Jason Edwards
Certified: The GIAC GSTRT Audio Course
This audio-first security strategy course helps you turn security intent into measurable execution. You will learn how to assess current capabilities against mission outcomes and real risk, identify gaps and root causes, and prioritize improvements with clear business rationale. The course shows you how to translate technical work into outcomes leaders care about, like reliability, resilience, and reduced incident impact, then sequence initiatives so they land with minimal friction across teams. You will also learn how to build a strategic roadmap that blends quick wins with foundational capab...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Welcome to the GIAC GSTRT Audio Course! 08.02.2026 1:19
This audio-first security strategy course helps you turn security intent into measurable execution. You will learn how to assess current capabilities against mission outcomes and real risk, identify gaps and root causes, and prioritize improvements with clear business rationale. The course shows you how to translate technical work into outcomes leaders care about, like reliability, resilience, and...
Episode 57 — Execute your exam-day gameplan calmly, decisively, and to full effect 08.02.2026 13:45
The final episode of the series teaches you how to execute your exam-day gameplan with tactical composure, ensuring that your preparation is translated into a successful certification outcome. We discuss the "gameplan" as a pre-defined sequence of actions that protects your mental energy, such as scanning for easy questions first or knowing when to flag and move past a difficult scenario. We defin...
Episode 56 — Final review: focus, retrieval cues, and confidence calibration 08.02.2026 15:56
This penultimate session focuses on a high-level final review designed to sharpen your focus, reinforce your retrieval cues, and calibrate your confidence before the formal exam. We revisit the core pillars of the GSTRT blueprint—business and threat analysis, security programs, and strategic leadership—and synthesize them into a unified mental map. We define "confidence calibration" as the ability...
Episode 55 — Essential terms: plain-language glossary for rapid comprehension 08.02.2026 14:50
As the GSTRT curriculum draws to a close, this episode provides a plain-language glossary of essential terms to ensure rapid comprehension and consistent communication during the exam and in professional practice. We review the foundational definitions of risk, threat, vulnerability, and control, while also exploring strategic concepts like "capability maturity" and "risk appetite." For the certif...
Episode 54 — Operationalize strategy into action with owners, milestones, and reviews 08.02.2026 14:51
Operationalizing a strategy means moving from the boardroom to the server room by assigning owners, setting clear milestones, and conducting regular reviews for every project. This session focuses on the "execution framework" required to ensure that high-level goals are translated into daily technical and administrative actions. We define a "milestone" as a specific, measurable checkpoint that all...
Episode 53 — Plan budgeting and staffing to sustain execution without burnout 08.02.2026 16:39
Sustaining the execution of a multi-year security strategy requires a realistic plan for budgeting and staffing that prevents team burnout and ensures the right skills are available for every project. This episode covers the "human capital" side of strategy, discussing how to balance permanent staff, contractors, and managed service providers. We define "sustainable resourcing" as the ability to m...
Episode 52 — Socialize the program internally to build champions and durable support 08.02.2026 16:40
Socializing a security program is the process of building a network of internal champions across the firm who understand the vision and provide durable support for its goals. This session explores techniques for "internal advocacy," such as meeting with non-technical department heads to explain how data protection supports their specific objectives. We define a "security champion" as a non-securit...
Episode 51 — Sequence initiatives for maximum impact with minimal organizational friction 08.02.2026 15:40
Effective sequencing involves planning the order of security projects to ensure maximum risk-reduction impact while causing the minimal amount of organizational friction. This episode addresses the "human element" of implementation, discussing how to space out high-impact changes to avoid overwhelming the workforce or technical teams. We define "friction" as the operational disruption that occurs...
Episode 50 — Define outcome-based metrics that prove progress and guide pivots 08.02.2026 13:34
To demonstrate the success of a security strategy, a leader must define outcome-based metrics that prove actual progress and provide the data needed to guide strategic pivots. This session explores the difference between "vanity metrics" (like the number of blocked emails) and "outcome-based metrics" (like the reduction in mean time to detect a breach). We define actionable insights as the data po...
Episode 49 — Craft convincing business cases that secure funding and executive backing 08.02.2026 13:19
Securing the funding needed for a world-class security program requires the ability to craft convincing business cases that address the concerns of financial and operational executives. This episode details the essential elements of a business case, including the problem statement, the proposed solution, the total cost of ownership (TCO), and the anticipated benefits. We define the "value proposit...
Episode 48 — Build a strategic security roadmap that sequences wins and impact 08.02.2026 13:39
A strategic security roadmap serves as the master plan that sequences technical and administrative initiatives to build cumulative impact and organizational momentum. This session explores how to design a multi-year timeline that prioritizes "foundational wins" early to secure the trust and resources needed for later, more complex phases. We define a roadmap as a high-level visual communication to...
Episode 47 — Recommend prioritized improvements with crisp rationale and business value 08.02.2026 15:01
A security leader’s influence is defined by their ability to recommend prioritized improvements using a crisp rationale that highlights tangible business value. This episode focuses on the transition from identifying technical gaps to presenting actionable solutions that resonate with the executive suite. We explore how to rank recommendations based on their risk-reduction potential and their retu...
Episode 46 — Evaluate resources and metrics to calibrate scope, pace, and ambition 08.02.2026 14:47
Successfully executing a security strategy requires a rigorous evaluation of available resources and the use of metrics to calibrate the appropriate scope, pace, and ambition of the program. For the GSTRT exam, candidates must understand that an overambitious strategy without the necessary financial or human capital will inevitably lead to project failure and organizational burnout. We define reso...
Episode 45 — Read culture and constraints to shape strategies that actually land 08.02.2026 15:23
The best technical strategy will fail if it is fundamentally incompatible with the organization’s culture or if it ignores critical resource constraints. This episode explores how to read "Organizational Culture" and build it into your strategic planning to ensure your initiatives are accepted and sustained. We define cultural reading as the process of understanding how people communicate, make de...
Episode 44 — Run gap and SWOT reviews to target improvements precisely 08.02.2026 14:37
To target security improvements with precision, a leader must master the use of gap analysis and SWOT reviews (Strengths, Weaknesses, Opportunities, and Threats). This session teaches you how to conduct a SWOT review to identify internal factors that help or hinder your security goals and external factors that could impact the business mission. We define a gap review as the comparison of your curr...
Episode 43 — Assess current security capabilities against mission and risk realities 08.02.2026 16:10
A realistic security strategy must begin with an honest assessment of the organization’s current capabilities compared to the threats it faces and the mission it must fulfill. This episode explores different capability assessment models, such as the Cybersecurity Capability Maturity Model (C2M2), and how to apply them in a business context. We define a capability assessment as the process of evalu...
Episode 42 — Review the policy lifecycle to cement lessons and improvements 08.02.2026 15:19
Reflecting on the entire policy lifecycle allows a security leader to identify systemic improvements and cement the lessons learned during the drafting and implementation phases. This session focuses on the use of "Post-Implementation Reviews" to evaluate whether a new policy achieved its intended risk-reduction goals. We define continuous improvement as the process of using feedback from the work...
Episode 41 — Communicate updates organization-wide so changes are understood and adopted 08.02.2026 14:29
The final stage of the policy lifecycle is the successful communication of updates to ensure the workforce understands and adopts the changes. This episode discusses strategies for "Governance Outreach," moving beyond mass emails toward targeted education and awareness campaigns. We define communication clarity as the ability to explain not just what changed, but how it impacts the daily work of d...
Episode 40 — Retire or refresh policies systematically to keep the corpus current 08.02.2026 15:41
A lean and current policy corpus is far more effective than a bloated one filled with outdated rules, and this episode covers the systematic retirement and refreshing of documentation. We define policy retirement as the formal process of removing a document that is no longer applicable, such as a policy for a technology that has been decommissioned. For the exam, candidates should understand that...
Episode 39 — Audit policies for gaps and drift to restore intended outcomes 08.02.2026 14:16
Policies can lose their effectiveness over time due to technical changes or shifting business priorities, a phenomenon known as policy drift. This episode focuses on the auditing process required to identify these gaps and restore the governance framework's intended outcomes. We define a policy gap as a scenario where a known threat or a new regulatory requirement is not addressed by the current d...
Episode 38 — Handle exceptions and waivers without eroding control effectiveness 08.02.2026 14:36
In the real world of business operations, a perfect "one-size-fits-all" policy is rare, making the formal management of exceptions and waivers a critical skill for any security leader. This episode details how to handle requests for policy deviations without compromising the organization’s overall security posture. We define an exception as a temporary, approved deviation from a standard that incl...
Episode 37 — Measure adoption and compliance with meaningful, decision-ready indicators 08.02.2026 15:41
A policy's value is non-existent if it is not followed, making the measurement of adoption and compliance a primary duty of the security strategist. This session explores how to move beyond simple "check-the-box" audits toward the use of meaningful, decision-ready indicators that highlight systemic issues. We define compliance metrics as the quantitative data points that track how well the workfor...
Episode 36 — Govern policy lifecycles with ownership, cadence, and measured accountability 08.02.2026 16:33
Effective governance requires treating security documentation as a living asset rather than a one-time project, which is why establishing a formal policy lifecycle is essential. This episode focuses on the management of policies from creation through regular review cycles and eventual retirement. We define policy ownership as the assignment of a specific individual or role responsible for the docu...
Episode 35 — Validate policies pre-release using pilots, feedback, and risk checks 08.02.2026 16:38
Before a security policy is released organization-wide, it must undergo a rigorous validation process to ensure it is technically sound and operationally viable. This session covers the use of pilot programs, where a new rule is tested with a small, representative group of users to identify unforeseen impacts or technical bugs. We define "Pre-Release Risk Checks" as the final review to ensure the...
Episode 34 — Win stakeholder policy buy-in through collaboration and early validation 08.02.2026 14:10
A security policy is only effective if it is accepted by the stakeholders who must live by its rules, making early buy-in a critical component of the governance lifecycle. This episode discusses techniques for collaborative policy development, such as forming "Policy Working Groups" that include representatives from Legal, IT, and individual business units. We define "Early Validation" as the proc...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.