Jason Edwards

Certified: The ISACA CGEIT Audio Course

Welcome to Certified: The ISACA CGEIT Audio Course. A focused, audio-first path through enterprise governance of IT, built for people who have responsibilities, deadlines, and real stakeholders. Here’s what you can expect: clear explanations that assume you’re capable, but don’t assume you have unlimited study time or a quiet desk. We’ll connect governance concepts to practical decisions—how organizations choose priorities, how they measure value, how they control risk, and how they manage resources across a portfolio. The tone stays professional and direct, because CGEIT rewards disciplined t...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 15, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Welcome to the ISACA CGEIT Audio Course 15.02.2026

If you’re responsible for how technology supports business outcomes, you already know the hard part is not choosing tools, it’s governing decisions. **Certified: The ISACA CGEIT Audio Course** is built for IT leaders, security leaders, program managers, auditors, and governance professionals who need a practical path to the CGEIT credential. You might be stepping into an enterprise role for the fi...

Episode 90 — Essential Terms: Plain-Language CGEIT Glossary for Fast Executive Recall (Glossary) 15.02.2026

This is the last episode. This episode delivers a plain-language glossary of essential CGEIT terms so you can recall definitions quickly and apply them to executive-level scenario questions without getting stuck in academic wording. You’ll reinforce core governance vocabulary such as decision rights, accountability, value delivery, benefits realization, portfolio management, risk appetite, toleran...

Episode 89 — Exam Acronyms: High-Yield Audio Reference for CGEIT Domains and Tasks (Glossary) 15.02.2026

This episode provides a high-yield acronym reference designed for fast recognition and accurate interpretation during scenario questions, where missing a single term can change what the “best answer” looks like. You’ll review the most common governance, risk, and resource acronyms you are likely to encounter in CGEIT study materials and workplace usage, with clear explanations of what each one mea...

Episode 88 — Exam-day tactics: calm two-pass questions and “best answer” governance logic (Exam) 15.02.2026

This episode gives you exam-day tactics tailored to CGEIT-style scenario questions, where multiple answers sound plausible and the goal is to choose the one that best reflects governance logic, accountability, and evidence. You’ll learn a calm two-pass approach: first pass to secure confident points quickly, and second pass to handle ambiguous scenarios by identifying the decision being tested, th...

Episode 87 — Align data governance to analytics and AI needs without losing control (1C1) 15.02.2026

This episode explains how to align data governance to analytics and AI needs so the enterprise can increase insight and automation without losing control over privacy, quality, lineage, and accountability. You’ll learn how analytics and AI expand risk surfaces through broader data access, more data copies, new derived datasets, and model-driven decisions that can amplify data quality problems, bia...

Episode 86 — Prevent architecture drift by governing standards, patterns, and waivers consistently (1B5) 15.02.2026

This episode focuses on preventing architecture drift, meaning the slow spread of inconsistent platforms, integration methods, and design choices that increase cost and risk over time. You’ll learn how governance keeps architecture coherent by maintaining clear standards and approved patterns, embedding architecture reviews into decision checkpoints, and running a waiver process that is evidence-b...

Episode 85 — Handle “shadow IT” using governance, incentives, and service improvements (1B6) 15.02.2026

This episode teaches you how to handle shadow IT using governance that addresses root causes, because simply banning unsanctioned tools often drives the behavior underground instead of reducing risk. You’ll learn how shadow IT emerges from unmet needs like speed, usability, missing capabilities, cost friction, or slow approvals, and how governance should respond by improving sanctioned services wh...

Episode 84 — Manage exceptions and deviations without undermining governance credibility (1A1) 15.02.2026

This episode explains how to manage exceptions and deviations in a way that preserves governance credibility, because uncontrolled exceptions are how standards quietly collapse while leaders still believe controls exist. You’ll learn how a governance-grade exception process defines eligibility criteria, required evidence, approval authority, compensating controls, expiration dates, and review cade...

Episode 83 — Develop and communicate risk policies and standards people can follow (Task 38) 15.02.2026

This episode focuses on developing and communicating risk policies and standards that people can actually follow, because governance fails when requirements are unclear, unrealistic, or disconnected from day-to-day workflows. You’ll learn how to write policy intent in outcome terms, then support it with standards that define what “compliant” looks like using testable requirements, approved pattern...

Episode 82 — Align IT and information risk management with the enterprise ERM framework (Task 37) 15.02.2026

This episode teaches you how to align IT and information risk management with the enterprise ERM framework so risk decisions are comparable across the business and escalation paths actually work when tradeoffs get difficult. You’ll learn how alignment requires shared risk language, consistent categorization, compatible scoring methods, and a governance cadence that connects IT risk signals to ente...

Episode 81 — Align IT processes with legal and regulatory compliance objectives every time (Task 36) 15.02.2026

This episode explains how to align IT processes with legal and regulatory compliance objectives so compliance is predictable and repeatable, not dependent on individual memory or last-minute reviews. You’ll learn how to translate obligations into process requirements by embedding controls and evidence expectations into the way work is requested, designed, approved, changed, and operated, including...

Episode 80 — Monitor and report adherence to risk policies and standards continuously (Task 35) 15.02.2026

This episode explains how to monitor and report adherence to risk policies and standards continuously, because governance only works when it can detect drift early and drive corrective action before risk accumulates into an incident or compliance failure. You’ll learn how continuous adherence monitoring relies on clear, testable standards, measurable indicators, and defined ownership for respondin...

Episode 79 — Establish comprehensive IT and information risk management programs enterprise-wide (Task 34) 15.02.2026

This episode focuses on establishing comprehensive IT and information risk management programs that operate enterprise-wide, meaning they are consistent across business units while still adaptable to different risk profiles and regulatory demands. You’ll learn what “comprehensive” implies for governance: clear program scope, defined roles and decision rights, standardized methods for assessment an...

Episode 78 — Apply practical risk assessment methods that support real decisions (4B4) 15.02.2026

This episode teaches you how to apply practical risk assessment methods that support real decisions, rather than producing reports that look rigorous but don’t change outcomes. You’ll learn how to select assessment approaches based on decision needs, such as qualitative methods for fast triage, semi-quantitative scoring for portfolio comparisons, and more detailed analysis when high-impact exposur...

Episode 77 — Run the risk management lifecycle from identification to monitoring and response (4B3) 15.02.2026

This episode explains the risk management lifecycle as a repeatable governance loop that moves from identification to assessment, treatment decisions, implementation, monitoring, and response, with documented accountability at each stage. You’ll learn how to prevent lifecycle breakdowns such as risks identified but never assessed, assessments completed but never acted on, or controls implemented b...

Episode 76 — Identify business risk, exposures, and threats with clarity and shared language (4B2) 15.02.2026

This episode teaches you how to identify business risk, exposures, and threats using clear, shared language that enables executives and technical teams to align quickly on what matters and what to do next. You’ll learn to translate technical conditions into business exposure, such as how a weak access model becomes fraud risk, how inconsistent data handling becomes regulatory exposure, or how frag...

Episode 75 — Govern risk across IT-enabled capabilities, processes, and services end-to-end (4B1) 15.02.2026

This episode focuses on governing risk end-to-end across IT-enabled capabilities, processes, and services, because risk does not respect org charts and often emerges in handoffs, integrations, and shared dependencies. You’ll learn how end-to-end risk governance connects strategy, architecture, delivery, operations, vendors, and information assets into a single view of exposure that leaders can act...

Episode 74 — Set risk appetite and tolerance that leaders will enforce consistently (4A3) 15.02.2026

This episode teaches you how to set risk appetite and tolerance in a way leaders can enforce consistently, which is critical because many governance failures come from appetite statements that are too vague to guide decisions. You’ll learn to express appetite in outcome terms, such as acceptable downtime, data exposure thresholds, compliance deviation boundaries, or financial loss limits, and to c...

Episode 73 — Integrate IT risk governance into enterprise risk management without friction (4A2) 15.02.2026

This episode explains how to integrate IT risk governance into enterprise risk management so risk is evaluated consistently, escalations work smoothly, and leadership can compare tradeoffs across the enterprise without translation problems. You’ll learn how integration depends on shared language, common risk categories, aligned reporting cadence, and clear boundaries for what IT risk governance ow...

Episode 72 — Select risk frameworks and standards that fit enterprise complexity and maturity (4A1) 15.02.2026

This episode teaches you how to select risk frameworks and standards that fit the enterprise’s complexity, regulatory reality, and governance maturity, because choosing an ill-fitting approach creates bureaucracy, confusion, or gaps that the exam expects you to notice. You’ll learn how to evaluate fit by asking what decisions the framework must support, what evidence must be produced, how risk app...

Episode 71 — Define risk optimization as informed tradeoffs, not risk avoidance (4 Risk Optimization) 15.02.2026

This episode defines risk optimization as the disciplined practice of making informed tradeoffs that protect enterprise objectives while still enabling delivery, innovation, and measurable value. You’ll distinguish optimization from avoidance by focusing on decisions that balance likelihood, impact, cost, and opportunity, rather than trying to eliminate risk in ways that stall the business. We’ll...

Episode 70 — Base improvement initiatives on performance results, not politics or anecdotes (Task 33) 15.02.2026

This episode explains how to base improvement initiatives on performance results so governance drives meaningful change instead of chasing politics, personal preferences, or one-off anecdotes. You’ll learn how to interpret performance data, trend indicators, exception patterns, audit findings, and stakeholder feedback as inputs to improvement prioritization, then translate those inputs into initia...

Episode 69 — Establish performance management across investments, processes, and services consistently (Task 32) 15.02.2026

This episode teaches you how to establish performance management consistently across investments, processes, and services so governance can see enterprise-wide performance, spot drift early, and enforce accountability at the right level. You’ll learn how to build a coherent performance model that connects strategy to portfolio outcomes, operational service performance, risk and compliance indicato...

Episode 68 — Evaluate benefits realization across investments, processes, and services for truth (Task 31) 15.02.2026

This episode focuses on evaluating benefits realization across investments, processes, and services to ensure governance gets the truth about value, not optimistic narratives or isolated success stories. You’ll learn how benefits realization must be consistent across the portfolio, using common definitions, baselines, measurement windows, and evidence standards, so executives can compare outcomes...

Episode 67 — Align IT investment management with enterprise investment governance practices (Task 30) 15.02.2026

This episode explains how to align IT investment management with enterprise investment governance so IT is not treated as a special case that escapes the discipline applied to other capital and strategic investments. You’ll learn how enterprise governance expectations—such as standardized business case requirements, risk-based approval thresholds, portfolio reporting, and benefits accountability—s...

Listen to the Certified: The ISACA CGEIT Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.