Jason Edwards

Certified: The ISACA CCOA Audio Course

Welcome to Certified: The ISACA CCOA Audio Course, a focused, audio-first program designed to help you build confidence in cybersecurity audit and assurance. If you’ve ever struggled to interpret an audit request, map security work to a control expectation, or explain evidence in a way that satisfies reviewers, you’re in the right place. I’ll guide you through the concepts that show up again and again in assurance work: how audit scope gets defined, how controls are evaluated, what strong evidence looks like, and how findings are framed. Expect clear explanations, practical language, and a ste...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 15, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Welcome to the ISACA CCOA Audio Course 15.02.2026

Certified: The ISACA CCOA Audio Course is built for working cybersecurity professionals who need to strengthen their audit and assurance skills without turning study time into a second job. If you support governance, risk, compliance, security operations, or internal audit—and you want a clear path into an audit-focused mindset—this course is for you. You do not need to be an auditor already, but...

Episode 70 — Exam-Day Tactics: Calm Mental Models for Confident Incident Prioritization (Task 12) 14.02.2026

This episode teaches exam-day tactics using calm mental models that help you prioritize incidents and choose the most defensible next step even when questions are intentionally ambiguous. You will learn how to quickly identify what the scenario is testing, such as triage logic, evidence integrity, containment tradeoffs, or governance alignment, and how to eliminate answer choices that fail basic p...

Episode 69 — Essential Terms: Plain-Language Glossary for Fast Recall Under Pressure (Task 5) 14.02.2026

This episode provides an essential terms glossary in plain language, designed to strengthen recall under pressure by tying definitions to operational meaning. You will learn how to translate common security terms into the specific actions, controls, and evidence they imply, which helps you avoid misreading exam questions that rely on subtle wording. We will connect terms across governance, risk, d...

Episode 68 — Vulnerability Tracking Discipline: Ownership, SLAs, Verification, and Closure Proof (Task 18) 14.02.2026

This episode focuses on vulnerability tracking discipline, where the real security outcome depends on ownership, service level expectations, verification steps, and credible proof of closure. You will learn how to assign remediation ownership, define SLAs that reflect risk, and prevent “ticket closure” from substituting for actual remediation. We will discuss how verification works, including resc...

Episode 67 — Vulnerability Remediation Strategies: Patch, Mitigate, Accept, or Compensate (Task 2) 14.02.2026

This episode explains vulnerability remediation strategies as a set of choices that must match business constraints while still reducing risk in measurable, defensible ways. You will learn when patching is the best answer, when mitigation is appropriate, when risk acceptance is justified, and how compensating controls can reduce exposure while long-term fixes are planned. We will discuss factors s...

Episode 66 — Vulnerability Identification Skills: CVE Context, Validation Steps, and False Positives (Task 2) 14.02.2026

This episode teaches vulnerability identification skills by focusing on how to interpret CVE context, validate whether an exposure is real, and manage false positives without ignoring true risk. You will learn what a CVE represents, what it does not represent, and why environmental context such as configuration, reachable paths, and compensating controls changes the practical risk. We will discuss...

Episode 65 — Vulnerability Assessment Basics: Scopes, Methods, Evidence, and Interpreting Findings (Task 2) 14.02.2026

This episode covers vulnerability assessment basics with an emphasis on how scope, method, and evidence quality determine whether findings are trustworthy and actionable. You will learn how to define assessment scope across assets, environments, and time windows, and how different methods, such as scanning, configuration review, and manual validation, produce different levels of confidence. We wil...

Episode 64 — Apply Industry Best Practices and Frameworks Without Overcomplicating Operations (Task 21) 14.02.2026

This episode explains how to apply industry best practices and frameworks in a way that strengthens operations instead of creating paperwork that teams ignore. You will learn why frameworks are useful as reference models for coverage, language alignment, and audit readiness, but how they fail when adopted without tailoring to business context and maturity. We will discuss practical methods for map...

Episode 63 — Identity and Access Management Mastery: Authentication, Authorization, and Least Privilege (Task 4) 14.02.2026

This episode builds identity and access management mastery by clearly separating authentication, authorization, and least privilege, then showing how mistakes in each area drive major incidents. You will learn how identity systems issue and validate credentials, how authorization should be enforced consistently across services, and why least privilege must include both human and non-human identiti...

Episode 62 — Choose Controls and Techniques Wisely: Prevent, Detect, Correct, and Deter (Task 4) 14.02.2026

This episode teaches how to choose controls and techniques with intent, using the categories of preventive, detective, corrective, and deterrent controls to structure decisions. You will learn how each control type contributes differently to risk reduction, and why a strong program balances them rather than relying on a single tool or layer. We will discuss how to select the best control for a sce...

Episode 61 — Contingency Planning That Works: Backups, RTO RPO, and Recovery Priorities (Task 4) 14.02.2026

This episode explains contingency planning as an operational capability that determines whether an organization can recover from attacks, outages, and mistakes without unacceptable harm. You will learn the meaning of backups, recovery time objective, and recovery point objective, and how these concepts translate into practical design decisions about frequency, storage separation, testing, and rest...

Episode 60 — Spaced Retrieval Review: Detection and Response From Signal to Lessons Learned (Task 18) 14.02.2026

This episode reviews detection and response as a full arc, from the first signal to the final lessons learned, reinforcing the process steps that the exam expects you to apply consistently. You will revisit triage prioritization, enrichment choices, containment tradeoffs, evidence handling, and communication discipline, but in a connected storyline that mirrors real SOC operations. We will practic...

Episode 59 — Threat Analysis Synthesis: Hypotheses, Root Cause, and Adversary Objectives (Task 15) 14.02.2026

This episode teaches threat analysis synthesis, where you transform scattered evidence into hypotheses, test those hypotheses, and arrive at a defensible statement of root cause and adversary objectives. You will learn how to avoid overconfidence by separating facts from assumptions, and how to update your narrative as new evidence appears. We will discuss methods for determining objectives, such...

Episode 58 — Packet Analysis Deep Listening: Decode Protocols and Reconstruct Conversations (Task 10) 14.02.2026

This episode explains packet analysis as “deep listening,” where you decode protocols and reconstruct conversations to confirm what actually occurred on the wire. You will learn when packet analysis is appropriate, what questions it can answer that logs cannot, and how to avoid common interpretation errors caused by incomplete captures or missing context. We will discuss how to recognize protocol...

Episode 57 — Network Traffic Analysis: Flows, Sessions, and Finding the Needle Fast (Task 10) 14.02.2026

This episode teaches network traffic analysis using flows and sessions as the main units of reasoning, helping you find meaningful patterns quickly when time and data volume are constraints. You will learn how to interpret flow records, session metadata, and common context fields to identify unusual communication, suspicious destinations, and data movement patterns that suggest staging or exfiltra...

Episode 56 — Malware Analysis Essentials: Static Clues, Behavioral Signals, and Scope Estimation (Task 10) 14.02.2026

This episode explains malware analysis essentials for analysts who need to make informed decisions quickly without becoming reverse engineers. You will learn the difference between static clues, such as hashes, strings, and metadata, and behavioral signals, such as process injection, persistence creation, and network callbacks, and how each helps determine what the malware is trying to achieve. We...

Episode 55 — Forensic Analysis in Practice: Timelines, Artifacts, and Proving What Happened (Task 14) 14.02.2026

This episode focuses on practical forensic thinking: building timelines, identifying artifacts, and proving what happened using evidence that can stand up to scrutiny. You will learn how timelines combine events from endpoints, network telemetry, identity logs, and application records, and how clock drift, missing logs, and normal administrative activity complicate interpretation. We will discuss...

Episode 54 — Forensic Analysis Fundamentals: Preservation, Collection, Integrity, and Chain of Custody (Task 14) 14.02.2026

This episode introduces forensic analysis fundamentals that support credible investigations and defensible outcomes, especially when incidents have legal, regulatory, or disciplinary implications. You will learn why preservation matters, how collection methods differ for volatile versus non-volatile data, and how integrity is maintained through hashing and controlled handling. We will define chain...

Episode 53 — Incident Handling End to End: Classification, Escalation, Notification, and Handoffs (Task 9) 14.02.2026

This episode explains incident handling as an end-to-end process that must remain consistent under stress, with clear classification, escalation logic, notification triggers, and disciplined handoffs. You will learn how incident categories and severity levels influence who gets involved, how fast decisions must be made, and what evidence must be collected before actions change the environment. We...

Episode 52 — Incident Containment Choices: Isolate, Block, Disable, or Deceive Safely (Task 13) 14.02.2026

This episode teaches how to make containment choices that reduce attacker capability quickly while minimizing unnecessary business disruption and preserving evidence for follow-on investigation. You will learn the practical difference between isolating a host, blocking network paths, disabling accounts, and using deception or sinkholing approaches, and how each option carries tradeoffs. We will di...

Episode 51 — Compare Monitoring Tools and Technologies: SIEM, EDR, NDR, SOAR, and IDS (Task 7) 14.02.2026

This episode compares major monitoring tools and technologies in terms of what they detect well, what blind spots they have, and what evidence they can produce during investigations. You will learn practical distinctions between SIEM aggregation, EDR endpoint visibility, NDR network behavior detection, IDS signature and anomaly concepts, and SOAR orchestration that accelerates response workflows....

Episode 50 — Logs and Alerts Triage: Prioritization, Enrichment, and Next-Best Questions (Task 8) 14.02.2026

This episode focuses on triage as a structured decision process: prioritize what matters, enrich what is missing, and ask the next-best questions that move you toward resolution. You will learn how to classify alerts by asset criticality, exposure, and potential impact, and how to avoid wasting time on low-value noise without ignoring real threats. We will discuss enrichment techniques such as add...

Episode 49 — Master Logs and Alerts: Sources, Normalization, Context, and Alert Fatigue (Task 7) 14.02.2026

This episode teaches how to master logs and alerts by understanding where telemetry comes from, how it is normalized, and why context determines whether an alert is actionable. You will learn common log sources across identity, endpoint, network, cloud, and applications, and how differences in timestamps, fields, and collection methods can distort interpretation. We will discuss normalization bene...

Episode 48 — Recognize Indicators of Compromise and or Attack With High Confidence (Task 7) 14.02.2026

This episode explains how to recognize indicators of compromise and indicators of attack with high confidence by combining context, validation, and careful interpretation of evidence. You will learn why a single indicator rarely proves compromise, how to validate indicators against known baselines, and how to avoid confirmation bias when evidence is incomplete. We will discuss different indicator...

Episode 47 — Tune Detection Use Cases: Reduce Noise Without Missing True Positives (Task 6) 14.02.2026

This episode focuses on tuning detection use cases so alerts become actionable without sacrificing the ability to catch real attacks. You will learn how noise is created by weak baselines, incomplete context, overly broad rules, and changes in environment behavior, and how tuning is a disciplined process rather than a one-time tweak. We will discuss methods like adding context fields, narrowing sc...

Listen to the Certified: The ISACA CCOA Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.