Dr Jason Edwards
Certified: The ISACA CISA Audio Course
The Bare Metal Cyber CISA Audio Course is your complete, exam-focused companion for mastering the Certified Information Systems Auditor (CISA) certification. Designed for IT auditors, security professionals, and governance specialists, this comprehensive Audio Course transforms the ISACA exam blueprint into over one hundred clear, structured, and engaging episodes. Each lesson delivers practical explanations and real-world context across all five CISA domains—ranging from audit processes and IT governance to systems acquisition, operations, resilience, and information asset protection. Whether...
Author
Dr Jason Edwards
Category
Podcast website
Latest episode
Oct 14, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 56: Operational Log Management 06.07.2025 17:38
Logs provide critical evidence for detecting incidents and monitoring system health. This episode explains how to audit log collection, retention, analysis, and alerting mechanisms. You will also learn how auditors evaluate whether logs support accountability, forensics, and compliance with organizational policies. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.
Episode 55: Configuration and Patch Management Processes 06.07.2025 17:37
Configuration and patch controls are essential for system stability and security. In this episode, you will learn how to audit configuration baselines, patch deployment processes, exception handling, and rollback procedures. These controls are highly relevant for questions involving system hardening and change assurance. Ready to start your journey with confidence? Learn more at BareMetalCyber.com...
Episode 54: Change Management Processes 06.07.2025 16:29
Effective change management minimizes disruption and maintains control over the IT environment. This episode walks you through change request procedures, approval workflows, emergency change handling, and audit trail verification. Mastering these elements is essential for answering CISA questions on change governance. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.
Episode 53: Problem Management and Root Cause Analysis 06.07.2025 16:20
Problem management focuses on eliminating the underlying causes of incidents. In this episode, you will learn how to audit problem detection, investigation, root cause analysis, and resolution tracking. We also cover the importance of documentation and trend analysis, which are key areas for Domain 4 exam preparation. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.
Episode 52: Incident Management Best Practices 06.07.2025 16:28
When things go wrong, incident management ensures that services are restored quickly and effectively. This episode explains how to audit detection procedures, escalation paths, incident logs, and resolution workflows. You will learn how incident response aligns with audit standards and how these topics are framed in the CISA exam. Ready to start your journey with confidence? Learn more at BareMeta...
Episode 51: Systems Availability and Capacity Management 06.07.2025 14:56
Auditors must verify that IT systems are designed and managed to meet performance demands. This episode explores how to evaluate availability strategies, capacity planning, monitoring tools, and escalation processes. Learn how these elements support operational resilience and how they appear in Domain 4 exam questions. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.
Episode 50: Shadow IT and End-User Computing 06.07.2025 18:14
Shadow IT introduces risk outside the view of central IT. In this episode, you will learn how to identify and audit unauthorized tools, spreadsheets, applications, and systems created by business units. We also cover end-user computing controls, policies, and monitoring, which are increasingly tested in Domain 4 scenarios. Ready to start your journey with confidence? Learn more at BareMetalCyber.c...
Episode 49: System Interfaces 06.07.2025 18:40
When systems talk to each other, auditors must ensure that the communication is controlled and secure. This episode explores interface types (manual and automated), error checking, data reconciliation, and exception handling. You’ll gain clarity on how to audit inter-system interactions—knowledge that’s essential for Domain 4. Ready to start your journey with confidence? Learn more at BareMetalCyb...
Episode 48: Job Scheduling and Production Process Automation 06.07.2025 17:42
This episode covers how auditors evaluate job scheduling systems, batch processing, and automated task workflows. You’ll learn how to assess controls for error handling, reprocessing, and change approval—all of which are frequently tested in Domain 4 scenarios involving IT operations and reliability. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.
Episode 47: IT Asset Management 06.07.2025 17:28
IT asset management is more than keeping an inventory—it’s about control, accountability, and lifecycle oversight. In this episode, you’ll learn how to audit asset acquisition, tagging, usage, and disposal. We also explore how asset management intersects with compliance and risk, making it a key topic for your CISA exam prep. Ready to start your journey with confidence? Learn more at BareMetalCybe...
Episode 46: IT Components 06.07.2025 18:24
Understanding the elements that make up the IT environment is essential for audit readiness. This episode breaks down how to evaluate the hardware, software, network, and data assets that support critical business processes. You’ll also learn how to audit system dependencies and asset configuration controls, all mapped to Domain 4 objectives. Ready to start your journey with confidence? Learn more...
Episode 45: Overview of Domain 4 – Information Systems Operations & Business Resilience 06.07.2025 18:11
Domain 4 shifts focus to the reliability and sustainability of IT operations. In this episode, you’ll gain an overview of operational controls, availability, service delivery, incident response, and business continuity. We highlight what ISACA wants you to know about managing daily operations and preparing for disruptions. Ready to start your journey with confidence? Learn more at BareMetalCyber.c...
Episode 44: Post-Implementation Review 06.07.2025 18:48
Once a system is deployed, the work isn’t over—auditors still need to assess whether objectives were achieved. This episode teaches you how to conduct a post-implementation review, evaluate project outcomes, assess stakeholder satisfaction, and document lessons learned. It’s a must-know process for Domain 3 exam questions. Ready to start your journey with confidence? Learn more at BareMetalCyber.c...
Episode 43: System Migration, Infrastructure Deployment, and Data Conversion 06.07.2025 19:18
CISA candidates must understand the risks and controls involved in moving systems and data. This episode explains how to audit system migrations, infrastructure rollouts, and data conversion processes. You’ll learn how to identify red flags during transitions and verify that testing, backups, and validation controls are in place. Ready to start your journey with confidence? Learn more at BareMetal...
Episode 42: Implementation Configuration and Release Management 06.07.2025 19:24
Poor configuration control can lead to outages, vulnerabilities, and audit findings. In this episode, we cover how to evaluate release planning, version control, rollback procedures, and configuration documentation. You’ll understand how to audit change approvals and production readiness, giving you the tools to answer configuration-related questions with confidence. Ready to start your journey wi...
Episode 41: System Readiness and Implementation Testing 06.07.2025 18:05
Before a new system goes live, auditors must confirm that it’s ready for production. This episode explains how to evaluate readiness through testing, validation, and stakeholder approvals. You’ll learn how to assess user acceptance testing (UAT), implementation criteria, and go/no-go decisions—all key exam topics in Domain 3. Ready to start your journey with confidence? Learn more at BareMetalCybe...
Episode 40: Control Identification and Design 06.07.2025 17:59
Strong control design starts early in the system lifecycle. In this episode, you'll learn how auditors assess whether appropriate controls have been identified and designed during planning, development, and implementation. From input validation to segregation of duties, this session aligns closely with Domain 3 control objectives and audit best practices. Ready to start your journey with confidenc...
Episode 39: Agile, DevOps, and Modern SDLC Approaches 06.07.2025 18:01
Agile and DevOps are increasingly popular in IT development, and the CISA exam expects you to understand how to audit these environments. This episode explains how control requirements shift in iterative, fast-paced delivery models. You'll learn how to audit sprints, CI/CD pipelines, backlog grooming, and quality gates in flexible but compliant ways. Ready to start your journey with confidence? Le...
Episode 38: Waterfall and Traditional SDLC 06.07.2025 18:38
Understanding the traditional software development lifecycle is essential for CISA candidates. This episode explains each phase of the waterfall model and the corresponding audit controls. You'll learn how to evaluate documentation, testing, change controls, and stakeholder approvals, all of which are commonly tested under Domain 3 of the CISA exam. Ready to start your journey with confidence? Lea...
Episode 37: Business Case and Feasibility Analysis 06.07.2025 18:37
Before a project begins, auditors must evaluate whether it’s justified. This episode focuses on auditing business case development, feasibility assessments, and benefit realization. You'll learn how to assess whether proposed IT investments align with strategic goals and whether cost, risk, and return have been properly considered—core concepts in Domain 3. Ready to start your journey with confide...
Episode 36: Project Governance and Management 06.07.2025 17:46
Project governance ensures IT initiatives deliver value and align with business goals. This episode covers how auditors evaluate project oversight, milestone tracking, risk management, and stakeholder involvement. You'll also learn how to audit project management methodologies like PMBOK and Agile, which the CISA exam often references in Domain 3 scenarios. Ready to start your journey with confide...
Episode 35: Overview of Domain 3 – Information Systems Acquisition, Development & Implementation 06.07.2025 17:04
Domain 3 focuses on the controls and governance involved in acquiring and implementing IT solutions. This episode provides a strategic overview of project governance, system development methodologies, and how these elements align with audit objectives. If you're looking to understand what ISACA expects from auditors in development environments, this is your starting point. Ready to start your jour...
Episode 34: Quality Assurance and Quality Management of IT 06.07.2025 16:49
The CISA exam expects candidates to understand how IT quality is planned, implemented, and improved over time. This episode covers quality assurance policies, continuous improvement practices, metrics, and reviews. You’ll learn how to audit the effectiveness of IT quality management frameworks and ensure they support reliable and consistent service delivery. Ready to start your journey with confid...
Episode 33: IT Performance Monitoring and Reporting 06.07.2025 17:13
Audit success depends on knowing how to evaluate IT performance. This episode explains how key performance indicators (KPIs) and reports are used to measure service delivery, support governance goals, and drive corrective action. You’ll learn how to assess the accuracy, relevance, and alignment of performance data with business strategy—just like the CISA exam will test. Ready to start your journe...
Episode 32: IT Vendor Management 06.07.2025 18:06
Managing third-party risk is a key topic on the CISA exam, and this episode dives into how to audit vendor selection, onboarding, performance evaluation, and contract compliance. You'll learn how to assess risk from service providers, examine contract clarity, and ensure that controls are in place to manage vendor performance effectively across the lifecycle. Ready to start your journey with confi...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.