Dr Jason Edwards
Certified: The ISACA CISA Audio Course
The Bare Metal Cyber CISA Audio Course is your complete, exam-focused companion for mastering the Certified Information Systems Auditor (CISA) certification. Designed for IT auditors, security professionals, and governance specialists, this comprehensive Audio Course transforms the ISACA exam blueprint into over one hundred clear, structured, and engaging episodes. Each lesson delivers practical explanations and real-world context across all five CISA domains—ranging from audit processes and IT governance to systems acquisition, operations, resilience, and information asset protection. Whether...
Author
Dr Jason Edwards
Category
Podcast website
Latest episode
Oct 14, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 31: IT Resource Management 06.07.2025 17:00
Resource management is foundational to IT governance, and the CISA exam tests your ability to evaluate how organizations allocate, monitor, and optimize people, hardware, software, and funding. This episode walks you through how auditors assess resource alignment with business objectives, identify misallocations, and verify that capacity planning is realistic and well-documented. Ready to start yo...
Episode 30: Practical Data Classification Techniques and Compliance 06.07.2025 18:06
Data classification is a key input to effective security and compliance auditing. In this episode, you’ll learn how to evaluate classification policies, review labeling and access controls, and understand how classification ties into privacy, retention, and audit scope. It’s a critical concept for mastering both Domains 2 and 5. Ready to start your journey with confidence? Learn more at BareMetalC...
Episode 29: Data Governance Program Fundamentals 06.07.2025 16:51
Governance doesn’t stop at systems—it includes data. This episode explores how data is owned, classified, and controlled across the enterprise. You’ll learn how to evaluate governance roles, policies, and procedures related to data quality, security, and accountability, which are all highly relevant to CISA exam questions. Ready to start your journey with confidence? Learn more at BareMetalCyber.c...
Episode 28: Privacy Program and Principles 06.07.2025 16:35
Data privacy is no longer optional—it’s a regulatory and reputational imperative. This episode covers privacy frameworks, laws, and controls auditors must assess during evaluations. You'll also learn how to audit privacy program design, policy enforcement, and data protection measures, all aligned with CISA Domain 2 objectives. Ready to start your journey with confidence? Learn more at BareMetalCy...
Episode 27: ERM Implementation and Evaluation Examples 06.07.2025 18:22
Building on the last episode, we now focus on how ERM is implemented and assessed. Through audit-relevant examples, you’ll learn how to evaluate risk ownership, review program maturity, and assess documentation quality. This practical insight will prepare you for case-based questions that test your understanding of ERM in action. Ready to start your journey with confidence? Learn more at BareMetal...
Episode 26: ERM Frameworks and Principles 06.07.2025 16:30
Enterprise Risk Management (ERM) is a key pillar of IT governance. This episode explains risk frameworks like COSO ERM and ISO 31000 and shows how auditors evaluate the structure, roles, and processes of ERM programs. You’ll gain a clear understanding of how strategic risk management connects with audit objectives on the CISA exam. Ready to start your journey with confidence? Learn more at BareMet...
Episode 25: Enterprise Architecture and Considerations 06.07.2025 16:06
Enterprise Architecture (EA) connects IT design to business strategy, and the CISA exam wants you to evaluate how well it supports organizational goals. In this episode, you’ll learn the components of EA, including frameworks like TOGAF, and how auditors assess EA governance, integration, and documentation across the enterprise. Ready to start your journey with confidence? Learn more at BareMetalC...
Episode 24: IT Policies, Standards, Procedures, and Practices 06.07.2025 16:27
Policies and standards form the backbone of IT governance, and this episode helps you understand how auditors evaluate their design, communication, and enforcement. You’ll explore the differences between policies, procedures, and guidelines, and how each supports control objectives—critical distinctions the CISA exam frequently tests. Ready to start your journey with confidence? Learn more at Bare...
Episode 23: Organizational Structure, IT Governance, and IT Strategy 06.07.2025 17:12
A solid grasp of organizational structure is key to evaluating IT governance. This episode walks you through reporting lines, governance committees, roles like CIO and CISO, and how strategy aligns with structure. You’ll also learn what the CISA exam expects you to know about evaluating the effectiveness of governance models. Ready to start your journey with confidence? Learn more at BareMetalCybe...
Episode 22: Laws, Regulations, and Industry Standards 06.07.2025 16:24
The CISA exam expects you to recognize and apply legal, regulatory, and industry-specific requirements to audit scenarios. This episode explores major compliance drivers like GDPR, HIPAA, and SOX, and explains how auditors assess adherence to these standards. You’ll also learn how to distinguish between laws, regulations, and frameworks—a critical distinction for exam success. Ready to start your...
Episode 21: Overview of Domain 2 – Management of IT 06.07.2025 15:20
Domain 2 doesn’t stop at governance—it also expects you to understand IT management practices. This episode introduces the key responsibilities of IT leaders, including resource allocation, vendor oversight, performance monitoring, and quality assurance. You’ll gain clarity on how management supports governance goals and what you’ll need to know for CISA exam questions on IT operations. Ready to s...
Episode 20: Overview of Domain 2 – Governance of IT 06.07.2025 17:49
Domain 2 shifts your focus from audit execution to how IT supports business objectives. This episode provides a strategic overview of IT governance principles, roles and responsibilities, and how auditors assess the effectiveness of governance frameworks. You'll gain a preview of the domain’s major topics—including risk management, IT strategy, and compliance—so you can prepare to master this high...
Episode 19: Quality Assurance and Improvement of Audit Processes 06.07.2025 36:40
ISACA expects CISA-certified professionals to uphold audit quality through structured QA practices. In this episode, we explore internal reviews, peer assessments, and continuous improvement models that strengthen the audit function. You'll learn how quality metrics are defined, how findings are tracked, and how QA fits into the professional standards you’ll be tested on. This is a vital component...
Episode 18: Audit Reporting and Communication Techniques 06.07.2025 20:22
Communicating audit results effectively is critical for both real-world auditors and CISA exam success. This episode teaches you how to write clear findings, structure reports logically, and deliver recommendations that management can act on. We’ll also explore techniques for presenting sensitive results diplomatically—a key soft skill that shows up in audit reporting scenarios on the test. Ready...
Episode 17: Practical Applications and Case Studies of Audit Data Analytics 06.07.2025 19:13
To truly master data analytics, you need to see it in action. This episode presents real-world examples and case studies showing how data analytics is used in fraud detection, operational audits, and compliance testing. You’ll understand the workflow from data extraction to final analysis and learn how CISA exam questions might present similar scenarios. It’s a high-value session that connects the...
Episode 16: Introduction to Audit Data Analytics Tools and Techniques 06.07.2025 18:33
Modern audits demand more than checklists—they require smart use of data. This episode introduces audit data analytics, explains the types of analytics (descriptive, diagnostic, predictive), and outlines how tools like ACL and IDEA support audit objectives. You’ll also learn how data analytics supports risk-based auditing, improves coverage, and enhances evidence quality—core areas for CISA Domain...
Episode 15: Audit Evidence Collection Techniques 06.07.2025 17:52
Effective audits rely on strong, defensible evidence. In this episode, we explore how to gather evidence using inquiry, observation, inspection, and re-performance. You'll learn how to assess evidence sufficiency, reliability, and relevance—three key terms you’ll see on the exam. We also discuss the auditor’s professional judgment in deciding which method to use and when. These foundational skills...
Episode 14: Audit Testing and Sampling Methodology 06.07.2025 17:37
Sampling is a heavily tested concept, and many CISA candidates struggle to distinguish between statistical and judgmental sampling. This episode demystifies sampling strategy, explains how to choose the right sample size, and shows you how to interpret sample-based results accurately. You'll also learn how testing ties directly into audit objectives. If you're unsure how to approach audit evidence...
Episode 13: Audit Project Management 06.07.2025 18:13
CISA candidates must not only understand audits—they must also understand how to manage them. This episode outlines the core principles of audit project management, including setting timelines, assigning resources, monitoring progress, and addressing unexpected changes. You’ll learn how to apply project management techniques to real audit environments and understand how these tasks align with ISAC...
Episode 12: Types of Controls and Audit Considerations 06.07.2025 18:44
The CISA exam tests your ability to evaluate and differentiate between control types—preventive, detective, corrective, and compensating. This episode breaks down each control category, explains when and how they’re used, and ties them to audit objectives. We also explore the difference between design and operational effectiveness, a key area where exam questions often challenge candidates. If you...
Episode 11: Advanced Risk Assessment Methods and Practical Examples 06.07.2025 16:55
Understanding risk is a cornerstone of the CISA exam, and this episode takes you beyond the basics. You’ll explore advanced techniques such as scenario-based analysis, quantitative vs. qualitative risk scoring, and how to apply them in real audit environments. Through practical examples, we connect these methods to the types of audit planning decisions you’ll be tested on. This deep dive gives you...
Episode 10: Fundamentals of Risk-Based Audit Planning 06.07.2025 18:00
Risk-based planning is at the core of IT auditing and a major theme on the CISA exam. This episode covers how to prioritize audits, identify risks, and design audit scopes that align with business impact—all framed for what you need to know to pass. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.
Episode 9: Types of Audits, Assessments, and Reviews 06.07.2025 17:45
Not all audits are the same. This episode teaches you how to distinguish between audit types—compliance, financial, operational, and more—so you can answer CISA questions with clarity. Learn the nuances that the exam loves to test. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.
Episode 8: IS Audit Standards, Guidelines, and Codes of Ethics 06.07.2025 17:48
Know the rules before you’re tested on them. This episode covers the ISACA audit standards and ethics you’ll need to master for Domain 1. You’ll learn what to memorize, how these principles shape audits, and why they matter for exam questions. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.
Episode 7: Overview of Domain 1 – Information Systems Auditing Process 06.07.2025 17:46
Domain 1 is the foundation of the CISA exam. In this episode, we break down what IS auditing means, how it fits into the bigger picture of IT governance, and what the exam expects you to understand about audit roles, risk, and controls. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.