Jason Edwards
Certified: The ISC2 CC Audio Course (2026 Version)
This is the 2026 Edition. Certified: The ISC2 CC (2026) Audio Course is a narrated, audio-first learning experience for people preparing for the upcoming ISC2 Certified in Cybersecurity exam. It is built for new and aspiring cybersecurity professionals, career changers, IT support staff, help desk technicians, students, and anyone who wants a structured entry point into security without needing slides, labs, or long reading assignments. The course assumes you may be new to formal cybersecurity language, but it does not talk down to you. Each episode is designed to help you understand the ideas...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 34 — Secure AI Data Pathways with Segmentation Zero Trust and Protected Environments 22.04.2026 16:57
This episode examines how AI data pathways should be secured from input to storage to output so that sensitive information is not exposed through convenience, weak boundaries, or excessive integration. On the exam, this topic fits naturally with segmentation, least privilege, monitoring, and zero trust because AI systems often touch knowledge bases, shared files, user prompts, APIs, and model outp...
Episode 33 — Layer Defense in Depth and Zero Trust into Architecture 22.04.2026 17:21
This episode explains how defense in depth and zero trust strengthen security architecture by reducing dependence on any single control, assumption, or network location. For certification purposes, you should know that defense in depth uses multiple complementary safeguards across technology, people, and process, while zero trust emphasizes continuous verification, limited trust, and access decisi...
Episode 32 — Design Segmentation with Firewall Zones VLANs and Micro-Segmentation 22.04.2026 18:42
This episode focuses on network segmentation as a practical method for reducing attack paths, limiting exposure, and improving control over how users, systems, and services communicate. On the exam, segmentation questions often test whether you can distinguish broad separation methods such as firewall zones and VLANs from more granular approaches like micro-segmentation, while also understanding w...
Episode 31 — Recognize Embedded Systems ICS and IoT Security Boundaries 22.04.2026 18:26
This episode explains how embedded systems, industrial control systems, and Internet of Things devices create unique security boundaries that differ from traditional desktops, servers, and general-purpose enterprise platforms. For the exam, you need to understand that these technologies often emphasize availability, safety, long operational life, limited patching windows, proprietary protocols, an...
Episode 30 — Secure Wireless Concepts Across Wi-Fi Bluetooth and Everyday Connections 22.04.2026 17:50
This episode explains wireless security across common technologies such as Wi-Fi and Bluetooth, with attention to the convenience they provide and the risks they introduce when configuration, authentication, or user behavior is weak. For certification study, you should know the basic purpose of wireless protections, the value of strong encryption and secure pairing, and the importance of limiting...
Episode 29 — Interpret Firewalls Ports and Applications as Network Control Points 22.04.2026 16:18
This episode focuses on firewalls, ports, and application traffic as practical control points that shape how systems communicate and how defenders enforce policy. On the exam, you should understand that ports are associated with services, firewalls filter traffic according to rules, and application awareness can provide more precise control than simple address-based decisions alone. Examples such...
Episode 28 — Map OSI TCP IP IPv4 IPv6 and VPN Concepts Clearly 22.04.2026 17:13
This episode explains the networking foundations that cybersecurity professionals must understand in order to interpret traffic, communicate clearly, and make better control decisions. For the exam, you are expected to know the purpose of the OSI and TCP/IP models, recognize the role of addressing in IPv4 and IPv6, and understand how virtual private networks protect traffic across less trusted net...
Episode 27 — Apply IAM Concepts Through Role Lifecycle and Access Scenarios 22.04.2026 18:33
This episode brings identity and access management together by showing how role definition, provisioning, review, adjustment, and deprovisioning play out across real workplace scenarios. On the exam, IAM questions often require you to spot where the lifecycle broke down, such as unclear role ownership, excessive inherited permissions, weak approval evidence, or delayed access removal after a statu...
Episode 26 — Evaluate Access Control Models for Realistic Logical Control Choices 22.04.2026 17:29
This episode introduces the major access control models and explains how they influence logical security decisions in real systems rather than existing only as theory for exam memorization. You will review concepts such as discretionary access control, mandatory access control, role-based access control, and attribute-based access control, while focusing on what each model is trying to achieve and...
Episode 25 — Enforce Least Privilege and Separation of Duties in Daily Decisions 22.04.2026 16:03
This episode explains how least privilege and separation of duties work together to reduce both error and abuse by ensuring that people receive only the access they need and that critical actions are not controlled by one person alone. For the exam, you should recognize that these are not abstract principles but practical control decisions that affect approvals, access design, transaction review,...
Episode 24 — Control AI Bots and Service Accounts Through Lifecycle and Least Privilege 22.04.2026 16:45
This episode examines AI bots and service accounts as nonhuman identities that still require the same discipline applied to people, including ownership, approval, limited permissions, monitoring, and timely cleanup. On the exam, these identities matter because they often accumulate broad access quietly, interact with sensitive data, and can be overlooked during normal review cycles even though the...
Episode 23 — Compare IAM Frameworks and Tools Without Losing the Lifecycle View 22.04.2026 15:29
This episode compares identity and access management frameworks and supporting tools while keeping attention on the full lifecycle from onboarding to review and removal. For certification purposes, it is easy to become distracted by product features or terminology, but the exam is more likely to reward an understanding of how governance, provisioning, authentication, authorization, review, and dep...
Episode 22 — Deprovision Access Cleanly When Roles People or Systems Change 22.04.2026 16:22
This episode focuses on deprovisioning as a critical security process that must happen quickly and accurately when users leave, responsibilities change, contractors roll off, or systems are retired. On the exam, deprovisioning questions often test whether you recognize the risk of lingering access, shared credentials, forgotten service dependencies, or inconsistent offboarding between departments....
Episode 21 — Review Identity Access Regularly Before Privilege Drift Becomes Dangerous 22.04.2026 15:27
This episode explains why identity and access reviews are necessary after provisioning, because permissions that were once appropriate can become risky as roles change, projects end, and responsibilities shift over time. For the exam, you need to understand privilege drift as a common control failure that occurs when accounts keep access they no longer need, especially in fast-moving organizations...
Episode 20 — Provision Access with Lifecycle Control and Accountability in Mind 22.04.2026 17:00
This episode focuses on provisioning as a controlled lifecycle activity that must align with role definitions, business need, approval authority, and traceable accountability. For the certification exam, it is not enough to know that accounts are created; you must understand how proper requests, reviews, documentation, and technical enforcement reduce the risk of excessive or inappropriate access....
Episode 19 — Define Identity Roles Before Provisioning Decisions Create Access Risk 22.04.2026 17:35
This episode explains why access control begins with clearly defined identities, responsibilities, and role boundaries before accounts and permissions are ever assigned. On the exam, poorly defined roles often appear as the hidden cause of overprovisioning, privilege creep, inconsistent approvals, or failed audits, so you need to understand why accurate role design is a security control in itself....
Episode 18 — Connect GRC Redundancy Awareness and Metrics into Practical Governance Thinking 22.04.2026 19:17
This episode brings together governance, risk, compliance, redundancy, and measurement so you can think about security as an integrated management system rather than a set of unrelated topics. For the exam, this matters because strong governance depends on seeing how policies guide resilience, how redundancy supports business goals, and how metrics show whether those decisions are actually working...
Episode 17 — Measure Cybersecurity Effectiveness Using KRIs Dashboards Scorecards and Reports 22.04.2026 16:50
This episode covers how organizations measure cybersecurity effectiveness so that leadership can see trends, emerging concerns, and whether controls are producing the intended results. On the exam, you should know the purpose of key risk indicators, dashboards, scorecards, and reports, as well as the difference between useful metrics and numbers that look impressive but fail to support action. Pra...
Episode 16 — Defend Against Social Engineering with Password Protection and Phishing Awareness 22.04.2026 17:44
This episode explains how social engineering attacks exploit trust, urgency, curiosity, and routine behavior to bypass technical safeguards and gain access through people. For certification success, you should understand the mechanics of phishing, pretexting, impersonation, and other manipulative tactics, along with how password discipline, user awareness, and reporting processes reduce the chance...
Episode 15 — Shape Security Awareness Through Organizational Culture and Leadership 22.04.2026 17:50
This episode explores how security awareness becomes more effective when it is supported by leadership behavior, clear expectations, and a culture that treats security as part of everyday work rather than a separate burden. On the exam, awareness is not just about annual training; it includes communication, reinforcement, accountability, and the way management priorities influence employee choices...
Episode 14 — Protect AI Continuity Through Dataset Backups Configuration Recovery and Model Drift 22.04.2026 16:42
This episode examines continuity for AI-supported systems by focusing on the supporting assets that keep them reliable, recoverable, and useful over time. For the exam, it is important to view AI environments through standard continuity and recovery thinking, including protected datasets, recoverable configurations, version control, access restrictions, and monitoring for drift that can gradually...
Episode 13 — Build Redundancy Thinking Around Business Continuity and Disaster Recovery 22.04.2026 17:37
This episode focuses on the role of redundancy in keeping critical functions available and helping organizations recover when systems, facilities, people, or suppliers are disrupted. On the exam, business continuity and disaster recovery questions often test whether you can distinguish between sustaining operations and restoring them after serious failure, while also understanding the value of alt...
Episode 12 — Plan Governance Risk and Compliance with Purpose and Practical Tools 22.04.2026 18:15
This episode explains governance, risk, and compliance as connected management functions that turn security from scattered activity into a coordinated program. For the exam, you must understand that governance sets direction and accountability, risk management evaluates uncertainty and impact, and compliance helps ensure required obligations are met through documented controls and oversight. Pract...
Episode 11 — Apply Security Principles Through Fast Scenario Based Decision Making 22.04.2026 16:52
This episode develops the skill of applying core security principles quickly when the exam presents short scenarios with competing priorities and incomplete facts. Rather than memorizing isolated definitions, you need to recognize how confidentiality, integrity, availability, least privilege, separation of duties, and defense in depth guide the best answer under time pressure. Examples such as sus...
Episode 10 — Maintain Professional Conduct with Due Care Diligence and ISC2 Ethics 22.04.2026 18:18
This episode focuses on professional conduct and the responsibility to act competently, consistently, and ethically when protecting systems, users, and organizations. For the exam, candidates should understand the difference between due care and due diligence, how those ideas appear in oversight and operations, and why the ISC2 Code of Ethics matters when choices involve pressure, shortcuts, or co...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.