Jason Edwards
Certified: The GIAC GISF Audio Course
Welcome to Certified: The ISACA GISF Audio Course. I built this course for people who want a clear, practical path into cybersecurity fundamentals—whether you’re moving into a security role, supporting security from IT or operations, or trying to build a reliable baseline before you specialize. Here’s what you can expect: short, focused lessons that connect concepts to real environments, plain-language explanations that still respect the technical detail, and a steady progression that helps you understand not just what something is, but why it matters. We’ll cover threats, risk, controls, gove...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 40 — Map TTPs Using MITRE ATT&CK Within Adversary Analysis and Threat Frameworks 14.02.2026 11:26
Standardized language is the foundation of modern threat analysis, and this episode focuses on mapping Tactics, Techniques, and Procedures (TTPs) using the MITRE ATT&CK framework. We define TTPs as the specific actions and operational habits that describe how an attacker achieves their goals, such as initial access or persistence. The discussion explains how the MITRE ATT&CK matrix organiz...
Episode 39 — Turn Attacker Behavior into Clear Notes with Adversary Analysis Methods 14.02.2026 12:01
Structured documentation is essential for a coordinated response, and this episode explores how to turn messy attacker behavior into clear, actionable notes using adversary analysis methods. We define adversary analysis as the professional process of understanding an attacker's goals, technical steps, and capabilities. The discussion explains how building a chronological timeline from the first si...
Episode 38 — Spaced Retrieval: Initial Access Techniques and Defensive Clues for Quick Recognition 14.02.2026 13:34
This spaced retrieval session is designed to make attacker behaviors familiar so you can recognize them under the high stress of a real-world incident. We move through spoken drills that require you to recall reconnaissance stages, phishing triggers, and exploitation paths from memory. This session forces you to apply your knowledge to rapid-fire scenarios, such as deciding what to check first dur...
Episode 37 — Detect Malware Delivery, Persistence Footholds, and Early Intrusion Indicators 14.02.2026 13:05
Early detection is the key to minimizing the impact of a breach, and this episode focuses on spotting malware delivery and the persistence footholds an intruder uses to stay in your network. We describe common delivery paths like attachments and drive-by downloads, explaining how attackers establish persistence to survive system reboots. The discussion details early indicators of compromise, such...
Episode 36 — Spot Exploitation Paths Through Vulnerabilities, Misconfigurations, and Weak Credentials 14.02.2026 15:19
Attackers turn technical weaknesses into authorized access with surprising speed, and this episode deconstructs the exploitation paths of vulnerabilities, misconfigurations, and weak credentials. We define a vulnerability as a software weakness that enables unintended behavior and a misconfiguration as an insecure setting that creates avoidable exposure. The discussion explains the risk of weak cr...
Episode 35 — Defend Against Phishing and Social Engineering as Initial Access Gateways 14.02.2026 12:32
The human element is often the most targeted link in the security chain, and this episode focuses on defending against phishing and social engineering as primary initial access gateways. We define phishing as deceptive messaging aimed at stealing access or data, delivered through channels like email, text, and voice. The discussion describes the psychological triggers attackers use, such as urgenc...
Episode 34 — Recognize Intrusion and Initial Access Techniques from Recon to Targeting 14.02.2026 12:17
Recognizing the early stages of a cyber attack is vital for a proactive defense, and this episode explores the transition from reconnaissance to specific targeting. We define reconnaissance as the information-gathering phase that occurs before any direct interaction with your systems, utilizing both passive public sources and active scanning. The discussion describes how attackers map exposed serv...
Episode 33 — Spaced Retrieval: Identity, Access, and DLP Fast Recall with Mini Scenarios 14.02.2026 10:06
This high-intensity spaced retrieval session is designed to lock in your understanding of identity, access control, and Data Loss Prevention (DLP) through rapid-fire mini scenarios. We move through spoken drills that require you to recall the differences between authentication and authorization and to explain the goals of least privilege and RBAC. This session forces you to apply your knowledge to...
Episode 32 — Deploy Data Loss Prevention Concepts: Purpose, Types, and Integration with IAM 14.02.2026 11:57
Data Loss Prevention (DLP) acts as a final safety net for sensitive information, and this episode deconstructs its purpose, types, and integration with Identity and Access Management (IAM). We define DLP as a set of controls designed to detect and stop risky data movement across endpoints, email, cloud storage, and networks. The discussion describes the specific data classes targeted by DLP, such...
Episode 31 — Control Identity Lifecycle: Provisioning, Deprovisioning, and Privileged Access Management 14.02.2026 12:19
This episode examines the critical phases of the identity lifecycle, focusing on the professional management of accounts from initial creation to final removal. We define provisioning as the process of quickly assigning baseline access to new identities and deprovisioning as the prompt removal of rights when a role ends. Understanding why orphaned accounts—those left active after an employee leave...
Episode 30 — Clarify Authorization Decisions Using RBAC, ABAC, and Least Privilege Thinking 14.02.2026 12:50
Once an identity has been verified, the next critical step is determining what they are allowed to do, and this episode clarifies authorization decisions using R B A C, A B A C, and the principle of least privilege. We define Role-Based Access Control (R B A C) as a system where permissions are assigned to specific job roles, and Attribute-Based Access Control (A B A C) as a more granular method t...
Episode 29 — Strengthen Identity, Access and Data Protection with Modern Authentication and MFA 14.02.2026 12:27
Identity is the new perimeter in cybersecurity, and this episode focuses on strengthening data protection through the use of modern authentication and Multi-Factor Authentication (M F A). We define the three primary "factors" of authentication—something you know, something you have, and something you are—and explain why combining them significantly reduces the risk of credential compromise. The di...
Episode 28 — Spaced Retrieval: Network Security Architecture Controls and Common Misconfigurations 14.02.2026 14:45
This spaced retrieval session is dedicated to reinforcing your command of network security architecture controls and the common misconfigurations that can lead to organizational breaches. We move through a spoken drill that requires you to recall the functions of firewalls, proxies, and V P Ns, and to identify the risks associated with "flat" networks or unencrypted management protocols. This sess...
Episode 27 — Operationalize Zero Trust Principles in Modern Network Security and Architecture 14.02.2026 11:52
The traditional "castle-and-moat" security model is no longer sufficient, and this episode explores the operationalization of Zero Trust principles in modern network architecture. We define Zero Trust as a strategic framework based on the core philosophy of "Never Trust, Always Verify," where every access request is continuously authenticated and authorized regardless of its origin. The discussion...
Episode 26 — Secure Remote Access with VPNs and Encrypted Tunnels Without Confusion 14.02.2026 11:55
Remote work has made secure connectivity a primary business requirement, and this episode focuses on operationalizing Virtual Private Networks (V P N) and encrypted tunnels with professional precision. We define a V P N as a secure "tunnel" that encapsulates and encrypts traffic as it moves over an untrusted public network, ensuring the confidentiality and integrity of the data. You will learn abo...
Episode 25 — Choose Firewalls, Proxies, and Filtering Strategies in Network Security Architecture 14.02.2026 14:31
Selecting the right defensive tools is a critical professional skill, and this episode evaluates the different types of firewalls, proxies, and filtering strategies available in modern network security architecture. We compare stateless and stateful packet inspection, explaining how stateful firewalls track the "context" of a connection to make more intelligent permit or deny decisions. The discus...
Episode 24 — Design Network Security and Architecture with Segmentation and Security Zones 14.02.2026 11:41
Strategic architectural choices are the first line of defense in an enterprise, and this episode focuses on designing network security through the use of segmentation and security zones. We define network segmentation as the practice of dividing a broad network into smaller, isolated subnetworks to contain threats and limit the "blast radius" of a potential compromise. The discussion introduces th...
Episode 23 — Spaced Retrieval: Network Communication Essentials as a Spoken Traffic Walkthrough 14.02.2026 9:51
This interactive episode utilizes a spoken traffic walkthrough to reinforce the network communication essentials required for the G I S F blueprint through high-intensity spaced retrieval. We move through a series of mental scenarios, such as tracing a packet from a browser request through D N S resolution and a T C P handshake to a final web server response. This active recall drill forces you to...
Episode 22 — Tell the Story of TCP, UDP, and Web Communication Handshakes 14.02.2026 15:57
Reliable data transport is the backbone of digital communication, and this episode tells the story of the Transmission Control Protocol (T C P) and the User Datagram Protocol (U D P) through the lens of their unique handshake mechanics. We deconstruct the T C P three-way handshake—S Y N, S Y N-A C K, and A C K—which establishes a formal, connection-oriented session to ensure every packet arrives i...
Episode 21 — Decode DNS and DHCP Mechanics That Help Devices Find Each Other 14.02.2026 12:55
This episode explores the essential protocols that manage how devices identify themselves and locate others across a network, specifically focusing on the Domain Name System (D N S) and the Dynamic Host Configuration Protocol (D H C P). We define D N S as the service that translates human-readable hostnames into the numerical I P addresses required for routing, acting essentially as the internet's...
Episode 20 — Grasp IP Addressing and Routing Paths in Foundations of Network Communication 14.02.2026 11:56
This episode explores the technical mechanics of IP addressing and the routing paths that allow data to navigate the global network infrastructure. We define the structure of IPv4 and IPv6 addresses, explaining the role of the subnet mask in dividing a network into smaller, manageable segments. You will learn how a router uses its routing table to make high-speed decisions about the "next hop" for...
Episode 19 — Build a Mental Model of OSI and TCP IP Data Flow 14.02.2026 12:26
Understanding how data flows through a network is a fundamental requirement of the GISF blueprint, and this episode focuses on building a clear mental model using the OSI and TCP/IP models. We deconstruct the seven layers of the OSI model—from the Physical layer to the Application layer—explaining the specific role and protocol found at each level. The discussion compares this to the four-layer TC...
Episode 18 — Spaced Retrieval: Cryptography and Digital Trust Concepts You Must Recall 14.02.2026 11:07
This rapid recall session is dedicated to reinforcing your understanding of the complex cryptographic and digital trust concepts required for the GISF exam. We move through a spoken drill that challenges you to define the differences between symmetric and asymmetric encryption and to explain how digital signatures provide non-repudiation. This session acts as a mental bridge, ensuring that the tec...
Episode 17 — Demystify Certificates, PKI, and Trust Chains that Power Secure Communication 14.02.2026 11:07
The Public Key Infrastructure (PKI) acts as the trust engine of the digital world, and this episode demystifies the certificates and trust chains that secure our online interactions. We define a digital certificate as a technical document that binds a public key to a specific identity, and we explain the role of the Certificate Authority (CA) as the trusted third party that signs these documents....
Episode 16 — Understand Asymmetric Crypto, Key Pairs, and Digital Signatures for Trust 14.02.2026 10:57
Asymmetric cryptography solves the key distribution problem through the use of mathematically linked public and private key pairs, a concept we explore in-depth in this episode. We explain how data encrypted with a public key can only be decrypted by the corresponding private key, enabling secure communication between parties who have never met. The discussion expands into digital signatures, whic...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.