Jason Edwards
Certified: The ISC(2) ISSAP Audio Course
Certified: The ISC(2) ISSAP Certification Audio Course is an audio-first study and skills program for security architects who need to design, justify, and lead real-world security architecture work. It’s built for experienced practitioners who already understand core security concepts and now want to operate at the architecture level—people moving from engineer to architect, senior analysts stepping into design authority, consultants who must defend decisions, and managers who need to evaluate architecture proposals with confidence. If you work with requirements, risk, controls, and design tra...
Author
Jason Edwards
Category
Podcast website
Latest episode
Feb 22, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 61 — Plan Out-of-Band Communications for Incident Response and BC/DR Operations 22.02.2026 16:53
This episode explains why out-of-band communications are a core security architecture requirement, not a convenience, and how ISSAP questions often test whether you can preserve coordination when primary systems are compromised or unavailable. You’ll learn how to define communication objectives for incident response and BC/DR, including confidentiality, integrity, availability, and authenticated...
Episode 60 — Build Content Monitoring Using DLP Across Email, Web, Data, and Social Media 22.02.2026 23:12
This episode covers how to design data loss prevention as a practical monitoring and control capability across multiple channels, which ISSAP often tests through scenarios involving regulated data, insider risk, and third-party sharing. You’ll learn how DLP works at a high level, what detection methods can and cannot see, and how to choose enforcement points across email, web gateways, endpoints,...
Episode 59 — Design Infrastructure Monitoring Architecture That Supports Fast Triage and Containment 22.02.2026 17:03
This episode explains how to architect monitoring so it drives fast triage and containment instead of producing dashboards that look busy but do not shorten incident timelines, a key ISSAP theme when questions ask what capabilities matter most under attack. You’ll learn how to define telemetry requirements across identity systems, endpoints, networks, servers, and cloud control planes, then desig...
Episode 58 — Integrate Third Parties Using Federation, APIs, VPN, and SFTP Safely 22.02.2026 19:49
This episode teaches how to integrate partners and vendors without turning “business connectivity” into permanent, poorly governed trust, which ISSAP often tests through scenarios that include outsourcing, data exchange, and shared operations. You’ll learn how to choose between federation, APIs, VPN connections, and SFTP based on data sensitivity, transaction patterns, and the partner’s security...
Episode 57 — Secure Shared Services Like Email and Communications With Practical Control Sets 22.02.2026 17:13
This episode focuses on shared services that become enterprise-wide attack surfaces, which is important for ISSAP because email and collaboration platforms often sit at the intersection of identity, data protection, and incident response. You’ll learn how to architect controls for authentication, anti-phishing defenses, message integrity, and administrative governance, then align those controls t...
Episode 56 — Design Endpoint Security for BYOD, Mobile, EDR, and HIDS/HIPS 22.02.2026 20:59
This episode explains how endpoint security architecture changes when you mix corporate devices, BYOD, and mobile platforms, and why ISSAP questions often test control selection under uneven visibility and ownership. You’ll learn how to define endpoint requirements for identity assurance, device posture, configuration baselines, and telemetry, then choose between approaches like EDR and host-base...
Episode 55 — Secure Industrial Control Systems and SCADA Without Breaking Safety Operations 22.02.2026 22:48
This episode teaches how to apply security architecture to industrial control environments where safety, uptime, and vendor constraints are dominant, a theme ISSAP often uses to test whether you can adapt controls to real operational limits. You’ll review how ICS and SCADA differ from typical IT systems, including long lifecycles, limited patch windows, specialized protocols, and a high cost of d...
Episode 54 — Architect Cloud Security Across IaaS, PaaS, and SaaS Responsibility Boundaries 22.02.2026 18:04
This episode explains how cloud responsibility boundaries shape architecture decisions, which is central to ISSAP because many exam items hinge on knowing what the provider secures, what you must secure, and how to prove it. You’ll compare IaaS, PaaS, and SaaS through the lens of control ownership, visibility, and configuration risk, then learn how to design consistent outcomes for identity, logg...
Episode 53 — Secure Data Repositories With Access Control, Encryption, Redaction, and Masking 22.02.2026 21:11
This episode focuses on protecting data repositories in ways that remain effective during normal operations, audits, and incidents, which ISSAP often tests through questions about confidentiality versus usability. You’ll learn how to choose access controls that match data sensitivity, including least privilege boundaries, administrative separation, and service account constraints, then layer encr...
Episode 52 — Design Storage Security for DAS, SAN, NAS, Archives, and Removable Media 22.02.2026 19:53
This episode teaches how storage architecture choices change your threat model and your control options, which is directly relevant to ISSAP because exam scenarios frequently involve protecting data across mixed storage types and lifecycles. You’ll define the security characteristics of direct-attached storage, SANs, NAS, archival systems, and removable media, then translate those differences int...
Episode 51 — Apply Web Application Firewalls Where They Help and Where They Fail 22.02.2026 17:49
This episode explains what a web application firewall actually does, what it cannot do, and why ISSAP questions often test whether you can place a WAF as part of a layered design instead of treating it as a cure-all. You’ll review key deployment modes, common rule strategies, and how to align WAF controls to application risk, especially for internet-facing APIs and legacy apps that cannot be refa...
Episode 50 — Secure VoIP and Unified Communications Without Sacrificing Availability and Quality 22.02.2026 14:32
This episode teaches how to secure VoIP and unified communications systems while preserving availability, call quality, and user trust, which ISSAP questions often frame as a balance problem where security controls must be compatible with real-time traffic and operational support needs. You’ll learn the key security concerns for voice and collaboration platforms, including signaling protection, m...
Episode 49 — Apply NAC, DNS, and NTP Protections to Prevent Control-Plane Attacks 22.02.2026 13:57
This episode explains how Network Access Control, DNS, and NTP protections defend the control plane that everything else depends on, a concept ISSAP often targets because these services are easy to overlook until an attacker uses them to redirect traffic, poison trust, or disrupt operations. You’ll learn how NAC enforces who and what is allowed on the network, how DNS protections reduce spoofing...
Episode 48 — Design VPN and IPsec Strategies That Preserve Identity, Integrity, and Scale 22.02.2026 14:18
This episode covers how to design VPN and IPsec solutions that do more than create encrypted tunnels, which is directly relevant to ISSAP because exam questions often test identity binding, access scope, and operational scalability. You’ll learn how to choose between remote access and site-to-site designs, how to align authentication with enterprise identity, and how to prevent broad network acce...
Episode 47 — Select Firewalls, Airgaps, and Software Defined Perimeters for Clear Boundaries 22.02.2026 13:24
This episode explains how to choose between firewalls, airgaps, and software defined perimeters based on threat models, operational constraints, and assurance requirements, which the ISSAP exam often frames as “best control approach for this boundary.” You’ll learn what each option actually provides in terms of isolation, policy enforcement, and attack surface reduction, and how to avoid misunder...
Episode 46 — Architect IoT and Management Plane Security Without Losing Operational Visibility 22.02.2026 14:00
This episode teaches how to secure IoT environments and their management planes while still preserving the visibility and uptime that operations teams require, which ISSAP questions often test through scenarios involving constrained devices, vendor ecosystems, and remote administration. You’ll learn how IoT threats differ due to weak patching, limited logging, hardcoded credentials, and long devi...
Episode 45 — Secure Public, Private, and Management Networks With Segmentation and Policy 22.02.2026 14:27
This episode focuses on designing separate public, private, and management networks with segmentation and policy enforcement that remains consistent as environments grow, which is a common ISSAP testing point when questions involve mixed workloads, admins, and external exposure. You’ll learn how to define what belongs on each network, what protocols are allowed, and where policy should be enforce...
Episode 44 — Design Wired and Wireless Network Security Without Creating Hidden Trust Paths 22.02.2026 14:10
This episode explains how to design wired and wireless network security so trust is explicit, enforced, and observable, which is central to ISSAP scenarios that test segmentation intent versus what traffic can actually do. You’ll learn how to define trust boundaries across switch ports, wireless SSIDs, authentication methods, and routing paths, then choose controls that prevent “it works, so it m...
Episode 43 — Architect Platform Security Across Hardware, Firmware, OS, Virtual, and Container 22.02.2026 15:31
This episode teaches how to think about platform security as a layered stack that starts below the operating system and extends through virtualization and containers, which ISSAP questions often probe when they ask where to place controls and how to prove platform integrity. You’ll define the security responsibilities at each layer, including hardware roots of trust, firmware protections, secure...
Episode 42 — Build Physical Security Control Sets Using Cameras, Doors, and Controllers 22.02.2026 15:22
This episode focuses on building a coherent physical security control set using cameras, door hardware, access controllers, and supporting procedures, which the ISSAP exam treats as part of architecture when facility controls protect sensitive systems, keys, and evidence. You’ll learn how to translate physical threats and business needs into layered controls that support deterrence, prevention, d...
Episode 41 — Translate Application Security Needs Using Traceability and Architecture Documentation 22.02.2026 15:59
This episode explains how security architects capture application security needs as traceable requirements and how that traceability becomes a scoring advantage on ISSAP questions that ask you to justify controls across stakeholders. You’ll learn how to use architecture documentation to connect business objectives, data classifications, trust boundaries, and threat assumptions to concrete securit...
Episode 40 — Define Infrastructure and System Cryptography Requirements That Avoid Fragile Designs 22.02.2026 21:04
This episode explains how to set cryptography requirements that are secure, maintainable, and operationally realistic, which aligns with ISSAP because exam questions often test whether you can avoid designs that fail due to poor key management or misunderstood crypto boundaries. You’ll learn how to define when to use encryption in transit and at rest, how to select appropriate primitives and prot...
Episode 39 — Specify Infrastructure and System Monitoring Requirements for Detection and Response 22.02.2026 25:41
This episode teaches how to define monitoring requirements that support detection, investigation, and response, which is a frequent ISSAP exam topic because architecture is only defensible when you can observe whether controls are working. You’ll learn how to specify what must be logged and monitored across endpoints, servers, networks, identity platforms, cloud control planes, and critical appli...
Episode 38 — Architect Physical Security Requirements, Perimeter Controls, Zoning, and Fire Suppression 22.02.2026 19:38
This episode explains how physical security requirements support and constrain security architecture, and why ISSAP questions often include facility and environmental controls as part of a complete protection strategy. You’ll learn how to translate business and threat requirements into physical design choices like perimeter controls, access zones, mantraps, visitor management, camera coverage, an...
Episode 37 — Separate IT and Operational Technology Requirements Without Breaking Safety Goals 22.02.2026 23:27
This episode covers how to distinguish IT and OT requirements in a way that preserves safety, uptime, and integrity, which is highly relevant to ISSAP scenarios that test whether you can adapt security architecture to environments where availability and physical consequences dominate. You’ll learn how OT constraints change common security assumptions, including patch cycles, latency tolerance, ve...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.