Jason Edwards

Certified: The GIAC GSOM Audio Course

Welcome to Certified: The ISACA GSOM Audio Course. I’m here to help you build the kind of security operations management mindset that works in the real world, where priorities shift, alerts pile up, and executives want answers in plain language. Across this course, you can expect practical explanations, clear definitions, and guidance that connects day-to-day operations to business risk. We’ll talk about how security teams are structured, how work gets triaged and tracked, how incidents are managed without chaos, and how to report progress in a way leaders trust. Everything is taught with the...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 15, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Welcome to the GIAC GSOM Audio Course 15.02.2026

Certified: The ISACA GSOM Audio Course is built for security leaders, managers, and senior practitioners who need to run a security program that holds up under real pressure. If you’re stepping into a security operations management role, leveling up from hands-on work into leadership, or trying to bring order to a messy set of tools and processes, this course is for you. It assumes you understand...

Episode 65 — Exam-Day Tactics: mental models for triage and confident GSOM answers 15.02.2026

This episode prepares you for exam-day decision making by treating each question like a mini triage event: identify what is being tested, classify the situation, choose the safest high-value next action, and avoid choices that create evidence loss or uncontrolled business disruption. You will learn mental models for quickly spotting the domain in play, such as whether the prompt is really about da...

Episode 64 — Final Review: weave every GSOM objective into one coherent SOC operating model 15.02.2026

This episode integrates the full GSOM scope into a single operating model, because the exam rewards candidates who can connect planning, tooling, telemetry, alerting, incident response, hunting, and metrics into a consistent set of choices rather than treating them as separate topics. You will walk through the SOC lifecycle end to end: defining mission and coverage, selecting and securing tools, c...

Episode 63 — Essential Terms: Plain-Language Glossary for Fast Recall 15.02.2026

This episode is a focused glossary pass designed for rapid recall under exam conditions, because GSOM questions often hinge on precise meaning and operational implications rather than memorizing buzzwords. You will review essential terms across SOC planning, telemetry, alerting, incident response, threat hunting, and metrics, with each term framed as “what it means in practice” and “what decision...

Episode 62 — Apply adversarial emulation to stress-test SOC people, process, and tools 15.02.2026

This episode covers adversarial emulation as a controlled way to evaluate SOC readiness, which GSOM may test by asking how to find real gaps in detection, response coordination, and decision quality without waiting for a real incident. You will define adversarial emulation as executing planned attacker-like behaviors in a safe, authorized manner to verify that telemetry, alerts, playbooks, and esc...

Episode 61 — Validate detections with analytic testing before attackers exploit your gaps 15.02.2026

This episode explains detection validation as a disciplined testing practice, because the GSOM exam expects you to recognize that detections are hypotheses that must be proven reliable before you trust them in production. You will define analytic testing as the process of confirming that a detection fires for the right behavior, includes the right context for triage, and does not create unacceptab...

Episode 60 — Automate repetitive SOC tasks to boost consistency and reduce burnout 14.02.2026

This episode teaches automation as a controlled way to improve consistency and free analysts for higher-value thinking, which GSOM tests by asking what should be automated, what should remain human-approved, and how to avoid automating mistakes at scale. You will define good automation candidates as repetitive, well-understood tasks with clear success criteria, such as enrichment lookups, evidence...

Episode 59 — Continuous Improvement: use post-incident data to fuel future growth 14.02.2026

This episode focuses on continuous improvement as a repeatable loop that uses post-incident evidence to strengthen the SOC, which GSOM tests because mature operations treat every incident as data for better prevention, detection, and response. You will learn how to extract improvement signals from timelines, decision logs, and investigation gaps, then convert them into prioritized changes such as...

Episode 58 — Spaced Review: make metrics, analytics, and planning feel automatic under pressure 14.02.2026

This episode reinforces the analytics mindset that GSOM tests: metrics are tools for better decisions, not decorations, and they must be chosen, interpreted, and acted on consistently even when operations are busy. You will revisit how to distinguish activity from outcomes, how to set goals that map to detection and response maturity, and how to diagnose bottlenecks using evidence from queues, han...

Episode 57 — Communicate SOC performance with metrics leaders trust and teams respect 14.02.2026

This episode explains how to communicate SOC performance in a way that earns trust, because GSOM expects leaders to report clearly without hiding problems or punishing the team through misleading numbers. You will learn to choose metrics that are credible, explainable, and connected to business risk, then present them with context that shows what changed, why it changed, and what actions are under...

Episode 56 — Build a strategic plan that turns metrics into sustained operational change 14.02.2026

This episode teaches how to convert metrics into a strategic improvement plan that survives beyond a single initiative, which GSOM tests because SOC leadership must demonstrate continuous maturity instead of reactive firefighting. You will define a strategic plan as a prioritized set of improvements with clear outcomes, owners, timelines, and validation methods, where metrics provide both the base...

Episode 55 — Analyze SOC operations to find bottlenecks, gaps, and high-impact improvements 14.02.2026

This episode focuses on operational analysis as a way to identify where your SOC is losing time, losing quality, or losing visibility, which GSOM tests by presenting symptoms and asking for the most effective corrective action. You will learn how to examine workflows from alert intake through triage, investigation, escalation, and closure, and how to use evidence such as queue age, reopens, handof...

Episode 54 — Set SOC goals and analytics that guide continuous maturity planning 14.02.2026

This episode teaches how to set SOC goals that are specific enough to guide day-to-day choices and long-term maturity, a GSOM expectation because exam questions often ask what to prioritize next when resources are limited. You will define good goals as ones tied to mission outcomes, such as improved detection coverage for critical attack paths, reduced time to contain high-confidence incidents, or...

Episode 53 — SOC Analytics and Metrics: choose measures that reflect progress and effectiveness 14.02.2026

This episode introduces SOC analytics and metrics as decision tools rather than vanity numbers, which GSOM tests because leaders must measure what matters, detect drift, and improve outcomes without incentivizing bad behavior. You will define the difference between activity metrics, quality metrics, and outcome metrics, and learn how to select measures that reflect detection effectiveness, respons...

Episode 52 — Spaced Review: reinforce threat hunting, active defense, and community resource leverage 14.02.2026

This episode consolidates proactive detection concepts that GSOM expects you to apply with confidence, especially when traditional alerts are not giving you enough clarity or coverage. You will revisit threat hunting as a hypothesis-driven process that demands clear questions, reliable telemetry, and defensible conclusions, then connect active defense to safe improvements that increase visibility...

Episode 51 — Convert hunt results into improved detections, playbooks, and data needs 14.02.2026

This episode explains how threat hunting creates lasting value only when results are converted into durable operational improvements, which GSOM tests by asking what to do after you discover a pattern, confirm suspicious behavior, or identify a visibility gap. You will define the main hunt outputs—confirmed malicious activity, confirmed benign behavior, and “inconclusive due to missing evidence”—a...

Episode 50 — Use community sourced resources to supplement gaps in detection capabilities 14.02.2026

This episode explains how to use community resources responsibly to accelerate detection coverage, which GSOM tests because leaders must balance speed with trust, quality, and operational fit. You will discuss how community detection content, threat reports, and shared hunting queries can provide starting points for new alerts and hunts, while emphasizing that everything must be validated against...

Episode 49 — Apply active defense techniques that increase visibility and adversary friction 14.02.2026

This episode focuses on active defense techniques that strengthen detection and slow adversaries, which GSOM may test by presenting options that range from safe improvements to risky actions that create legal or operational problems. You will define “increasing visibility” as ensuring key attacker behaviors leave reliable evidence, such as improved endpoint telemetry, richer identity logging, stro...

Episode 48 — Run the threat hunting process from hypothesis to defensible conclusions 14.02.2026

This episode teaches the full threat hunting workflow in a way the GSOM exam expects you to apply, emphasizing that hunts must produce defensible conclusions, not just interesting charts. You will learn how to form a hypothesis from threat intelligence, environmental knowledge, or observed anomalies, then translate it into specific questions your telemetry can answer, including what data sources,...

Episode 47 — Proactive Detection and Analysis: threat hunting and active defense fundamentals 14.02.2026

This episode introduces threat hunting and active defense as proactive practices that complement alert-driven monitoring, which GSOM tests because SOC maturity includes finding what detections miss and increasing attacker friction. You will define threat hunting as hypothesis-driven analysis across data sources to discover suspicious patterns that have not yet triggered reliable alerts, and active...

Episode 46 — Spaced Review: investigate, contain, eradicate, recover, and learn without guesswork 14.02.2026

This episode consolidates the incident response execution flow that GSOM repeatedly evaluates, helping you recognize which phase a question is targeting and what “best next step” logic applies. You will revisit rapid scoping with hypotheses and timelines, then reinforce containment as risk-reducing actions chosen with business impact in mind and verified through telemetry. We will review eradicati...

Episode 45 — Close the loop with lessons learned that strengthen every IR phase 14.02.2026

This episode teaches lessons learned as an operational improvement process, which GSOM tests because mature programs turn incidents into better detections, clearer playbooks, and fewer repeat failures. You will define lessons learned as evidence-driven findings tied to root causes, contributing factors, and control gaps, then connect those findings to concrete improvements across preparation, dete...

Episode 44 — Drive eradication and recovery with verification and controlled reentry steps 14.02.2026

This episode explains how eradication and recovery should be executed with verification gates, because GSOM expects you to prevent “false recovery” where systems return to service while persistence or attacker access remains. You will define eradication as removing the attacker’s foothold, including persistence mechanisms, malicious tooling, unauthorized accounts, and abused credentials, and recov...

Episode 43 — Execute containment choices that reduce risk without crippling the business 14.02.2026

This episode explores containment as a set of controlled options with tradeoffs, because GSOM questions often ask you to choose a response that reduces attacker capability while preserving critical operations and investigative integrity. You will define containment goals such as stopping spread, preventing further access, and protecting data, then map them to actions like isolating endpoints, disa...

Episode 42 — Scope incidents rapidly using hypotheses, timelines, and high-value evidence 14.02.2026

This episode teaches rapid scoping as a structured method rather than a guessing game, which GSOM tests because effective scoping determines whether you contain the right systems and avoid wasting hours on low-value data. You will define a hypothesis as a testable statement about attacker activity, then learn how to build and refine it using a timeline anchored to high-confidence events like authe...

Listen to the Certified: The GIAC GSOM Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.