Jason Edwards

Certified: The ISC(2) CC Audio Course

Certified: The ISC(2) CC Certification Audio Course is an audio-first study program built for people who want a clean, practical path into cybersecurity without getting buried in jargon. It’s designed for beginners and career changers, as well as IT and business professionals who need a solid security foundation. If you’re aiming for the ISC(2) Certified in Cybersecurity (CC) credential, this course gives you a structured way to learn the concepts the exam expects, using plain language and real-world framing. You do not need a deep technical background to start. You need consistency, curiosity...

Author

Jason Edwards

Category

Technology

Latest episode

Mar 11, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 40 — IPv4 and IPv6 Basics: Addressing, Notation, and Security-Relevant Differences 22.02.2026

This episode explains IPv4 and IPv6 addressing in practical terms, helping you recognize what you are looking at in exam questions and understand how addressing influences security and troubleshooting. You will learn basic IPv4 structure, private versus public ranges at a high level, and the purpose of subnetting concepts without turning the discussion into math-heavy drills. We will then introduc...

Episode 39 — Computer Networking Foundations: OSI and TCP/IP Models for Security Thinking 22.02.2026

This episode teaches networking fundamentals through the OSI and TCP/IP models, focusing on how layered communication helps you reason about where security controls operate and where attacks occur, which is CC-relevant knowledge. You will learn what each layer is responsible for and how data moves from an application down to the network and back, along with the practical meaning of encapsulation....

Episode 38 — Role-Based Access Control: Designing Roles That Actually Reflect Job Duties 22.02.2026

This episode covers role-based access control (RBAC) and prepares you to apply it in exam questions that ask how to manage access at scale without creating chaos. You will learn how RBAC assigns permissions to roles based on job functions, then assigns users to roles, making access easier to administer and review than individual, user-by-user permissions. We will discuss how good role design reduc...

Episode 37 — Mandatory Access Control: Labels, Rules, and High-Control Environments 22.02.2026

This episode explains mandatory access control (MAC), a model where a central authority defines access rules and users cannot override them, which is frequently tested through comparisons with DAC and RBAC. You will learn how MAC uses labels, classifications, and clear rules to control information flow, and why it is common in environments that require strict confidentiality protections. We will d...

Episode 36 — Discretionary Access Control: Ownership, Permissions, and Where It Breaks Down 22.02.2026

This episode focuses on discretionary access control (DAC), a model where resource owners decide who gets access and what level of permission is granted, and it helps you answer CC questions that compare access control approaches. You will learn how DAC commonly appears in operating systems through file and folder permissions, access control lists, and user-managed sharing settings. We will discus...

Episode 35 — Segregation of Duties Made Simple: Preventing Abuse and Catching Mistakes Early 22.02.2026

This episode explains segregation of duties (SoD) and why it is a powerful administrative control for preventing fraud, reducing insider threat risk, and catching errors before they become incidents, all of which are exam-relevant at the foundational level. You will learn how SoD works by splitting critical tasks across multiple roles so no single person can complete a high-impact action end-to-en...

Episode 34 — Least Privilege in Practice: Reducing Risk Without Slowing Work to a Crawl 22.02.2026

This episode covers least privilege as the principle of giving users and systems only the access they need to perform required tasks, and it prepares you for CC questions that ask how to reduce exposure without harming productivity. You will learn how least privilege applies to users, service accounts, applications, and administrative tools, and why over-permissioning creates large blast radius wh...

Episode 33 — Authorized Versus Unauthorized Personnel: Verification, Escorts, and Real Control 22.02.2026

This episode teaches you how organizations separate authorized personnel from unauthorized personnel, which is essential for both physical and logical security and appears in CC objectives through access control concepts. You will learn how identity verification works in practice using badges, check-in procedures, visitor logs, escorts, and restricted area rules, and why “knowing someone” is not a...

Episode 32 — Monitoring Physical Security: Guards, CCTV, Alarms, and Logs That Matter 22.02.2026

This episode focuses on physical security monitoring and how detection mechanisms support deterrence, response, and investigation, which the CC exam expects you to understand at a practical level. You will learn how guards, cameras, alarms, motion sensors, and access logs provide signals that an organization can use to verify events and respond quickly to suspicious activity. We will discuss the d...

Episode 31 — Physical Access Controls: Badges, Gate Entry, and Environmental Design Basics 22.02.2026

This episode explains physical access controls and how they reduce risk by limiting who can enter facilities and restricted areas, a foundational topic for the CC exam. You will learn how badges, keys, locks, turnstiles, mantraps, and controlled entry points work together to prevent unauthorized access, support accountability, and create useful audit trails. We will discuss how environmental desig...

Episode 30 — Incident Response Components: Prepare, Detect, Contain, Eradicate, Recover 22.02.2026

This episode walks through the major components of incident response, showing how preparation, detection, containment, eradication, and recovery fit together as a repeatable lifecycle. You will learn what preparation includes in practical terms, such as clear roles, access to tools, logging readiness, and playbooks that reduce decision time. We will discuss detection as the process of turning sign...

Episode 29 — Incident Response Importance: Speed, Evidence, and Communication Under Stress 22.02.2026

This episode explains why incident response is important, emphasizing the time-sensitive nature of attacks and the need for disciplined decisions when pressure is high. You will learn how delays increase attacker dwell time, expand impact, and complicate recovery, while rushed actions can destroy evidence, trigger broader outages, or lead to incorrect conclusions. We will discuss the role of evide...

Episode 28 — Incident Response Purpose: Contain Damage and Restore Normal Operations 22.02.2026

This episode introduces incident response as the structured approach for handling security events so the organization can limit damage, preserve evidence, and recover operations efficiently. You will learn how incident response differs from general troubleshooting by focusing on security objectives such as containment, eradication, and preventing recurrence. We will define key terms like incident,...

Episode 27 — Disaster Recovery Components: Backups, Failover, Runbooks, and Recovery Checks 22.02.2026

This episode covers the building blocks of a workable disaster recovery capability, including backups, replication, failover planning, documented runbooks, and validation steps that confirm systems are truly restored. You will learn how different backup types and storage choices influence recovery speed and reliability, and why integrity checks are critical before trusting restored data. We will d...

Episode 26 — Disaster Recovery Importance: RTO, RPO, and Tradeoffs You Must Understand 22.02.2026

This episode explains why disaster recovery planning is essential, focusing on how RTO and RPO translate into real business tradeoffs and investment decisions that security professionals must understand. You will learn that shorter recovery times and smaller data loss windows usually require higher cost, more complexity, and more disciplined operations, which is why organizations must define reali...

Episode 25 — Disaster Recovery Purpose: Restore IT Services Fast and Validate the Return 22.02.2026

This episode introduces disaster recovery as the focused effort to restore IT systems and data after an outage or major disruption, and it clarifies how disaster recovery differs from broader business continuity. You will learn how disaster recovery emphasizes technical restoration activities such as rebuilding servers, restoring backups, failing over to alternate infrastructure, and confirming se...

Episode 24 — Business Continuity Components: Roles, Dependencies, Plans, and Testing Cadence 22.02.2026

This episode breaks down the core components of a business continuity program and prepares you to answer CC questions that ask what a continuity plan must include to be effective. You will learn the role of business impact analysis, dependency mapping, continuity strategies, and clear ownership so actions are not delayed during a crisis. We will discuss how plans define responsibilities, communica...

Episode 23 — Business Continuity Importance: Downtime Costs, Priorities, and Stakeholder Trust 22.02.2026

This episode explains why business continuity matters, focusing on the real costs of downtime and the broader impacts that reach beyond IT into revenue, safety, legal exposure, and reputation. You will learn how continuity planning protects stakeholder trust by ensuring the organization can keep promises to customers, partners, and employees during disruptions. We will discuss how continuity prior...

Episode 22 — Business Continuity Purpose: Keep Critical Work Going During Disruption 22.02.2026

This episode introduces business continuity as the discipline of keeping essential business functions operating during disruptive events, which is foundational knowledge for the CC exam. You will learn how continuity planning focuses on the mission, the people, and the processes—not just the technology—and how organizations decide what must continue versus what can pause. We will cover key ideas s...

Episode 21 — Navigate Regulations and Laws: What Compliance Demands From Security Work 22.02.2026

This episode explains how laws and regulations influence security requirements, and it prepares you for CC questions that test your ability to recognize compliance drivers without needing to memorize specific statutes. You will learn the practical difference between legal requirements, regulatory requirements, contractual obligations, and internal policy, and how each can create mandatory controls...

Episode 20 — Turn Governance Into Action: Policies, Procedures, and Standards That Stick 22.02.2026

This episode focuses on governance as the structure that makes security consistent, measurable, and aligned with business goals, which is a recurring theme in the CC objectives. You will learn how policies set high-level intent, standards define mandatory requirements, and procedures describe the step-by-step actions people follow to implement controls reliably. We will discuss why governance fail...

Episode 19 — Operationalize the ISC2 Code of Ethics Under Real Workplace Pressure 22.02.2026

This episode explains how the ISC2 Code of Ethics guides professional behavior, and why the CC exam expects you to recognize ethical responsibilities as part of being trusted with systems and data. You will learn the intent of ethical principles such as protecting society, acting honorably, providing diligent service, and advancing the profession, then connect those ideas to realistic workplace de...

Episode 18 — Strengthen Physical Controls: Layers, Barriers, and Practical Deterrence Strategies 22.02.2026

This episode covers physical controls, which protect facilities, equipment, and people from unauthorized access, theft, and environmental hazards, a topic the CC exam expects you to understand at a foundational level. You will learn how barriers, locks, fences, lighting, visitor procedures, and secured areas work together as layers, and why a single control rarely solves a physical risk by itself....

Episode 17 — Use Administrative Controls Well: Policies, Process Discipline, and Human Factors 22.02.2026

This episode explains administrative controls, which are the governance and process mechanisms that shape behavior and reduce risk, and they are critical for CC because they connect security to people and organizational decision-making. You will learn how policies, procedures, standards, training, background checks, and change management reduce vulnerabilities created by human error and inconsiste...

Episode 16 — Apply Technical Controls That Reduce Risk Without Breaking Operations 22.02.2026

This episode focuses on technical controls and how they are used to reduce risk in practical, testable ways that show up in the CC objectives. You will learn how controls such as encryption, access control, firewalls, endpoint protection, and logging are selected to address specific threats and vulnerabilities, rather than being applied as a random checklist. We will discuss preventive, detective,...

Listen to the Certified: The ISC(2) CC Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.