Jason Edwards
Certified: The GIAC GISF Audio Course
Welcome to Certified: The ISACA GISF Audio Course. I built this course for people who want a clear, practical path into cybersecurity fundamentals—whether you’re moving into a security role, supporting security from IT or operations, or trying to build a reliable baseline before you specialize. Here’s what you can expect: short, focused lessons that connect concepts to real environments, plain-language explanations that still respect the technical detail, and a steady progression that helps you understand not just what something is, but why it matters. We’ll cover threats, risk, controls, gove...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Welcome to the GIAC GISF Audio Course 15.02.2026 0:57
If cybersecurity feels important but confusing, you’re not alone—and you don’t need a computer science degree to get traction. Certified: The ISACA GISF Audio Course is built for busy people who want a clear, practical foundation and a confident path into the GISF certification. In about a minute at a time, you’ll learn how threats actually unfold, how risk gets discussed and measured, and which c...
Episode 64 — Exam-Day Tactics: Calm Pacing, Smart Elimination, and Confident Final Checks 14.02.2026 9:17
The final episode of the series focuses on the tactical habits and mindset required to perform at your peak on exam day. We discuss a three-pass approach to managing your time, where you secure easy wins first before returning to complex scenarios and reference checks. The discussion outlines elimination rules that allow you to remove obviously wrong answers quickly, increasing your statistical pr...
Episode 63 — Essential Terms: Plain-Language Glossary for Fast Recall Under Pressure 14.02.2026 15:23
This episode deconstructs essential security terms into plain language to ensure fast recall during high-pressure scenarios on the exam or in the field. We define core concepts—including asset, threat, vulnerability, and control—through a consistent narrative, and explain risk management terms like likelihood, impact, and residual risk. The discussion clarifies the differences between authenticati...
Episode 62 — Exam Acronyms: High-Yield Audio Reference for the GISF Blueprint 14.02.2026 10:41
Building acronym fluency is a primary requirement for navigating the GISF blueprint, and this episode serves as a high-yield audio reference for the most common shorthand used in the exam. We cover identity acronyms like MFA, IAM, and RBAC, as well as networking fundamentals including DNS, DHCP, TCP, and UDP. The discussion extends to cryptographic terms like PKI and CA, explaining how they enable...
Episode 61 — Spaced Retrieval: Web Risks, Roles, and Awareness Concepts in One Drill 14.02.2026 10:12
This episode integrates the human, procedural, and technical elements of cybersecurity into a high-intensity spaced retrieval drill focused on web security, organizational roles, and awareness. We move through rapid-fire recall prompts where you must identify common web risks—such as cross-site scripting or session hijacking—and match them to specific prevention habits like input validation and se...
Episode 60 — Build Security Awareness Habits that Reduce Real Risk Across Teams 14.02.2026 10:30
Building security awareness is about changing routine behaviors to reduce avoidable mistakes and organizational exposures. This episode explains awareness not as a one-time training event, but as a collection of professional habits like verifying requests and reporting suspicious activity. We describe the core habits of a resilient culture: slowing down to recognize emotional triggers, using MFA f...
Episode 59 — Coordinate Security Roles to Strengthen Organizational Posture and Shared Accountability 14.02.2026 11:17
Improving security outcomes requires knowing exactly who is responsible for specific tasks across the enterprise, and this episode focuses on coordinating security roles for shared accountability. We describe security roles as duties that span technical administrators, business leaders, and individual employees. The discussion explains why clear ownership is necessary to prevent defensive gaps and...
Episode 58 — Identify Fundamental Web Security Risks in Security Foundations and Awareness 14.02.2026 11:11
Many modern cyber attacks begin within the browser, making the identification of fundamental web security risks a vital professional skill. This episode explains web risk as the byproduct of trusting unvalidated inputs, insecure session handling, and third-party scripts. We describe common risks such as weak authentication, unsafe file uploads, and the danger of session hijacking leading to accoun...
Episode 57 — Reduce Connected Device and IoT Risk Through Isolation, Updates, and Monitoring 14.02.2026 12:07
The Internet of Things (IoT) represents a significant expansion of the attack surface, and this episode focuses on reducing the risks associated with these often unmanaged connected devices. We define IoT risk as being driven by limited security features, hardcoded passwords, and long lifecycles that exceed manufacturer support. The discussion explains isolation as the primary defense, involving t...
Episode 56 — Secure Data in Cloud Storage and SaaS Workflows Without Losing Control 14.02.2026 11:53
This episode examines how to maintain control over organization data within cloud storage and Software as a Service (SaaS) workflows. We explain that cloud storage risk often stems from misconfigured permissions and uncontrolled external sharing settings. The discussion describes the risks inherent in SaaS collaboration, such as the use of private sharing links that may not stay private over time....
Episode 55 — Harden Cloud Identity, Keys, and Access Guardrails for Data Protection 14.02.2026 11:15
In the cloud, identity is the new perimeter, and this episode focuses on hardening cloud access by securing identities, keys, and implementing automated guardrails. We explain why cloud identity is uniquely powerful because it acts as the primary control plane for all technical resources. We define keys and tokens as critical secrets that allow services to communicate, and we describe the danger o...
Episode 54 — Adopt the Shared Responsibility Mindset for Securing Connected and Cloud-Based Environments 14.02.2026 11:12
Securing modern cloud and connected environments requires a clear understanding of the shared responsibility model, which divides security duties between the service provider and the customer. This episode defines the framework where providers manage the underlying infrastructure and physical security while customers retain ownership of data protection, identity, and configurations. We describe th...
Episode 53 — Spaced Retrieval: Post-Exploitation Tactics and Detection Cues Rapid Review 14.02.2026 10:43
This high-intensity spaced retrieval session reinforces the post-exploitation story, ensuring you can rapidly recognize signs of escalation, lateral movement, and data theft. We move through spoken drills that require you to define privilege escalation and identify high-risk target identities, such as domain administrators or service accounts. This session forces you to recall the meaning of inter...
Episode 52 — Recognize Data Exfiltration Patterns and Advanced Threat Techniques at Scale 14.02.2026 12:20
Data exfiltration represents the final, often most damaging stage of a cyber attack, and this episode focuses on recognizing the technical patterns associated with unauthorized data movement. We define exfiltration as the removal of sensitive information from trusted organizational boundaries through paths like web uploads, cloud sharing, or encrypted tunnels. A key concept is the staging phase, w...
Episode 51 — Understand Command and Control and Living Off the Land Stealth 14.02.2026 11:51
This episode explores how attackers maintain a persistent connection to compromised systems while evading traditional detection through command and control (C2) channels and living off the land (LotL) techniques. We define command and control as the remote communication infrastructure used by an adversary to direct infected hosts and receive data. A critical professional concept is why attackers u...
Episode 50 — Trace Lateral Movement and Internal Discovery in Advanced Threat Techniques 14.02.2026 12:02
In this episode, we trace the methodical patterns of lateral movement and internal discovery used by advanced threat actors to navigate your network. We define lateral movement as moving from one system to another internally and explain internal discovery as the act of mapping hosts, shares, and services. The discussion focuses on why discovery typically precedes movement, as the attacker seeks th...
Episode 49 — Identify Privilege Escalation and Credential Theft in Post-Exploitation Techniques 14.02.2026 12:38
Recognizing how attackers expand control after an initial entry is a primary focus of this episode on privilege escalation and credential theft. We define privilege escalation as gaining higher rights than initially obtained and credential theft as capturing secrets to impersonate trusted identities. The discussion describes common escalation paths like misconfigured services and token abuse, high...
Episode 48 — Spaced Retrieval: Defensive Technologies Recall and Triage Decision Practice 14.02.2026 11:42
This spaced retrieval session is designed to turn your defensive tools into instincts through rapid recall and practical triage decision practice. We move through spoken drills that challenge you to define the differences between logs, telemetry, and alerts and explain the core purpose of a S I E M. This session forces you to apply the unique value of E D R and N D R to a suspicious login or malwa...
Episode 47 — Leverage Automation and AI in Defense While Avoiding Dangerous Overtrust 14.02.2026 12:38
In this episode, we focus on leveraging automation and A I to scale your defense while maintaining the professional judgment needed to avoid dangerous overtrust. We define automation as the repeatable actions that reduce manual response time and A I as the pattern recognition that supports human decision-making. The discussion explains where these technologies fit—such as in alert enrichment, tria...
Episode 46 — Understand EDR and NDR Visibility for Defensive Technologies and Emerging Intelligence 14.02.2026 12:00
Deep visibility into both hosts and networks is critical for modern defense, and this episode examines the unique roles of E D R and N D R in the technology stack. We define Endpoint Detection and Response (E D R) as monitoring for process and file behavior on individual machines and Network Detection and Response (N D R) as the analysis of internal traffic patterns. The discussion explains why vi...
Episode 45 — Work Smarter with SIEM Correlation and Scalable Alert Triage Workflows 14.02.2026 11:30
This episode deconstructs how to work smarter by utilizing Security Information and Event Management (S I E M) correlation and scalable triage workflows to reduce alert fatigue. We define a S I E M as the central repository for collecting and searching events across the enterprise and explain correlation as the logic that links these events to spot hidden patterns. Triage is described as the profe...
Episode 44 — Build a Defensive Technologies Stack from Logs, Telemetry, and Alerts 14.02.2026 12:47
Building a manageable defense requires a clear visibility stack, and this episode explores the roles of logs, telemetry, and alerts in creating a measurable security posture. We define logs as discrete records of past events used for auditing and telemetry as the richer, continuous behavior signals from processes and networks. Alerts are described as the prioritized signals that require human or a...
Episode 43 — Spaced Retrieval: Threat Frameworks Recap Through Rapid Adversary Story Prompts 14.02.2026 13:02
This high-intensity spaced retrieval session focuses on fusing various threat frameworks into a single, cohesive narrative that you can recall quickly under pressure. We move through rapid-fire story prompts that require you to map technical evidence to M I T R E A T T A C K tactics, identify Kill Chain stages, and connect Diamond Model elements to real-world scenarios. This session forces you to...
Episode 42 — Prioritize Intelligence: Indicators, Observables, and the Pyramid of Pain 14.02.2026 17:21
Prioritizing security efforts is essential in a data-heavy environment, and this episode examines how to focus on intelligence that truly changes attacker behavior using the Pyramid of Pain. We define an indicator as a clue suggesting malicious activity and an observable as raw data, such as a log or hash, that provides the evidence for analysis. The discussion centers on the Pyramid of Pain, whic...
Episode 41 — Anticipate Next Moves with Kill Chain and Diamond Model Threat Frameworks 14.02.2026 14:52
In this episode, we explore how to predict attacker steps by utilizing structured models like the Cyber Kill Chain and the Diamond Model of Intrusion Analysis. We define the Kill Chain as a linear sequence of stages an attacker must complete—from reconnaissance and weaponization to actions on objectives—providing defenders with multiple opportunities to detect and disrupt the mission. Complementin...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.