Jason Edwards
Certified: The GIAC GSOM Audio Course
Welcome to Certified: The ISACA GSOM Audio Course. I’m here to help you build the kind of security operations management mindset that works in the real world, where priorities shift, alerts pile up, and executives want answers in plain language. Across this course, you can expect practical explanations, clear definitions, and guidance that connects day-to-day operations to business risk. We’ll talk about how security teams are structured, how work gets triaged and tracked, how incidents are managed without chaos, and how to report progress in a way leaders trust. Everything is taught with the...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 41 — Managing Incident Response Execution: investigation techniques that reach the truth 14.02.2026 20:02
This episode focuses on how incident response execution works in practice once an event is declared, because the GSOM exam often tests whether you can move from alert-level uncertainty to evidence-backed conclusions without destroying artifacts or rushing to assumptions. You will define core investigation techniques such as triage validation, scoping by observable facts, artifact collection from e...
Episode 40 — Spaced Review: remember IR preparation, phases, and SOC coordination essentials 14.02.2026 20:02
This episode consolidates incident response preparation and coordination concepts that GSOM revisits in multiple domains, helping you recognize the most defensible next action when a scenario accelerates. You will review readiness as prebuilt access, logging, evidence routines, playbooks, and communication paths, then reinforce the incident response cycle and what the SOC contributes at each phase...
Episode 39 — Build communication paths and decision points before the first incident hits 14.02.2026 19:02
This episode teaches communication and decision design as part of incident response readiness, because GSOM expects you to prevent “communication incidents” that slow containment, confuse stakeholders, and increase business damage. You will define communication paths as pre-agreed channels, roles, and escalation ladders that answer who must be informed, who can authorize disruptive actions, and ho...
Episode 38 — Prepare investigation foundations: evidence handling, tooling access, and documentation 14.02.2026 19:55
This episode focuses on the investigation foundations that make your conclusions defensible, because GSOM often tests whether you preserve evidence, maintain integrity, and document decisions in a way that survives scrutiny after the incident. You will define evidence handling in SOC terms, including preserving original artifacts, tracking chain-of-custody where needed, and avoiding actions that o...
Episode 37 — Master the incident response cycle and where SOC operations plug in 14.02.2026 19:23
This episode teaches the incident response cycle as an end-to-end workflow that the SOC supports at every stage, which GSOM tests by asking where specific actions belong and what the correct sequence should be when the situation evolves. You will define the major phases—preparation, detection and analysis, containment, eradication, recovery, and lessons learned—and connect each phase to SOC respon...
Episode 36 — Preparing for Incident Response: readiness steps that prevent chaos later 14.02.2026 16:53
This episode introduces incident response readiness as deliberate preparation that keeps you from improvising under pressure, and GSOM frequently tests these fundamentals because they determine whether investigations are credible and containment is controlled. You will define readiness in practical terms: having clear roles, access, evidence handling practices, logging retention, and escalation pa...
Episode 35 — Spaced Review: build, prioritize, classify, respond, and tune alerts confidently 14.02.2026 18:38
This episode is a high-speed consolidation of alert lifecycle skills that show up repeatedly in GSOM questions, designed to help you recognize what decision the exam is actually testing in a noisy scenario. You will revisit how use cases become actionable alerts, how severity, confidence, and business impact shape priority, and why consistent classification speeds routing and preserves context dur...
Episode 34 — Tune noisy detections using feedback loops that shrink backlogs over time 14.02.2026 17:57
This episode teaches detection tuning as an iterative feedback loop that improves signal quality while preserving coverage, which GSOM tests because “turn it off” is rarely the right long-term answer. You will define noise sources such as overly broad logic, missing allowlists for known-good behavior, poor asset or user context, and environmental changes like new software deployments that shift ba...
Episode 33 — Implement best practices for timely, manageable, and sustainable alert response 14.02.2026 18:21
This episode focuses on building an alert response engine that can run every day without burning out the team, a key GSOM expectation because response sustainability directly impacts detection quality and incident outcomes. You will learn how queue management, response SLAs, and escalation thresholds should be designed around evidence-driven actions, not arbitrary timers, so analysts know what “go...
Episode 32 — Classify alerts consistently to speed triage, routing, and investigation handoffs 14.02.2026 14:47
This episode teaches alert classification as a standard language that keeps SOC operations fast and defensible, which GSOM tests because inconsistency creates delays, misroutes, and poor incident narratives. You will define what a “classification” should capture, such as suspected activity type, affected scope, current confidence, and required next action, and how that differs from raw severity or...
Episode 31 — Prioritize alerts using severity, confidence, and business impact tradeoffs 14.02.2026 14:56
This episode explains how GSOM expects you to prioritize alerts as a disciplined triage system, not as a gut-feel reaction to whichever notification is loudest. You will define severity as potential impact if the alert is true, confidence as how strongly the evidence supports the detection, and business impact as the operational consequence of both attacker activity and your response actions. We w...
Episode 30 — Create actionable alerts from use cases and observable attacker behaviors 14.02.2026 14:17
This episode teaches the workflow for turning a detection use case into an alert that reliably drives the right action, which is a high-value GSOM skill because the exam often asks what to alert on, what to include, and what to do when ambiguity remains. You will learn to start with a behavior statement, identify the minimum evidence that proves it, and then build logic that balances precision and...
Episode 29 — Managing Alert Creation and Processing: build alerts people can act on 14.02.2026 15:16
This episode introduces alert management as an operational discipline that GSOM frequently tests, because alerting is where detection theory meets real workload, and poor alert design creates burnout, missed incidents, and false confidence. You will define an actionable alert as one that has a clear detection logic, a meaningful signal-to-noise ratio, enough context to start triage, and a predicta...
Episode 28 — Spaced Review: prioritize, collect, and enrich data sources without blind spots 14.02.2026 14:32
This episode consolidates the data-source decision chain that GSOM expects you to apply quickly: start from mission and risk, define use cases, identify required evidence, then implement collection and enrichment that makes the evidence usable at speed. You will revisit what makes telemetry high value, why operations context changes priority, and how frameworks help you spot coverage gaps that mat...
Episode 27 — Enrich collected data with context so monitoring becomes decisively faster 14.02.2026 15:56
This episode focuses on enrichment as the difference between “an event happened” and “an analyst can act,” which GSOM tests because strong triage depends on context that reduces uncertainty and speeds defensible decisions. You will define enrichment as attaching business and technical context to raw telemetry, such as asset ownership, criticality, environment, user role, geolocation, known-good se...
Episode 26 — Orchestrate secure and efficient data collection pipelines across diverse systems 14.02.2026 15:35
This episode explains how to design data collection pipelines that are both reliable and secure, a frequent GSOM theme because weak pipelines create blind spots, integrity risks, and operational chaos when incidents happen. You will define the pipeline components, including collection agents or API pulls, transport, buffering, parsing, normalization, routing, storage, and indexing, then connect ea...
Episode 25 — Leverage industry frameworks to prioritize collection, enrichment, and coverage gaps 14.02.2026 15:16
This episode teaches how to use industry frameworks as a prioritization accelerator rather than a compliance checkbox, because GSOM expects you to justify collection choices using defensible models when time and resources are limited. You will discuss how frameworks help you categorize attacker behaviors, map them to control and detection needs, and identify where your telemetry cannot support the...
Episode 24 — Turn organizational use cases into specific data source requirements fast 14.02.2026 15:36
This episode explains how to translate security use cases into concrete data requirements, which is a high-yield GSOM skill because the exam often tests whether you can identify what evidence is needed to detect a behavior and investigate it quickly. You will define a use case as a statement of what you want to catch, why it matters, and what observable signals prove it, then convert that into spe...
Episode 23 — Use business operations knowledge to select telemetry that matters most 14.02.2026 16:49
This episode shows how to use business operations context to choose telemetry that actually helps, because GSOM rewards decisions that align monitoring with how the organization runs rather than how a tool vendor describes the world. You will learn to start with business-critical services, key workflows, and peak operational periods, then map them to the assets, identities, and data flows that wou...
Episode 22 — Data Source Assessment and Collection: decide what to collect and prioritize 14.02.2026 13:41
This episode teaches how to assess and prioritize data sources so your SOC collects the minimum set that enables strong detection and investigation outcomes, which is a core GSOM competency because many exam questions assume you must make tradeoffs under cost, bandwidth, and staffing constraints. You will define what “high-value telemetry” means by linking events to questions the SOC must answer d...
Episode 21 — Spaced Review: cement SOC tooling choices, integrations, and secure implementation habits 14.02.2026 15:08
This episode reinforces how GSOM expects you to think about SOC technology decisions as operational systems that must stay reliable, secure, and supportable over time, not as a one-time procurement checklist. You will quickly revisit what SIEM, EDR, SOAR, and case tooling each contribute, then focus on integration fundamentals that make the data trustworthy, including normalization, time alignment...
Episode 20 — Secure SOC technology with least privilege, hardening, monitoring, and logging 14.02.2026 18:16
This episode treats SOC tooling as high-value infrastructure that must be protected like production systems, because GSOM expects you to recognize that attackers target the SOC to blind detection and manipulate evidence. You will define least privilege for analysts, engineers, and service accounts, then connect it to hardening practices such as secure baseline configurations, patch discipline, and...
Episode 19 — Integrate SOC tools safely so data flows without breaking trust 14.02.2026 18:35
This episode explains SOC integration as a security and reliability engineering problem, because GSOM questions often probe whether you can connect systems without creating new attack paths, data integrity issues, or operational fragility. You will define what “safe integration” means in practice: well-scoped APIs, least-privilege service accounts, secure secrets handling, clear data ownership, an...
Episode 18 — Choose SIEM, EDR, SOAR, and case tooling that supports operations 14.02.2026 19:57
This episode teaches selection logic for core SOC tooling categories, a frequent GSOM topic because the exam tests whether your choices support detection quality, response safety, and manageable operations. You will compare how SIEM and EDR complement each other, where SOAR adds value through consistent automation and integrated approvals, and why case management is not optional if you need defens...
Episode 17 — SOC Tools and Technology: know what common platforms do and why 14.02.2026 20:28
This episode builds a practical map of common SOC platforms and what problems they solve, because the GSOM exam expects you to select tools based on operational outcomes, not brand names. You will define the roles of log management and SIEM, endpoint telemetry and EDR, network visibility, ticketing and case management, and orchestration layers that coordinate workflows. We will explain why each pl...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.