Jason Edwards
Certified: The GIAC GISF Audio Course
Welcome to Certified: The ISACA GISF Audio Course. I built this course for people who want a clear, practical path into cybersecurity fundamentals—whether you’re moving into a security role, supporting security from IT or operations, or trying to build a reliable baseline before you specialize. Here’s what you can expect: short, focused lessons that connect concepts to real environments, plain-language explanations that still respect the technical detail, and a steady progression that helps you understand not just what something is, but why it matters. We’ll cover threats, risk, controls, gove...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 15 — Explain Hashing, Integrity, and Secure Password Storage in Digital Trust 14.02.2026 10:51
This episode deconstructs the role of hashing in ensuring data integrity and the critical methods for secure password storage in a modern infrastructure. We define a hash function as a "one-way" mathematical algorithm that produces a unique, fixed-length string of data, explaining why it is impossible to reverse-engineer the original input from the resulting hash. On the GISF exam, you must unders...
Episode 14 — Master Symmetric Encryption Basics for Foundations of Cryptography and Digital Trust 14.02.2026 12:04
Symmetric encryption is a cornerstone of high-speed data protection, and this episode provides a detailed exploration of its mechanics and professional application. We define symmetric cryptography as a system where the same secret key is used for both encryption and decryption, highlighting its efficiency for protecting large volumes of data at rest. You will learn about common algorithms such as...
Episode 13 — Spaced Retrieval: Cyber Risk, Governance, Compliance, and Ethics Memory Sprint 14.02.2026 10:12
This episode utilizes a rapid-fire spaced retrieval format to solidify your knowledge of cyber risk, governance, compliance, and professional ethics. We move through a series of spoken prompts designed to test your recall of previous concepts, such as the difference between policies and standards or the primary goals of regulatory drivers like HIPAA. This "memory sprint" is a critical component of...
Episode 12 — Apply Ethics and Professional Judgment When Security Decisions Get Messy 14.02.2026 11:57
Security professionals are often placed in positions of immense trust, and this episode focuses on applying ethics and professional judgment during complex decision-making scenarios. We discuss the (ISC)² Code of Ethics and similar professional standards as a compass for navigating conflicts of interest or the discovery of sensitive information. The GISF exam frequently tests your ability to choos...
Episode 11 — Navigate Laws, Regulations, and Compliance Drivers that Shape Cyber Risk 14.02.2026 12:23
This episode explores the complex landscape of legal and regulatory requirements that define the boundaries of modern cybersecurity risk management. We examine the critical distinction between mandatory compliance and actual security, highlighting how drivers like the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA) influence organizatio...
Episode 10 — Use Cyber Risk Frameworks to Align Security Work to Business Goals 14.02.2026 11:50
Standardized frameworks provide the professional structure needed to align security operations with overarching business goals, and this episode introduces the primary models used in the industry today. We examine how frameworks like NIST Cybersecurity Framework, ISO 27001, and the CIS Critical Security Controls provide a common language and a repeatable methodology for managing cyber risk. The di...
Episode 9 — Manage and Mitigate Cyber Risk with Practical Control Prioritization 14.02.2026 12:28
In this episode, we move from the theory of risk to the practical reality of management and mitigation through structured control prioritization. We explore how to evaluate a long list of vulnerabilities and decide which ones require immediate technical intervention based on their potential impact on the organization's mission. The discussion introduces the concept of "defense-in-depth," where mul...
Episode 8 — Spaced Retrieval: Foundations of Cybersecurity and Risk Fundamentals Rapid Recall 14.02.2026 10:12
This high-intensity episode is designed to lock in your understanding of cybersecurity foundations and risk management through a rapid-fire spaced retrieval drill. We revisit the core definitions of the CIA Triad, the asset-threat-vulnerability-control mapping, and the primary risk treatment strategies discussed in previous sessions. This active recall exercise forces you to retrieve information f...
Episode 7 — Translate Security Policies, Standards, and Procedures into Everyday Cybersecurity Actions 14.02.2026 12:17
The hierarchy of security documentation forms the operational backbone of a mature program, and this episode explains how to translate policies, standards, and procedures into daily professional actions. We define policies as high-level statements of intent, standards as the mandatory technical requirements used to achieve those policies, and procedures as the step-by-step instructions for impleme...
Episode 6 — Practice Risk Fundamentals: Likelihood, Impact, and Risk Treatment Choices 14.02.2026 11:40
Risk management is the language of executive leadership, and this episode deconstructs the fundamental principles of likelihood, impact, and risk treatment. We explain how to calculate risk by evaluating the probability of a threat occurring against the severity of the resulting damage to the business. The episode details the four primary risk treatment choices: avoidance, transference, mitigation...
Episode 5 — Map Assets, Threats, Vulnerabilities, and Controls with Foundations of Cybersecurity 14.02.2026 11:36
Mastering the relationship between assets, threats, vulnerabilities, and controls is a central requirement of the GISF blueprint, and this episode provides a clinical breakdown of these four pillars. We define an asset as anything of value to the organization and a threat as any potential event that could harm that asset. Vulnerabilities are characterized as specific weaknesses that a threat can e...
Episode 4 — Define Foundations of Cybersecurity and Why Security Matters to Business 14.02.2026 12:48
This episode establishes the theoretical bedrock of the certification by defining the core foundations of cybersecurity and explaining its critical relevance to modern business operations. We introduce the CIA Triad—Confidentiality, Integrity, and Availability—as the primary framework for evaluating every security decision and technical control. The discussion expands on why security is not just a...
Episode 3 — Build a Spoken GISF Study Plan Using Spaced Recall and Indexing 14.02.2026 12:23
Success on the GISF exam requires a disciplined approach to information retention, and this episode focuses on building a study plan centered on spaced recall and effective indexing. We explore the cognitive science behind spaced repetition, which involves revisiting key concepts at increasing intervals to move information into long-term memory. The episode provides a detailed walkthrough of creat...
Episode 2 — Know the Rules: Proctoring, Open-Book Boundaries, and Allowed Resources 14.02.2026 13:28
Navigating the administrative rules of the GISF exam is just as important as mastering the technical domains, as violations can lead to immediate disqualification. This episode clarifies the boundaries of the open-book format, explaining exactly what types of physical resources, such as personal indices and course books, are permitted in the testing center. We describe the role of the proctor in m...
Episode 1 — Orient to GISF Exam Structure, Scoring, Timing, and Question Style 14.02.2026 14:20
This introductory episode provides a comprehensive orientation to the Global Information Assurance Certification Security Fundamentals (GISF) exam, establishing the baseline for your certification journey. We examine the specific anatomy of the test, including the total number of questions, the passing score threshold, and the time management strategies required to navigate the session effectively...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.