Dr Jason Edwards

Certified: The ISACA CISA Audio Course

The Bare Metal Cyber CISA Audio Course is your complete, exam-focused companion for mastering the Certified Information Systems Auditor (CISA) certification. Designed for IT auditors, security professionals, and governance specialists, this comprehensive Audio Course transforms the ISACA exam blueprint into over one hundred clear, structured, and engaging episodes. Each lesson delivers practical explanations and real-world context across all five CISA domains—ranging from audit processes and IT governance to systems acquisition, operations, resilience, and information asset protection. Whether...

Author

Dr Jason Edwards

Category

Education

Podcast website

baremetalcyber.com

Latest episode

Oct 14, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 81: Planning Effective Information Systems Audits 06.07.2025

Audit planning is the foundation of a successful engagement. In this episode, you will learn how to define audit scope, assess risk, allocate resources, and align objectives with organizational priorities. The CISA exam emphasizes your ability to create structured, risk-based audit plans that support clear execution. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

Episode 80: Evidence Collection and Digital Forensics 06.07.2025

Auditors may need to evaluate how evidence is preserved and used in investigations. This episode introduces forensic readiness, chain of custody, data integrity controls, and tool validation. You will also explore how forensic practices align with legal requirements and audit objectives in Domain 5. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

Episode 79: Security Incident Response Management 06.07.2025

Incident response is a structured process that minimizes damage and recovers operations. This episode covers detection, escalation, containment, recovery, and reporting. You will learn how to evaluate incident handling procedures, assess team readiness, and align response plans with audit requirements. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

Episode 78: Security Monitoring Tools and Techniques 06.07.2025

Ongoing monitoring is vital for detecting and responding to threats. In this episode, you will explore how to evaluate log management, SIEM systems, network monitoring tools, and intrusion detection. Auditors must assess coverage, alerting capabilities, and response documentation to support Domain 5 objectives. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

Episode 77: Security Testing Tools and Techniques 06.07.2025

Security testing reveals weaknesses before attackers can exploit them. This episode explains how to audit vulnerability scanning, penetration testing, static code analysis, and system hardening. You will also learn how to interpret test results and validate remediation, which are common elements in Domain 5 questions. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

Episode 76: Information System Attack Methods and Techniques 06.07.2025

To audit effectively, you must understand how systems are attacked. This episode introduces common techniques such as phishing, malware, denial of service, and SQL injection. You will learn how to assess organizational preparedness and how this knowledge applies to audit procedures and CISA scenario questions. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

Episode 75: Security Awareness Training and Programs 06.07.2025

Human error is a top cause of security breaches. This episode covers how to evaluate security awareness training programs, including content quality, delivery methods, tracking, and feedback mechanisms. You will also learn how to link training effectiveness with audit findings and policy compliance. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

Episode 74: Mobile, Wireless, and IoT Device Security 06.07.2025

Endpoint diversity brings complexity to audits. In this episode, you will learn how to evaluate controls for mobile devices, wireless networks, and Internet of Things technologies. Topics include encryption, mobile device management, authentication, and endpoint hardening, all of which are relevant to CISA Domain 5. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

Episode 73: Cloud and Virtualized Environments 06.07.2025

Cloud and virtual systems require unique controls and audit approaches. This episode focuses on how to evaluate cloud security, shared responsibility models, virtual machine management, and containerization. You will also explore how to assess compliance and data protection within cloud-based infrastructures. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

Episode 72: Public Key Infrastructure (PKI) 06.07.2025

Public Key Infrastructure supports digital trust by enabling secure authentication and communication. In this episode, you will learn how to audit PKI components, such as certificate authorities, digital signatures, and key lifecycles. Understanding how PKI works and how to evaluate its controls is vital for passing Domain 5. Ready to start your journey with confidence? Learn more at BareMetalCybe...

Episode 71: Data Encryption Methods and Controls 06.07.2025

Encryption is one of the most powerful tools for protecting sensitive data. This episode explains how to audit encryption in transit and at rest, evaluate key management practices, and assess alignment with organizational policies and legal requirements. These concepts are essential for Domain 5 and appear frequently in security-related CISA exam questions. Ready to start your journey with confide...

Episode 70: Data Loss Prevention 06.07.2025

Data loss prevention (DLP) tools and policies help prevent unauthorized exposure of sensitive information. In this episode, you will learn how to evaluate DLP strategy, endpoint protections, outbound filtering, and audit logging. This is a highly tested topic that connects information protection with compliance and incident response. Ready to start your journey with confidence? Learn more at BareM...

Episode 69: Network and Endpoint Security 06.07.2025

Network and endpoint security controls are essential for protecting IT infrastructure. This episode explains how to audit firewalls, intrusion detection systems, antivirus software, and patching procedures. You will also learn how to assess monitoring practices and system hardening strategies for Domain 5. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

Episode 68: Identity and Access Management (IAM) 06.07.2025

Access control is a critical concept tested throughout the CISA exam. In this episode, you will learn how to audit identity provisioning, authentication mechanisms, access reviews, and privilege management. Understanding IAM controls will help you confidently address scenarios involving security, compliance, and fraud prevention. Ready to start your journey with confidence? Learn more at BareMetal...

Episode 67: Physical and Environmental Controls 06.07.2025

Physical security is a foundational element of protecting information systems. This episode covers perimeter defenses, badge access, fire suppression, climate control, and secure equipment disposal. You will learn how to evaluate the effectiveness of these controls and how questions about physical risks show up on the CISA exam. Ready to start your journey with confidence? Learn more at BareMetalC...

Episode 66: Information Asset Security Frameworks, Standards, and Guidelines 06.07.2025

Security frameworks provide the structure for implementing effective controls. In this episode, you will learn how to evaluate ISO 27001, NIST, COBIT, and organizational guidelines. You will also explore how auditors assess alignment with policies and determine whether information protection is governed effectively. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

Episode 65: Overview of Domain 5 – Protection of Information Assets 06.07.2025

Domain 5 is all about securing information against unauthorized access, alteration, or loss. This episode provides a strategic overview of confidentiality, integrity, and availability principles and introduces the areas covered by this domain. You will see how security audits connect with governance, operations, and compliance. Ready to start your journey with confidence? Learn more at BareMetalCy...

Episode 64: Disaster Recovery Planning Fundamentals 06.07.2025

Disaster recovery focuses on restoring IT systems after an outage or catastrophic event. In this episode, you will learn how to audit DR plans, assess backup infrastructure, evaluate recovery site readiness, and verify testing procedures. DR planning is a key area of the CISA exam, especially for questions on system availability and continuity. Ready to start your journey with confidence? Learn mo...

Episode 63: Developing and Maintaining a Business Continuity Plan 06.07.2025

Business continuity planning ensures the organization can operate during and after disruptions. This episode explains how auditors evaluate continuity plan development, critical process identification, training, and documentation. You will also learn how plans are tested and updated to remain effective under real-world conditions. Ready to start your journey with confidence? Learn more at BareMeta...

Episode 62: Data Backup, Storage, and Restoration Practices 06.07.2025

Backup and restoration processes are critical for protecting data integrity and ensuring continuity. In this episode, you will learn how to evaluate backup frequency, storage media security, offsite storage protocols, and restoration testing. Understanding these controls is essential for CISA exam topics related to recovery readiness and operational risk. Ready to start your journey with confidenc...

Episode 61: System and Operational Resilience 06.07.2025

Operational resilience is about sustaining essential services under stress. This episode explains how auditors evaluate systems for fault tolerance, high availability, and continuous operation. You will learn how to assess risk mitigation strategies, redundancy planning, and the effectiveness of proactive monitoring. These areas are core to Domain 4 exam questions. Ready to start your journey with...

Episode 60: Conducting a Business Impact Analysis (BIA) 06.07.2025

The business impact analysis is a foundational activity in resilience planning. In this episode, you will learn how to audit BIA processes, assess documentation of critical functions, and evaluate recovery time and recovery point objectives. CISA candidates must understand how to validate BIA results and tie them to continuity plans. Ready to start your journey with confidence? Learn more at BareM...

Episode 59: Overview of Business Resilience 06.07.2025

Business resilience ensures that critical operations can continue through disruption. This episode introduces the core concepts of business continuity, disaster recovery, redundancy, and failover. You will learn how to evaluate resilience strategies and how they relate to the audit objectives covered in Domain 4 and beyond. Ready to start your journey with confidence? Learn more at BareMetalCyber....

Episode 58: Database Management Practices 06.07.2025

Databases are central to most IT operations, and auditors must ensure they are managed securely and efficiently. This episode covers access controls, backup procedures, configuration changes, and performance optimization. You will gain insight into how to audit database environments using the lens of confidentiality, integrity, and availability. Ready to start your journey with confidence? Learn m...

Episode 57: IT Service Level Management 06.07.2025

Service level agreements define performance expectations between IT and the business. In this episode, you will learn how to audit SLA creation, monitoring, breach handling, and vendor service reporting. These concepts are tested frequently in Domain 4, especially in questions that examine governance and performance alignment. Ready to start your journey with confidence? Learn more at BareMetalCyb...

Listen to the Certified: The ISACA CISA Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.