical vulnerabilities outside your own code. You’ll define dependencies broadly, including open-source packages, internal shared libraries, base images, and hosted service components, then connect that definition to exam scenarios where the r...

Episode 45 — Secure the software lifecycle end-to-end: design, build, deploy, and operate safely 09.02.2026

This episode explains securing the software lifecycle as a continuous set of controls that start at design and extend through build, deployment, and ongoing operation, which aligns closely with control-based exam thinking. You’ll define lifecycle security goals such as reducing defect introduction, preventing tampering, and ensuring changes are traceable, then map those goals to practical practice...

Episode 44 — Prove recoverability with restore tests, integrity checks, and documented results 09.02.2026

This episode focuses on proving recoverability, because the exam frequently distinguishes “we have backups” from “we can restore correctly under pressure.” You’ll define recoverability as the ability to restore required systems and data within stated objectives, with verified integrity and usable outcomes, not merely completed backup jobs. We’ll cover restore testing types, from file-level restore...

Episode 43 — Protect backups as high-value targets: access controls, encryption, and isolation strategy 09.02.2026

This episode explains why backups are prime targets for attackers and how protecting them requires stronger controls than ordinary storage because backups can recreate the entire environment. You’ll define backup security objectives such as confidentiality, integrity, availability, and recoverability, then connect these to exam scenarios involving ransomware, insider threats, and compromised admin...

Episode 42 — Define recovery objectives that fit business reality: RPO, RTO, and scope decisions 09.02.2026

This episode teaches recovery objectives as decision tools that shape how resilient your environment truly is, and how exam questions often test whether you can match objectives to business needs instead of picking the most aggressive option. You’ll define RPO as the maximum tolerable data loss window and RTO as the maximum tolerable downtime window, then explain how scope decisions determine what...

Episode 41 — Retain and dispose of data safely with automation, approvals, and audit evidence 09.02.2026

This episode explains data retention and disposal as lifecycle controls that reduce legal exposure, breach impact, and storage sprawl while preserving what the business truly needs. You’ll define retention as keeping data for a justified period and disposal as verified removal or destruction, then connect both to exam scenarios that test whether controls are enforceable and evidenced, not merely d...

Episode 40 — Protect data with access boundaries, encryption decisions, and controlled sharing patterns 09.02.2026

This episode explains how to protect data by combining access boundaries, encryption decisions, and controlled sharing patterns that reduce accidental exposure and intentional misuse. You’ll define access boundaries as the segmentation of data by sensitivity, ownership, and purpose, then connect that to exam scenarios where the right answer depends on limiting who can access what, from where, and...

Episode 39 — Classify data in practice: sensitivity tiers, handling rules, and real-world exceptions 09.02.2026

This episode teaches data classification as an operational system that drives real handling behaviors, not a theoretical labeling exercise. You’ll define classification as assigning sensitivity tiers based on confidentiality, integrity, and availability needs, then explain how those tiers translate into handling rules like storage locations, access restrictions, encryption requirements, retention,...

Episode 38 — Confirm email and browser protections work with testing and measurable outcomes 09.02.2026

This episode focuses on confirming that phishing and browsing controls actually reduce risk by using testing and measurable outcomes rather than assuming tools are effective. You’ll define testing as controlled validation of control behavior, such as safe phishing simulations, benign attachment tests, and controlled link detonation, and you’ll connect the results to exam expectations around contin...

Episode 37 — Harden web browsing with technical safeguards and safer execution pathways 09.02.2026

This episode explains how to harden web browsing so routine internet use does not become an easy malware delivery channel or credential theft pathway. You’ll define browsing risk in terms of drive-by downloads, malicious scripts, exploit chains, and credential harvesting, then connect those risks to exam questions that emphasize preventative controls and safe defaults. We’ll cover technical safegu...

Episode 36 — Reduce phishing success with email controls that block, warn, and verify safely 09.02.2026

This episode focuses on reducing phishing success by combining blocking, warning, and verification controls that protect users even when messages look legitimate. You’ll define phishing as deception designed to steal credentials, deliver malware, or trigger fraudulent actions, then connect that to exam-style prompts that test layered defenses rather than a single tool. We’ll cover email controls s...

Listen to the Certified: The GIAC GCCC Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.