Jason Edwards

Certified: The GIAC GSLC Audio Course

This audio-first cybersecurity course is built for busy professionals who need security that works in real environments, not just on slides. You’ll learn how to design monitoring, logging, SIEM, and SOAR operations that produce usable visibility, reduce noise, and support fast, defensible response. Along the way, you’ll connect technical controls to practical program execution: ownership, SLAs, governance, decision rights, and evidence that holds up during incidents and audits. You’ll also strengthen your ability to explain risk in business terms and prioritize work using context like exposure...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 58 — Align Policy With Risk Appetite, Exceptions, and Accountability Mechanisms 10.02.2026

This episode teaches how to align policy with risk appetite and create exception and accountability mechanisms that prevent governance from becoming symbolic, a topic the exam tests through program maturity and leadership decision scenarios. You will learn how to translate risk appetite into clear requirements, how to design an exception process with documented rationale, compensating controls, ow...

Episode 57 — Distinguish Policies, Standards, Guidelines, Baselines, and Procedures Correctly 10.02.2026

This episode clarifies the differences between key governance document types, which is exam-relevant because many questions test whether leaders can choose the right instrument for the right purpose and enforce it consistently. You will learn how policies express mandatory direction aligned to risk appetite, how standards define specific mandatory requirements, how guidelines provide recommended p...

Episode 56 — Write Security Policies That People Can Follow and Auditors Can Verify 10.02.2026

This episode teaches how to write security policies that are clear, enforceable, and measurable, aligning with exam objectives that emphasize the role of governance artifacts in controlling risk and proving compliance. You will learn how to state required outcomes in plain language, define responsibilities and scope, and ensure policy requirements can be tested through evidence rather than interpr...

Episode 55 — Mature Awareness Programs Using Metrics, Reinforcement, and Targeted Campaigns 10.02.2026

This episode focuses on maturing an awareness program over time using metrics and targeted reinforcement, matching exam objectives that emphasize programs which evolve alongside risk and organizational change. You will learn how maturity progresses from baseline training to behavior-driven campaigns informed by incident data, role risk profiles, and observed weak points in workflows. We cover sele...

Episode 54 — Design Security Awareness That Changes Behavior and Reduces Real Incidents 10.02.2026

This episode explains how to build an awareness program that drives measurable behavior change, a certification objective that often appears in exam questions about program maturity and effectiveness. You will learn how to choose target behaviors such as verification, reporting, safe data handling, and resistance to common social engineering patterns, then craft messages that fit real workflows ra...

Episode 53 — Assess Human Risk Drivers: Roles, Behaviors, and Likely Failure Points 10.02.2026

This episode teaches how to assess human risk as a predictable set of behaviors shaped by roles, access, and workflow pressure, aligning with exam objectives on security awareness and risk management. You will learn how to identify high-risk roles, such as those with privileged access or high-value data exposure, and map common failure points like rushed approvals, credential sharing, insecure dat...

Episode 52 — Handle Project Drift: Change Control, Dependencies, and Delivery Evidence 10.02.2026

This episode explains how to recognize and correct project drift before it derails outcomes, which is exam-relevant because leaders must manage scope, schedule, quality, and risk under changing conditions. You will learn how drift appears as silent scope creep, slipping dependencies, or reduced quality, and how change control turns ad hoc requests into structured decisions with impact analysis and...

Episode 51 — Build Business Support for Security Work Using Value, Cost, and Tradeoffs 10.02.2026

This episode teaches how to gain business support for security initiatives by framing decisions in terms executives and stakeholders can evaluate, which aligns with exam objectives on leadership communication and program management. You will learn how to define value as outcomes such as reduced loss, improved reliability, and preserved customer trust, then connect that value to specific controls a...

Episode 50 — Run Security Projects: Scope, Schedule, Risk, and Stakeholder Commitments 10.02.2026

This episode teaches security project execution as disciplined delivery, emphasizing exam-relevant project management concepts like scope control, stakeholder alignment, dependency management, and proof of completion. You will learn how to define scope as outcomes and exclusions, build schedules with milestones and dependencies, and identify project risks early so they can be tracked and mitigated...

Episode 49 — Manage Third-Party Contracts: SLAs, Audit Rights, Breach Terms, and Ownership 10.02.2026

This episode focuses on third-party contracts as the mechanism that turns security expectations into enforceable obligations, a leadership skill tested on the exam through vendor management and program governance scenarios. You will learn how to structure SLAs around availability and support responsiveness, define breach notification timelines and required content, and ensure audit rights and evid...

Episode 48 — Build Vendor Risk Management: Intake, Due Diligence, and Ongoing Monitoring 10.02.2026

This episode teaches vendor risk management as a lifecycle that begins before purchase and continues through renewal and offboarding, matching exam expectations that leaders can classify, assess, and monitor third-party risk appropriately. You will learn how intake should categorize vendors by data exposure, criticality, and access, then tailor due diligence depth to that tier so effort is proport...

Episode 47 — Negotiate Security Outcomes With Vendors Using Requirements, Evidence, and Leverage 10.02.2026

This episode explains how to negotiate security outcomes with vendors so obligations are measurable and enforceable, reflecting exam objectives around negotiation, third-party management, and governance. You will learn how to start from outcomes such as confidentiality, availability, incident notification, and evidence access, then translate them into requirements that can be validated rather than...

Episode 46 — Align Compliance Expectations With Practical Security Evidence and Continuous Checks 10.02.2026

This episode teaches how to meet compliance expectations by building evidence into daily operations, a key exam concept because it tests whether leaders can sustain controls beyond audit season. You will learn what counts as defensible evidence, including configurations, logs, tickets, attestations, and test results, and how to map each requirement to a repeatable evidence source that can be produ...

Episode 45 — Translate Privacy Requirements Into Controls: Minimization, Retention, and Access 10.02.2026

This episode explains how to translate privacy requirements into enforceable security controls, a recurring exam theme because leaders must connect compliance concepts to practical implementation. You will learn how minimization reduces risk by limiting what is collected, how retention limits prevent long-term exposure and unnecessary obligations, and how purpose-based access controls ensure only...

Episode 44 — Protect Data at Rest Using Encryption, Key Custody, and Access Patterns 10.02.2026

This episode teaches how to protect data at rest so theft of media or unauthorized access does not automatically become disclosure, connecting exam objectives across encryption, key management, and system security design. You will learn how to classify data stores such as disks, databases, backups, and snapshots, then choose encryption scope at the volume, file, or application layer based on threa...

Episode 43 — Protect Data in Transit Using TLS Choices and Certificate Hygiene 10.02.2026

This episode explains how to protect data in transit using TLS and disciplined certificate management, a topic that appears on the exam through encryption, identity assurance, and operational troubleshooting scenarios. You will learn what TLS provides, including confidentiality and endpoint verification, and how to decide where encryption must be enforced end-to-end rather than relied on “somewher...

Episode 42 — Manage Cloud Risk With Baselines, Policies, and Exception Handling That Scales 10.02.2026

This episode teaches how to scale cloud security using enforceable baselines and disciplined exception handling, a core exam concept because it tests whether leaders can make security consistent without creating bottlenecks. You will learn how to define baselines as minimum required controls, translate policy into technical guardrails, and design exception workflows that require owners, justificat...

Episode 41 — Control Cloud Data Exposure: Storage Permissions, Keys, and Configuration Drift 10.02.2026

This episode focuses on preventing cloud data exposure by controlling the practical failure points that most often cause leaks, which aligns with exam expectations around cloud risk management, identity governance, and operational discipline. You will learn how data becomes exposed through overly permissive storage settings, inherited access rules that expand silently, weak key custody, and config...

Episode 40 — Operationalize Cloud Logging: Sources, Normalization, Retention, and Alert Quality 10.02.2026

This episode explains how to operationalize cloud logging so it supports detection, investigations, and compliance, a high-value exam theme because centralized visibility is foundational to modern security operations. You will learn which log sources are most critical, including identity events, control plane actions, network flows, and workload telemetry, and how normalization makes cross-service...

Episode 39 — Design Cloud Network Segmentation to Reduce Blast Radius and Lateral Movement 10.02.2026

This episode teaches how to segment cloud networks so inevitable compromises do not become enterprise-wide incidents, a topic tied to exam expectations around architecture, trust models, and risk reduction. You will learn how to separate environments by purpose and sensitivity, define permitted flows explicitly, and use constructs like security groups, routing boundaries, and controlled egress to...

Episode 38 — Secure Cloud Identity: Roles, Federation, MFA, and Least Privilege Enforcement 10.02.2026

This episode covers cloud identity as the primary control plane for modern environments, aligning with exam objectives that emphasize governance, access control strategy, and operational enforcement. You will learn how roles replace shared accounts for traceability, how federation links identities across trusted systems, and why multi-factor authentication is critical for privileged and remote acc...

Episode 37 — Master Cloud Service Models and Shared Responsibility Without Blind Spots 10.02.2026

This episode clarifies cloud service models and the shared responsibility concept so you can correctly assign security duties, a frequent exam requirement because misunderstandings here create major control gaps. You will define IaaS, PaaS, and SaaS in business-relevant terms, then map responsibility for identity, data protection, configuration, logging, and incident handling across provider and c...

Episode 36 — Set AI Governance: Acceptable Use, Access Controls, and Monitoring Expectations 10.02.2026

This episode explains how to build AI governance that is enforceable and sustainable, a concept the exam tests through leadership ability to translate risk appetite into policies, controls, and oversight mechanisms. You will learn how to define acceptable use in terms of permitted tasks and permitted data classes, assign ownership for approvals and exceptions, and implement access controls that re...

Episode 35 — Manage AI Security Risks: Data Leakage, Prompt Abuse, and Model Misuse 10.02.2026

This episode focuses on AI security risks that leaders must anticipate and control, including data leakage, prompt abuse, and misuse patterns, which connects to exam objectives around governance, privacy, and program controls. You will learn how sensitive data can escape through inputs, outputs, logs, retention policies, and third-party handling, and how prompt manipulation can influence behavior,...

Episode 34 — Evaluate AI Business Benefits Without Confusing Demos With Production Reality 10.02.2026

This episode teaches how to evaluate AI initiatives with disciplined criteria so you can separate real business value from impressive demonstrations, aligning with exam themes of governance, risk management, and vendor evaluation. You will learn to define benefits as measurable improvements to cost, speed, quality, or risk reduction, then assess whether the required data exists, who owns it, and h...

Listen to the Certified: The GIAC GSLC Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.