Jason Edwards
Certified: The ISACA CCOA Audio Course
Welcome to Certified: The ISACA CCOA Audio Course, a focused, audio-first program designed to help you build confidence in cybersecurity audit and assurance. If you’ve ever struggled to interpret an audit request, map security work to a control expectation, or explain evidence in a way that satisfies reviewers, you’re in the right place. I’ll guide you through the concepts that show up again and again in assurance work: how audit scope gets defined, how controls are evaluated, what strong evidence looks like, and how findings are framed. Expect clear explanations, practical language, and a ste...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 46 — Build Detection Use Cases That Map to Real Adversary Behavior (Task 6) 14.02.2026 17:27
This episode teaches how to build detection use cases that map to real adversary behavior rather than generic “bad event” lists. You will learn to start with an attacker objective, translate it into observable behaviors, and identify the telemetry sources required to detect those behaviors reliably. We will discuss how to write detection logic that is resilient to minor variations, such as focusin...
Episode 45 — Data Analytics for Detection: Baselines, Outliers, Correlation, and Meaningful Signals (Task 6) 14.02.2026 17:23
This episode explains data analytics concepts used in detection engineering, focusing on what makes a signal meaningful and how analysts avoid being overwhelmed by noise. You will define baselines, outliers, correlation, and contextual enrichment, then learn how each concept supports stronger alert quality and faster investigation. We will discuss why baseline building must account for business cy...
Episode 44 — Spaced Retrieval Review: Adversary Tactics, Techniques, and Procedures Rapid Recall (Task 18) 14.02.2026 15:30
This episode reinforces rapid recall of adversary tactics, techniques, and procedures by connecting them to the evidence and decisions analysts must make under pressure. You will revisit initial access patterns, privilege escalation behaviors, lateral movement signals, and exfiltration indicators, but framed as decision prompts you can use to answer exam questions efficiently. We will practice ide...
Episode 43 — Penetration Testing Explained for Defenders: Reading Results and Closing Gaps (Task 2) 14.02.2026 18:04
This episode explains penetration testing from a defender’s perspective, focusing on how to interpret results and convert them into prioritized remediation that reduces real risk. You will learn the difference between findings, evidence, and risk statements, and why a report’s severity labels should be validated against your asset criticality, exposure, and compensating controls. We will discuss c...
Episode 42 — Grasp Exploit Techniques: Privilege Escalation, Lateral Movement, and Living Off Land (Task 1) 14.02.2026 16:06
This episode explains key exploit techniques in a defender-friendly way, focusing on what each technique accomplishes and what evidence it leaves behind. You will learn how privilege escalation increases control, how lateral movement expands access across the environment, and how living off the land uses legitimate tools to blend in and reduce detection. We will discuss practical indicators such a...
Episode 41 — Walk Through Cyber Attack Stages: Recon, Exploit, Persist, and Exfiltrate (Task 1) 14.02.2026 15:35
This episode breaks down cyber attack stages into a practical sequence that helps you recognize where you are in an incident and what actions reduce risk most effectively. You will learn how reconnaissance, exploitation, persistence, and exfiltration each generate different artifacts and require different defensive priorities, from hardening and monitoring to containment and recovery. We will disc...
Episode 40 — Differentiate Attack Types: Ransomware, BEC, DDoS, and Data Theft (Task 1) 14.02.2026 14:37
This episode helps you differentiate major attack types by objectives, indicators, and the defensive priorities each one demands, which is a common exam requirement when time is limited and the best action must be chosen quickly. You will define ransomware, business email compromise, distributed denial of service, and data theft, then compare how each attack typically unfolds and what early warnin...
Episode 39 — Evaluate Threat Intelligence Sources: Credibility, Context, Timeliness, and Actionability (Task 3) 14.02.2026 15:04
This episode teaches how to evaluate threat intelligence sources so you can use intelligence effectively without being misled by hype, outdated indicators, or low-quality reporting. You will learn criteria such as credibility, context, timeliness, and actionability, and how each criterion affects whether an intelligence item should drive detection changes or incident decisions. We will discuss com...
Episode 38 — Profile Threat Actors and Agents: Motivation, Capability, and Likely Next Moves (Task 1) 14.02.2026 13:54
This episode explains how to profile threat actors and agents using motivation, capability, and constraints, so you can predict likely next moves and select appropriate defensive priorities. You will learn how different actor types, such as financially motivated criminals, insiders, or state-aligned groups, tend to differ in tradecraft, patience, and target selection. We will discuss why attributi...
Episode 37 — Trace Attack Vectors From First Contact to Initial Foothold (Task 1) 14.02.2026 15:20
This episode teaches how to trace attack vectors from first contact to initial foothold, which is critical for both incident response and exam questions that ask you to identify where defenses failed. You will learn common initial access methods such as phishing, credential abuse, exposed services, and third-party compromise, and how each leaves different artifacts in logs and endpoint telemetry....
Episode 36 — Spaced Retrieval Review: Cybersecurity Principles and Risk in One Narrative (Task 18) 14.02.2026 14:51
This episode provides a connected review of cybersecurity principles and risk concepts so you can recall them quickly and apply them to complex questions under exam timing. You will revisit governance, risk treatment choices, segmentation intent, identity boundaries, and evidence quality, but framed as a single narrative that mirrors how incidents unfold in real environments. We will practice link...
Episode 35 — Understand Web Application Risk: OWASP Patterns and Real-World Attack Paths (Task 2) 14.02.2026 15:43
This episode explains web application risk using common OWASP-style patterns and real-world attack paths that translate directly into exam scenarios. You will learn how issues like injection, broken access control, insecure session management, and misconfigured security headers create predictable exploitation opportunities. We will connect these patterns to practical evidence sources such as web s...
Episode 34 — Contain System and Endpoint Risk: Patching, Hardening, and EDR Realities (Task 2) 14.02.2026 16:19
This episode focuses on system and endpoint risk, where patching and hardening reduce the attack surface, but real operations include exceptions, delays, and imperfect coverage. You will learn how to prioritize patching based on exploitability, asset criticality, and exposure, and how hardening baselines reduce common misconfigurations that attackers rely on. We will discuss EDR realities, includi...
Episode 33 — Tackle Supply Chain Risk: Vendors, Dependencies, and Software Integrity Validation (Task 17) 14.02.2026 15:47
This episode explains supply chain risk as the set of threats that arise when your organization depends on vendors, cloud services, open-source libraries, and outsourced development or operations. You will learn how dependencies introduce risk through compromised updates, malicious packages, weak vendor controls, and limited visibility into third-party environments. We will discuss integrity valid...
Episode 32 — Manage Network Risk: Exposure, Lateral Movement Paths, and Resilience Weaknesses (Task 2) 14.02.2026 16:27
This episode teaches how to manage network risk by focusing on exposure points, lateral movement paths, and resilience weaknesses that amplify incident impact. You will learn to identify high-risk entry paths such as remote management access, exposed services, and weak segmentation, then connect those paths to real adversary behavior during reconnaissance and expansion. We will discuss resilience...
Episode 31 — Reduce Data Risk: Classification, Encryption, Retention, and Exfiltration Signals (Task 4) 14.02.2026 17:02
This episode explains how to reduce data risk by combining governance decisions with practical controls that influence exposure and detection. You will learn how classification drives handling rules, why encryption must be paired with key management discipline, and how retention policies reduce the amount of sensitive data available to steal. We will discuss how data risk shows up in real incident...
Episode 30 — Control Cloud Technology Risk: Identity Mistakes, Misconfigurations, and Shared Duties (Task 2) 14.02.2026 21:00
This episode focuses on cloud technology risk where the most damaging incidents often come from identity mistakes and misconfigurations rather than advanced exploits. You will learn how cloud permissions, roles, and keys create powerful access paths, and how small errors like wildcard permissions or long-lived credentials lead to outsized impact. We will discuss shared duties between cloud provide...
Episode 29 — Spot Application Risk Early: Insecure Design, Misconfigurations, and Input Abuse (Task 2) 14.02.2026 20:55
This episode explains application risk as a combination of design choices, configuration reality, and how attackers manipulate inputs to bypass intent. You will learn to recognize insecure design patterns such as missing trust boundaries, weak authorization logic, and unsafe defaults that become exploitable at scale. We will cover misconfigurations like exposed administrative endpoints, overly per...
Episode 28 — Use Cybersecurity Models to Think Clearly: Defense Layers and Zero Trust (Task 4) 14.02.2026 16:36
This episode teaches how to use cybersecurity models as thinking tools that improve decision-making in both exam scenarios and real incidents. You will learn how layered defense concepts help you identify where a control failed, where detection should have occurred, and which compensating controls reduce blast radius when prevention is bypassed. We will explain Zero Trust as a practical approach c...
Episode 27 — Clarify Roles and Responsibilities: SOC, IT, Legal, and Business Alignment (Task 20) 14.02.2026 18:35
This episode explains role clarity as a core operational control, because unclear responsibilities create delays, evidence gaps, and inconsistent decisions during incidents. You will learn how SOC, IT operations, legal, privacy, and business stakeholders typically interact, and how responsibility differs from authority in containment and notification decisions. We will explore common friction poin...
Episode 26 — Risk Management Deep Dive: Appetite, Registers, Exceptions, and Risk Communication (Task 4) 14.02.2026 19:58
This episode deepens risk management by focusing on how risk decisions are documented, communicated, and sustained when real-world constraints force tradeoffs. You will learn how risk appetite and tolerance guide prioritization, why risk registers matter for continuity, and how exceptions should be documented so they do not become permanent blind spots. We will discuss how analysts contribute to r...
Episode 25 — Risk Management Foundations: Identify, Assess, Treat, and Monitor Risk (Task 4) 14.02.2026 22:22
This episode builds the risk management foundation that underpins many CCOA questions, especially those involving prioritization, control selection, and communication with leadership. You will define risk in terms of likelihood and impact, then learn how identification, assessment, treatment, and monitoring form a repeatable lifecycle rather than a one-time exercise. We will connect risk language...
Episode 24 — Governance in Practice: Decision Rights, Policy Hierarchies, and Accountability (Task 21) 14.02.2026 19:12
This episode explains governance as the system that decides who can approve risk, who owns controls, and how policy becomes consistent action across the organization. You will learn how decision rights differ from day-to-day responsibilities, why policy hierarchies matter, and how accountability is proven through charters, approvals, and documented exceptions. We will discuss practical governance...
Episode 23 — Define Cybersecurity Objectives That Truly Support Business Outcomes (Task 19) 14.02.2026 17:56
This episode teaches how to define cybersecurity objectives that align with business outcomes, because exam scenarios often require prioritization decisions that balance risk, cost, and operational continuity. You will learn to translate business goals into security objectives that are specific, measurable, and defensible, such as reducing time to detect, improving recovery readiness, or limiting...
Episode 22 — Navigate Compliance Realities: Regulations, Controls Evidence, and Audit-Ready Operations (Task 21) 14.02.2026 20:03
This episode explains compliance as a practical operating reality, where the real challenge is producing credible evidence that controls exist, work, and are maintained over time. You will learn how regulations and frameworks translate into control requirements, and how analysts contribute through logging discipline, incident documentation, access reviews, and change tracking. We will define what...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.