Jason Edwards

Certified: The ISC(2) ISSAP Audio Course

Certified: The ISC(2) ISSAP Certification Audio Course is an audio-first study and skills program for security architects who need to design, justify, and lead real-world security architecture work. It’s built for experienced practitioners who already understand core security concepts and now want to operate at the architecture level—people moving from engineer to architect, senior analysts stepping into design authority, consultants who must defend decisions, and managers who need to evaluate architecture proposals with confidence. If you work with requirements, risk, controls, and design tra...

Author

Jason Edwards

Category

Technology

Podcast website

issap.baremetalcyber.com

Latest episode

Feb 22, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 86 — Align IAM Logging With Policies and Regulations Including PCI DSS and GDPR 22.02.2026

 This episode ties identity and access logging to policy and regulatory expectations, showing how to design evidence that satisfies both security outcomes and compliance requirements, which ISSAP frequently tests by mixing audit language with real-world architecture constraints. You’ll learn how to align IAM log content, retention, access controls, and reporting to organizational policies and to c...

Episode 85 — Build Log Analysis and Reporting That Connects IAM Events to Business Risk 22.02.2026

 This episode teaches how to analyze and report IAM-related log data in a way that connects technical events to business risk, which is central to ISSAP because the exam expects architects to communicate impact, not just produce dashboards. You’ll learn how to design analysis that highlights identity-driven attack paths, such as credential stuffing, MFA fatigue patterns, privilege escalation, serv...

Episode 84 — Engineer Log Retention and Integrity Controls That Hold Up in Court 22.02.2026

This episode explains how to design log retention and integrity so evidence remains trustworthy when it matters most, including legal discovery, regulatory review, and post-incident investigations, which ISSAP questions often probe through chain-of-custody and tamper-resistance scenarios. You’ll learn how to define retention periods by data type and risk, then design storage that preserves logs ag...

Episode 83 — Establish Log Alerts and Notifications That Support Rapid Response and Investigation 22.02.2026

 This episode focuses on turning logs into actionable alerts that reduce response time without creating alert fatigue, which is a common ISSAP theme when questions ask how to detect meaningful security events and respond with confidence. You’ll learn how to design alerting based on threat scenarios and control objectives, including high-signal identity events like repeated failed logins with succe...

Episode 82 — Define Audit Events That Matter Without Flooding Storage and Analysts 22.02.2026

 This episode teaches how to decide which audit events must be captured to satisfy exam objectives, investigations, and compliance evidence, without creating a logging firehose that hides the signals you actually need. You’ll learn how to categorize events by risk and purpose, including identity lifecycle changes, authentication and session activity, authorization decisions, privileged actions, da...

Episode 81 — Determine Accounting and Forensic Requirements That Drive Audit Logging Architecture 22.02.2026

 This episode explains how to define accounting and forensic requirements before you pick tools or storage, because ISSAP questions often test whether your logging design can support attribution, incident reconstruction, and governance proof under real scrutiny. You’ll learn how accounting requirements differ from general monitoring by focusing on who did what, when they did it, from where, and un...

Episode 80 — Select Authorization Approaches: SSO, RBAC, ABAC, Rules, Tokens, Certificates 22.02.2026

 This episode teaches how to select authorization approaches based on system requirements, scale, and governance needs, which is a core ISSAP exam skill because the best approach depends on context, not preference. You’ll learn how SSO affects access decisions by centralizing authentication while still requiring local authorization clarity, how RBAC supports repeatable role-based control, and how...

Episode 79 — Manage Privileged Accounts Using PAM to Reduce Standing Administrative Risk 22.02.2026

 This episode focuses on privileged access management as an architecture control that reduces standing risk, which ISSAP often tests through questions about limiting blast radius and improving accountability for administrative actions. You’ll learn what PAM typically includes, such as credential vaulting, session brokering, just-in-time elevation, approval workflows, and session recording, and how...

Episode 78 — Implement DRM and Group Strategies Without Creating Unmanageable Entitlement Sprawl 22.02.2026

 This episode explains how to use DRM and group-based strategies to control access to content while avoiding the entitlement sprawl that makes governance impossible, a nuance ISSAP may test when scenarios involve sensitive documents, collaboration platforms, and external sharing. You’ll learn what DRM is intended to protect, including controlling viewing, forwarding, printing, and offline access,...

Episode 77 — Map Roles, Rights, and Responsibilities to System, Application, and Data Access 22.02.2026

 This episode teaches how to map roles to rights in a way that stays consistent across systems and data stores, which is a frequent ISSAP topic because many access failures come from unclear responsibility boundaries and ad hoc entitlements. You’ll learn how to define roles based on job responsibilities and business processes, then translate those roles into permissions at the system level, applic...

Episode 76 — Design Authorization Workflows, Issuance, Review, Revocation, Suspension, and Governance 22.02.2026

 This episode covers authorization as a lifecycle workflow, which is essential for ISSAP because the exam frequently asks how to prevent stale access and how to prove governance, not just how to grant permissions. You’ll learn how authorization should be issued with clear request and approval steps tied to business justification, then maintained through periodic review that validates continued nee...

Episode 75 — Choose Authorization Models for Physical, Logical, and Administrative Access Control 22.02.2026

 This episode teaches how to choose authorization models that fit the access domain, which ISSAP often tests by mixing physical access, logical system access, and administrative control in the same scenario. You’ll learn how physical access decisions typically rely on zones, schedules, and role-based privileges tied to facilities, while logical access decisions must account for data sensitivity, a...

Episode 74 — Apply Authorization Principles, Least Privilege, SoD, and Interactive vs Non-Interactive 22.02.2026

 This episode explains the core authorization principles that show up repeatedly in ISSAP questions because they drive defensible access decisions across people, services, and systems. You’ll define least privilege as a measurable design goal, not a slogan, and learn how to apply it by limiting scope, duration, and blast radius while still supporting operations. We’ll cover segregation of duties a...

Episode 73 — Define Trust Relationships for Federated and Stand-Alone Identity Architectures 22.02.2026

 This episode teaches how to define trust relationships so identity assertions remain meaningful across systems, which is central to ISSAP because many scenarios hinge on whether trust is explicit, scoped, and verifiable. You’ll learn how trust differs in stand-alone architectures, where the same organization controls identity proofing, credential issuance, and policy enforcement, versus federated...

Episode 72 — Use LDAP and XACML Controls to Enforce Authentication and Access Policies 22.02.2026

 This episode covers how LDAP and XACML fit into identity and access architecture, and why ISSAP questions often test whether you can distinguish between identity data stores, authentication flows, and policy decision systems. You’ll review how LDAP is commonly used to store and query identity attributes and group membership, and how its structure, schema, and replication choices affect reliabilit...

Episode 71 — Apply SAML, RADIUS, Kerberos, and OAuth Where Each Fits Best 22.02.2026

 This episode explains how to choose between SAML, RADIUS, Kerberos, and OAuth based on the problem you are solving, which is a common ISSAP exam pattern because several options can sound correct while only one fits the architecture context. You’ll define what each protocol is designed to do, the trust assumptions it relies on, and the environments where it is strongest, such as SAML for enterpris...

Episode 70 — Define Authentication Approaches, Single-Factor, MFA, and Risk-Based Elevation 22.02.2026

 This episode teaches how to define authentication requirements that match risk and user context, which is central to ISSAP because many exam questions revolve around choosing the right assurance level without breaking usability or operations. You’ll learn how single-factor authentication fails under common threats, where MFA meaningfully reduces risk, and how risk-based elevation can add security...

Episode 69 — Select Identity Management Technologies That Support Scale, Recovery, and Governance 22.02.2026

 This episode covers how to select identity management technologies based on scalability, resilience, and governance, which aligns with ISSAP because exam questions often test whether your identity solution can be operated, recovered, and audited under real constraints. You’ll learn how to evaluate directory services, IAM platforms, federation services, and identity governance tools by looking at...

Episode 68 — Design Joiners-Movers-Leavers Provisioning and Deprovisioning That Prevents Orphan Access 22.02.2026

 This episode explains how to architect joiners-movers-leavers processes so access changes keep pace with real organizational change, which ISSAP often tests by presenting scenarios where stale entitlements create quiet, long-lived risk. You’ll learn how provisioning and deprovisioning should work across HR systems, identity directories, applications, and infrastructure, then translate that into a...

Episode 67 — Assign Identifiers to Users, Services, Devices, and Components Without Collisions 22.02.2026

 This episode teaches how to design identifier strategies that scale cleanly across users, services, devices, and components, a topic ISSAP may test when identity systems fail due to ambiguity, duplicates, or poor lifecycle handling. You’ll learn the difference between identifiers, attributes, and credentials, then design rules for uniqueness, persistence, and re-use that support auditability and...

Episode 66 — Architect Identity Proofing and Verification Using Physical and Logical Methods 22.02.2026

 This episode explains how identity proofing differs from authentication and why ISSAP often tests whether you can build trustworthy identity foundations before you rely on MFA and access control policies. You’ll learn how proofing establishes that a real person, device, or service is who it claims to be at enrollment, and how verification maintains that trust over time through revalidation, lifec...

Episode 65 — Plan Key Management Lifecycle From Generation Through Storage and Distribution 22.02.2026

 This episode teaches key management as a lifecycle discipline, because ISSAP questions frequently reward answers that focus on how keys are created, protected, rotated, revoked, escrowed, and recovered—not merely which algorithm you picked. You’ll learn the core phases of key management, including secure generation, strong protection at rest and in use, controlled distribution, rotation and renew...

Episode 64 — Choose Cryptographic Implementations for Data In-Transit, In-Use, and At-Rest 22.02.2026

 This episode covers how to choose cryptographic implementations based on when data is moving, being processed, or stored, which ISSAP often tests through scenarios where the wrong answer protects one state while leaving another exposed. You’ll learn how to reason about encryption in transit with protocols like TLS and IPsec, encryption at rest with file, volume, and database controls, and the har...

Episode 63 — Determine Cryptographic Design Constraints, Lifecycle, Algorithms, and System Capabilities 22.02.2026

 This episode explains how to identify cryptographic design constraints before you select an implementation, which is important for ISSAP because exam questions often hinge on whether your crypto choice matches lifecycle realities and platform limitations. You’ll learn to define constraints such as data lifetime, performance requirements, key rotation frequency, interoperability needs, regulatory...

Episode 62 — Evaluate Control Applicability Across Clients, Proxies, and Application Service Components 22.02.2026

 This episode teaches how to evaluate where controls can actually be enforced across clients, proxies, and application service components, a nuance ISSAP often tests by presenting options that sound correct but cannot be applied at the right enforcement point. You’ll learn to map controls to architecture layers by identifying where identity is established, where traffic is terminated, where data i...

Listen to the Certified: The ISC(2) ISSAP Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.