Jason Edwards
Certified: The GIAC GLEG Audio Course
Welcome to Certified: The GIAC GLEG Certification Audio Course. I’m your guide for this series, and my job is to make the legal side of cybersecurity feel clear, practical, and usable, even if you’ve never taken a law class. In the real world, security work doesn’t happen in a vacuum. The moment an incident becomes an investigation, or a monitoring tool becomes a privacy concern, legal rules start shaping what you can do and how you should document it. In this course, we’ll connect the law of data security and investigations to the decisions you make in policy, compliance, incident response, a...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 36 — Distill cybercrime case lessons into practical response playbooks 18.02.2026 12:53
Every digital investigation provides a wealth of information that should be used to improve the organization's future defensive and investigative capabilities. This episode explains how to conduct a "Post-Incident Review" and translate technical findings into actionable playbooks for the security operations center. For certification, it is important to know how to identify the "root cause" of an i...
Episode 35 — Prepare law-enforcement referrals that are complete and actionable 18.02.2026 12:38
When an organization decides to pursue criminal charges for a cybercrime, the quality of the law-enforcement referral determines whether the authorities will take the case. This episode explores what a "prosecutable" referral looks like, including a clear description of the harm, the identified evidence, and a summary of the loss incurred. For the GLEG exam, understanding the "jurisdictional" boun...
Episode 34 — Escalate security incidents with sound legal judgment and timing 18.02.2026 12:42
Knowing when and how to escalate a security incident is a strategic skill that requires a balance of technical urgency and legal caution. This episode examines the internal "escalation paths" and the criteria used to determine if a minor anomaly has crossed the threshold into a full-scale legal or regulatory event. For certification purposes, candidates must understand the notification requirement...
Episode 33 — Write investigation reports that read clearly and persuade 18.02.2026 12:00
An investigation report is the primary bridge between technical forensic findings and the non-technical stakeholders who must make decisions based on those facts. This episode details how to structure a report that includes an executive summary, a detailed methodology, and clear, evidence-backed conclusions. For the GLEG exam, practitioners must learn how to present "opinion" versus "fact" and ens...
Episode 32 — Preserve digital evidence using standardized, defensible handling practices 18.02.2026 12:31
The integrity of an entire investigation rests on the initial preservation of digital evidence using standardized, forensically sound methods. This episode covers the technical requirements for bit-stream imaging, write-blocking, and the immediate verification of data using cryptographic hashing. For certification, candidates must understand how to avoid the "footprints" that accidental boot-ups o...
Episode 31 — Coordinate effectively with forensics teams under counsel direction 18.02.2026 12:59
Successful digital investigations rely on the seamless coordination between technical forensic experts and legal counsel to ensure all findings are protected and strategically sound. This episode explores the "triad" of incident response, where the technologist provides the ground truth, the attorney manages the legal risk, and the organization maintains business continuity. For the GLEG exam, it...
Episode 30 — Spot fraud and misuse patterns before damage escalates 18.02.2026 12:47
Proactive identification of fraud and internal misuse is the most effective way to minimize the financial and reputational impact of a security incident. This episode examines common patterns of digital fraud, such as insider trading, intellectual property theft, and financial statement manipulation. For certification purposes, candidates must understand how to utilize "detective controls"—such as...
Episode 29 — Survey computer crime laws impacting investigations and response 18.02.2026 12:38
Understanding the statutory landscape of computer crime is a mandatory requirement for any professional involved in incident response or digital investigations. This episode surveys major laws such as the Computer Fraud and Abuse Act (CFAA) and the Wiretap Act, explaining how they define "unauthorized access" and "interception." For the GLEG exam, it is vital to know the difference between civil a...
Episode 28 — Rapid recap: retention and e-discovery essentials reinforced 18.02.2026 12:31
This rapid-fire recap episode consolidates the most critical takeaways from the records retention and e-discovery domains to ensure a high level of recall for the GLEG exam. We revisit the core stages of the EDRM, the legal "triggers" for a litigation hold, and the technical requirements for a forensically sound collection. For the certification, candidates should be comfortable distinguishing bet...
Episode 27 — Execute defensible disposition without increasing legal exposure 18.02.2026 12:50
Disposing of data that has reached the end of its retention period is a vital but risky task that must be performed with total administrative and technical precision. This episode explores how to execute "defensible disposition" by ensuring that no data is deleted while it is subject to a litigation hold or a regulatory inquiry. For certification purposes, it is important to understand the differe...
Episode 26 — Audit retention controls for completeness, consistency, and proof 18.02.2026 12:09
Regularly auditing your records retention controls is the only way to ensure that your governance policies are being translated into actual practice. This episode details the process of verifying that data is being deleted or archived according to the formal schedule across all business units and technical platforms. For the GLEG exam, candidates must know how to evaluate "compliance artifacts"—su...
Episode 25 — Learn landmark e-discovery cases shaping today’s expectations 18.02.2026 11:37
The rules governing e-discovery are constantly evolving through landmark judicial decisions that set the standard for "reasonable" behavior in the digital age. This episode reviews influential cases, such as Zubulake v. UBS Warburg, which established the primary framework for cost-shifting and the duty to preserve electronic records. For the GLEG exam, understanding these precedents is essential f...
Episode 24 — Orchestrate legal collection workflows that are targeted and defensible 18.02.2026 12:14
The collection phase of e-discovery requires a surgical approach to gather relevant data without over-collecting unnecessary or privileged information. This episode explores the technical workflows used to extract Electronically Stored Information (ESI) from various sources, including cloud storage, mobile devices, and legacy servers. For certification, it is critical to understand the principle o...
Episode 23 — Preserve electronic evidence while maintaining chain of custody 18.02.2026 12:10
Maintaining the integrity of electronic evidence is paramount for its admissibility in a court of law. This episode focuses on the "chain of custody," which provides a documented, chronological history of the evidence from the moment of collection to its presentation in court. For the GLEG exam, practitioners must understand the importance of cryptographic hashing to prove that an electronic file...
Episode 22 — Set litigation holds that actually preserve what matters most 18.02.2026 12:48
The issuance of a litigation hold is a high-stakes event that requires immediate and precise action to halt the routine destruction of potentially relevant evidence. This episode examines the "duty to preserve" and the technical steps necessary to ensure that data remains intact once a legal dispute is reasonably anticipated. For certification purposes, it is essential to know how to identify rele...
Episode 21 — Build records retention schedules that survive audits and lawsuits 18.02.2026 12:25
A robust records retention schedule is a critical component of information governance, balancing business needs with legal and regulatory requirements. This episode explores how to determine the "life cycle" of various data types, from creation to final disposition, ensuring that information is neither deleted prematurely nor kept indefinitely. For the GLEG exam, candidates must understand that re...
Episode 20 — Grasp e-discovery essentials every technologist and counsel needs 18.02.2026 12:18
Electronic discovery, or e-discovery, is the process by which organizations must identify, preserve, and produce digital evidence in response to a legal or regulatory request. This episode introduces the Electronic Discovery Reference Model (EDRM) and the various stages of the litigation lifecycle. For the GLEG exam, understanding the "duty to preserve" and when the "litigation trigger" is pulled...
Episode 19 — Exam Acronyms: quick audio reference for rapid recall 18.02.2026 12:12
The GLEG exam is dense with specialized acronyms that can trip up even the most experienced professionals if they are not second nature. This episode provides a rapid-fire audio glossary of the most common terms you will encounter, such as ESI (Electronically Stored Information), FRCP (Federal Rules of Civil Procedure), and DMCA (Digital Millennium Copyright Act). For certification, it is vital to...
Episode 18 — Apply electronic signatures that withstand regulatory and courtroom scrutiny 18.02.2026 12:25
Electronic signatures have become the standard for modern business, but they must meet specific technical and legal criteria to be considered as valid as a physical "ink" signature. This episode explores the different levels of electronic signatures, from simple checked boxes to cryptographically secure digital signatures. For the GLEG exam, understanding the ESIGN Act and the UETA, and how they p...
Episode 17 — Validate online assent using clickwrap, browsewrap, and recordkeeping 18.02.2026 11:59
The method by which an organization obtains agreement from its users online determines the legal enforceability of its terms and policies. This episode compares the legal strength of "clickwrap" agreements, which require a deliberate action, versus "browsewrap" agreements, which rely on the mere use of the site. For the GLEG exam, candidates must be familiar with the "conspicuousness" and "reasona...
Episode 16 — Bulletproof service agreements using clear security and audit clauses 18.02.2026 12:07
To truly protect the organization, service level agreements (SLAs) must be bolstered with specific, enforceable security and audit requirements. This episode outlines how to draft clauses that define "up-time" in a security context and establish the right to perform independent security assessments of the vendor’s environment. For certification, it is critical to understand the role of SOC 2 repor...
Episode 15 — Govern affiliate data sharing without creating privacy landmines 18.02.2026 12:54
Sharing personal data between corporate affiliates or subsidiaries requires a sophisticated governance framework to avoid significant privacy and regulatory violations. This episode examines the legal requirements for "inter-company" data transfer agreements and the necessity of maintaining transparency with the data subjects. For the GLEG exam, practitioners must understand the concept of "joint...
Episode 14 — Vet contractor agreements for confidentiality, IP, and liability alignment 18.02.2026 12:53
When engaging independent contractors or consultants, the protection of intellectual property and the clear definition of liability are paramount. This episode details the process of vetting contractor agreements to ensure that "Work for Hire" clauses are properly structured so the organization retains ownership of all created assets. For the GLEG exam, candidates must understand the difference be...
Episode 13 — Triage terms of service for hidden obligations and traps 18.02.2026 12:03
Navigating the complex and often dense language of Terms of Service (ToS) is a vital skill for preventing accidental legal or technical liabilities. This episode focuses on how to triage these agreements to identify "unconscionable" terms, hidden data sharing permissions, and broad liability waivers that could harm the organization. For certification purposes, it is important to understand the leg...
Episode 12 — Strengthen third-party contracts to reduce legal and cyber exposure 18.02.2026 11:56
Managing third-party risk begins with the inclusion of robust security and privacy clauses within every vendor and partner contract. This episode explores the essential legal components of a secure agreement, such as right-to-audit clauses, breach notification requirements, and data return or destruction mandates. For the GLEG exam, understanding the "privity of contract" and how liability can be...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.