Jason Edwards
Certified: The GIAC GCCC Audio Course
GCCC is a control-first security course built for busy professionals who want practical mastery of the CIS Controls v8 and the real-world workflows that make them stick. You’ll learn how to inventory assets and software with confidence, harden configurations without breaking operations, manage vulnerabilities with proof-based closure, and turn logging into outcomes through centralized collection, correlation, and sustainable alerting. The course also covers malware defense as layered prevention plus rapid containment, data protection through classification, access boundaries, and safe retentio...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 35 — Improve monitoring outcomes with tuning, validation, and gap-driven coverage fixes 09.02.2026 12:00
This episode teaches how to improve monitoring outcomes by treating detection as an engineered system that needs tuning, validation, and continuous coverage improvement. You’ll define tuning as adjusting detections to reduce false positives while preserving sensitivity to real threats, and validation as proving detections fire when expected through controlled tests and incident replay. We’ll conne...
Episode 34 — Detect threats faster with triage workflows, escalation rules, and response coordination 09.02.2026 12:47
This episode focuses on detection as a process, not a product, showing how triage workflows and escalation rules turn alerts into timely action. You’ll define triage as rapidly determining credibility, scope, and urgency, then connect that to exam scenarios where the correct response is to prioritize containment and evidence preservation based on risk. We’ll cover escalation rules that clarify whe...
Episode 33 — Design network visibility that matters: telemetry selection and baseline behavior modeling 09.02.2026 13:19
This episode teaches how to design network visibility that produces actionable security outcomes instead of overwhelming teams with noise. You’ll define telemetry as the signals collected from networks and devices, then explain which sources are most useful for detecting threats, investigating incidents, and validating controls. We’ll cover selecting telemetry such as flow records, firewall logs,...
Episode 32 — Control network changes safely with baselines, approvals, and rollback discipline 09.02.2026 7:39
This episode focuses on network change control as a security control, not just an IT process, because uncontrolled changes can create exposures faster than scanners can find them. You’ll define a network baseline as an approved “known good” configuration state and explain how baselines support both stability and defensible security posture. We’ll discuss approval workflows that match risk, such as...
Episode 31 — Harden network device management planes to reduce takeover and tampering risk 09.02.2026 8:13
This episode explains how to secure network device management planes so attackers cannot quietly take control of routing, switching, or security enforcement. You’ll define the management plane as the interfaces and services used to administer devices, then connect that concept to exam-style scenarios where compromise happens through exposed admin ports, weak authentication, or mis-scoped managemen...
Episode 30 — Inventory network infrastructure: devices, services, dependencies, and ownership clarity 09.02.2026 8:09
This episode explains network infrastructure inventory as a prerequisite for controlling exposure, troubleshooting outages, and answering exam questions about scope and accountability. You’ll define network infrastructure assets to include routers, switches, firewalls, wireless controllers, load balancers, VPN gateways, DNS and DHCP services, and cloud networking components, then discuss why unman...
Episode 29 — Validate malware defenses with testing, tuning, and incident-driven improvement loops 09.02.2026 8:06
This episode teaches how to validate malware defenses so you can prove protection is real and continuously improving, not merely installed. You’ll define validation as testing and measuring whether controls prevent execution, detect suspicious behavior, and support response actions like isolation and rollback. We’ll discuss testing approaches such as controlled simulations, safe test files, and re...
Episode 28 — Contain malware spread with segmentation, privilege limits, and rapid isolation routines 09.02.2026 9:00
This episode focuses on containment as the difference between a single compromised host and a widespread outage. You’ll define containment as limiting lateral movement and stopping further impact while preserving evidence, then connect that to exam scenarios where the correct action is to isolate quickly rather than chase root cause first. We’ll cover segmentation strategies that reduce reachabili...
Episode 27 — Prevent malware execution using layered controls across endpoints and servers 09.02.2026 9:15
This episode explains malware prevention as a layered control strategy that reduces both initial execution and successful persistence, which is core to control-based exam reasoning. You’ll define prevention layers including secure configuration baselines, patch hygiene, application allowlisting, macro and script controls, attachment filtering, browser protections, and endpoint security platforms t...
Episode 26 — Turn logs into outcomes: alerting strategy, review routines, and noise reduction 09.02.2026 7:44
This episode turns logging into a detection capability by focusing on alerting strategy, review routines, and sustainable noise reduction. You’ll define an alert as a decision-support signal, not a raw event, and you’ll learn how to design alerts around realistic threat scenarios like credential abuse, privilege escalation, malware persistence, and unusual data access. We’ll cover detection engine...
Episode 25 — Centralize and normalize logs for correlation, retention integrity, and fast search 09.02.2026 8:31
This episode explains why centralizing logs is necessary for modern detection and response and how normalization turns scattered records into a usable investigative timeline. You’ll define centralization as collecting logs from endpoints, servers, network devices, identity platforms, and cloud services into a common system, then define normalization as parsing and structuring fields so events can...
Episode 24 — Decide what to log and why: events that power detection and investigations 09.02.2026 9:05
This episode teaches log strategy from first principles so you can answer exam questions about visibility, detection, and investigation readiness. You’ll define logging as the capture of security-relevant events with enough context to support alerting, triage, and incident reconstruction, and you’ll learn how to decide what is “security-relevant” based on threat models and control objectives. We’l...
Episode 23 — Close vulnerabilities with verification evidence, rollback planning, and durable tracking 09.02.2026 5:17
This episode focuses on the part of vulnerability management that separates mature programs from noisy dashboards: closure with proof. You’ll define what it means to “close” a vulnerability, including remediation actions such as patching, configuration change, compensating controls, or retirement of the affected asset, and why closure must be verified rather than assumed. We’ll cover verification...
Episode 22 — Prioritize vulnerabilities with risk context, exploitability, and exposure-driven triage 09.02.2026 6:51
This episode teaches vulnerability prioritization as a decision process that combines severity with real risk, which is a frequent exam theme when multiple “correct” fixes compete for limited time. You’ll define why raw CVSS scores are insufficient by themselves and how risk context reshapes urgency based on asset criticality, internet exposure, privilege level, compensating controls, and known ex...
Episode 21 — Build continuous vulnerability management: coverage, scan cadence, and owner assignment 09.02.2026 6:14
This episode explains how to build a continuous vulnerability management program that the GCCC exam expects you to understand as an operational control, not a one-time scan. You’ll define vulnerability management as the lifecycle of discovering, assessing, prioritizing, remediating, and verifying weaknesses across in-scope assets, with special attention to coverage gaps that make “good results” me...
Episode 20 — Validate access control effectiveness with reviews, testing, and corrective action 09.02.2026 7:41
This episode teaches how to validate access controls so you can detect gaps before attackers or auditors do, a theme that shows up frequently in control-focused exams. You’ll learn what “effective” means: access matches job needs, sensitive resources are protected, privileges are limited, and changes are reviewed and corrected on a schedule. We’ll cover access reviews, including frequency, scoping...
Episode 19 — Build authorization models that match real work without privilege creep 09.02.2026 12:49
This episode focuses on authorization as the practical “what can you do” layer that must align to real job functions while resisting privilege creep over time. You’ll define authorization concepts like roles, permissions, entitlements, and resource scopes, then connect them to exam scenarios where access looks convenient but becomes dangerous when users accumulate rights across transfers and proje...
Episode 18 — Strengthen authentication foundations: factors, session controls, and identity assurance 09.02.2026 15:34
This episode explains authentication as more than “add MFA,” focusing on factors, session controls, and identity assurance that collectively reduce account takeover risk. You’ll define authentication factors, including knowledge, possession, and inherence, and you’ll discuss why factor strength varies depending on implementation, phishing resistance, and recovery pathways. For the exam, you’ll lea...
Episode 17 — Deprovision accounts cleanly to eliminate orphaned access and lingering entitlements 09.02.2026 12:05
This episode covers deprovisioning as a high-impact security control that reduces exposure after employees change roles, leave the organization, or when services are retired. You’ll define orphaned access as credentials and entitlements that remain active without a valid owner, then connect that to common exam scenarios where former users still have VPN access, cloud keys, or group memberships tha...
Episode 16 — Provision accounts safely with approvals, role fit, and minimum privilege intent 09.02.2026 13:21
This episode focuses on secure account provisioning as a control that prevents future incidents by getting access right at the start. You’ll learn how approvals should reflect business justification and role fit, not informal requests, and how to document intent so access is defensible and reviewable later. We’ll define minimum privilege as granting only the permissions needed for expected tasks,...
Episode 15 — Clarify account types and lifecycles: user, admin, service, shared, and temporary 09.02.2026 15:56
This episode breaks down account types and lifecycles so you can answer identity questions cleanly and design safer access in real environments. You’ll define standard user accounts, privileged admin accounts, service accounts, shared accounts, and temporary accounts, and you’ll connect each type to its typical risks, management needs, and audit expectations. For the exam, you’ll focus on recogniz...
Episode 14 — Prove configuration compliance with sampling, evidence, and exception governance 09.02.2026 10:11
This episode focuses on proving configuration compliance in ways that stand up to scrutiny, which is a common exam angle: the difference between claiming compliance and demonstrating it. You’ll learn how compliance evidence is created through repeatable checks, documented scope, and results that tie back to specific baseline requirements. We’ll discuss when sampling is acceptable, how to choose a...
Episode 13 — Control configuration drift with monitoring, remediation workflows, and change discipline 09.02.2026 10:16
This episode teaches configuration drift as an operational reality and shows how to control it without freezing the business. You’ll define drift as deviation from an approved baseline over time, caused by patches, manual fixes, emergency changes, tool updates, or unauthorized modifications, and you’ll connect it to exam themes like continuous control validation and lifecycle governance. We’ll cov...
Episode 12 — Design secure configuration baselines that are measurable, repeatable, and realistic 09.02.2026 9:30
This episode focuses on configuration baselines as the foundation for hardening that can be verified, maintained, and defended under audit. You’ll define a baseline as a documented, approved set of secure settings for a specific asset class, such as Windows workstations, Linux servers, network devices, or cloud workloads, and you’ll connect that definition to exam questions that test “policy versu...
Episode 11 — Prevent unapproved execution with allowlisting logic and tightly governed exceptions 09.02.2026 9:55
This episode explains how application allowlisting reduces attack surface by controlling what is permitted to execute, not just what is blocked after detection. You’ll define allowlisting in practical terms, including path rules, publisher signatures, hashes, and policy scopes that apply differently to servers, endpoints, and privileged admin workstations. For the exam, you’ll focus on the intent:...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.