Jason Edwards

Certified: The ISC(2) ISSAP Audio Course

Certified: The ISC(2) ISSAP Certification Audio Course is an audio-first study and skills program for security architects who need to design, justify, and lead real-world security architecture work. It’s built for experienced practitioners who already understand core security concepts and now want to operate at the architecture level—people moving from engineer to architect, senior analysts stepping into design authority, consultants who must defend decisions, and managers who need to evaluate architecture proposals with confidence. If you work with requirements, risk, controls, and design tra...

Author

Jason Edwards

Category

Technology

Podcast website

issap.baremetalcyber.com

Latest episode

Feb 22, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 36 — Define Deployment Model Requirements Across On-Premises, Cloud, and Hybrid Systems 22.02.2026

 This episode explains how deployment models change threat assumptions, control placement, and responsibility boundaries, which is a core ISSAP skill when exam scenarios blend on-premises constraints with cloud services and hybrid connectivity. You’ll learn how to define deployment requirements that stay consistent across environments, including identity integration, network segmentation, logging,...

Episode 35 — Use Source Composition Analysis to Control Supply Chain and Dependency Risk 22.02.2026

 This episode focuses on software composition analysis as a key supply chain control, and it explains why ISSAP questions often emphasize dependency governance, provenance, and operational control ownership in modern development environments. You’ll learn how SCA identifies third-party libraries, versions, licenses, and known vulnerabilities, then how to turn that visibility into architecture requ...

Episode 34 — Apply Manual Code Review Techniques for High-Risk Components and Interfaces 22.02.2026

This episode teaches how to perform manual code review in a way that supports security architecture goals, which matters for ISSAP because the exam frequently tests where human judgment is necessary even when automated tools are present. You’ll learn how to focus review effort on high-risk areas such as authentication and authorization logic, cryptographic handling, secrets management, deserializa...

Episode 33 — Use Static Analysis Effectively Without Drowning in False Positives 22.02.2026

 This episode explains how to use static analysis as an architecture-supporting control that improves code quality and reduces security defects, while avoiding the ISSAP-relevant failure mode of treating tool output as truth. You’ll learn what static analysis can and cannot prove, how rule sets and language features affect accuracy, and why tuning matters if you want results that engineering teams...

Episode 32 — Choose Dynamic Analysis Approaches That Reveal Runtime Security Weaknesses 22.02.2026

This episode covers dynamic analysis as a runtime-focused way to validate that security controls behave as designed, which connects directly to ISSAP exam questions that ask how to confirm real operational security, not just design intent. You’ll learn what dynamic analysis means in practice, including test techniques that exercise running applications, services, and infrastructure to expose issue...

Episode 31 — Execute Peer Review Practices That Improve Architecture Quality Without Politics 22.02.2026

 This episode explains how peer review functions as a quality control mechanism for security architecture and why ISSAP scenarios often reward answers that emphasize repeatable review discipline over individual opinion. You’ll learn how to structure an architecture review so the discussion stays anchored to requirements, trust boundaries, threat assumptions, and control objectives, rather than per...

Episode 30 — Perform Manual Function Reviews to Catch Design Flaws Automated Tools Miss 22.02.2026

 This episode focuses on manual function review as a disciplined way to find architecture and security design flaws that scanners and automated testing often miss, which can be a decisive skill on ISSAP questions that involve “best method” choices under ambiguity. You’ll learn how to review system functions and interfaces by tracing inputs, transformations, outputs, and trust boundaries, then aski...

Episode 29 — Use Modeling and Simulation to Expose Security Failures Before Production 22.02.2026

 This episode explains how modeling and simulation can reveal security failures earlier than deployment, which is relevant to ISSAP because the exam values proactive validation and strong assurance arguments, not reactive fixes. You’ll learn what types of models are useful for architecture work, including data flow models, trust boundary diagrams, attack path models, and failure mode simulations t...

Episode 28 — Run Tabletop Exercises to Validate Security Architecture Under Real Stress 22.02.2026

 This episode covers tabletop exercises as an architecture validation tool, not just an incident response activity, which aligns with ISSAP objectives that test whether you can prove a design will hold up during real disruption. You’ll learn how to design a tabletop that targets specific architecture claims, such as “we can contain lateral movement,” “we can restore keys safely,” or “we can mainta...

Episode 27 — Select Alternative Mitigations and Compensating Controls That Truly Reduce Risk 22.02.2026

 This episode explains how to choose compensating controls when ideal mitigations are blocked by legacy constraints, budget, or operational limits, which is a common ISSAP exam pattern where the best answer is the most effective feasible control set. You’ll learn how to evaluate whether an alternative mitigation actually addresses the threat path, rather than simply adding a control that looks imp...

Episode 26 — Identify Architecture Gaps Early and Document Them for Fast Remediation 22.02.2026

 This episode teaches a practical approach to finding and recording architecture gaps before they turn into expensive rework, a skill ISSAP tests indirectly when scenarios ask what you should do next after discovering misalignment, missing controls, or unclear requirements. You’ll learn how to spot gaps by comparing intended control outcomes to actual system behaviors, including trust boundary mis...

Episode 25 — Turn Threat Vectors, Impact, and Probability Into Testable Design Requirements 22.02.2026

 This episode shows how architects translate risk language into requirements that can actually be tested, which is central to ISSAP because many questions ask you to bridge the gap between assessment outputs and implementable design decisions. You’ll learn how to take a threat vector, the expected impact, and the probability in your context, then express the needed control behavior in clear, verif...

Episode 24 — Validate Design With Regression Thinking When Systems and Dependencies Change 22.02.2026

 This episode focuses on regression thinking as a security architecture discipline, because ISSAP scenarios frequently involve system changes that quietly break controls even when teams believe “nothing significant changed.” You’ll learn how to identify security behaviors that must remain stable across releases, patches, configuration updates, and dependency upgrades, then turn those behaviors int...

Episode 23 — Verify Design With Functional Acceptance Testing Without Missing Security Behaviors 22.02.2026

This episode teaches how to ensure security architecture requirements are validated during functional acceptance testing, which matters for ISSAP because the exam often probes whether you can prove a design works as intended, not merely that it looks correct on paper. You’ll define functional acceptance testing in an architecture context and then learn how to embed security behaviors into acceptan...

Episode 22 — Apply CVSS and Threat Intelligence to Prioritize Architecture Risk Decisions 22.02.2026

 This episode explains how to use CVSS and threat intelligence as inputs to architecture prioritization without treating either one as a magic score that replaces judgment, a nuance that often shows up in ISSAP questions that ask you to rank actions under constraints. You’ll review what CVSS actually measures, where it helps, and where it fails, especially when environmental context like asset cri...

Episode 21 — Operationalize STRIDE Threat Modeling From Concept to Concrete Mitigations 22.02.2026

 This episode takes STRIDE from a memorized acronym to a working method you can apply in security architecture reviews, which is directly relevant to ISSAP questions that test whether you can move from abstract threats to defensible control choices. You’ll define each STRIDE category and then practice mapping it to real system elements like data stores, APIs, identity flows, and administrative pat...

Episode 20 — Use Reference Architectures and Blueprints Without Copying Hidden Assumptions 22.02.2026

This episode teaches you how to use reference architectures as accelerators while still validating the assumptions they quietly embed, a common ISSAP exam theme when questions involve “recommended patterns” that may not fit the given environment. You’ll learn how to evaluate a blueprint’s trust boundaries, identity model, logging strategy, and key management approach, then determine what must chan...

Episode 19 — Apply TOGAF and SABSA to Structure Security Architecture Work Products 22.02.2026

This episode explains how common architecture frameworks can help you organize security architecture work so it is repeatable, reviewable, and aligned to business needs, which ISSAP questions often probe when they ask about methods, artifacts, and stakeholder alignment. You’ll learn what TOGAF contributes in terms of enterprise architecture process and governance touchpoints, and what SABSA contri...

Episode 18 — Choose Network and SOA Architecture Approaches That Match Threat Realities 22.02.2026

 This episode focuses on selecting network and service-oriented architecture approaches based on real threats and trust boundaries, which the ISSAP exam often tests through scenarios involving integration, segmentation, and lateral movement risk. You’ll review how to reason about zones, conduits, service-to-service authentication, and policy enforcement points, then learn how architecture choices...

Episode 17 — Define Security Architecture Scope and Types for Enterprise and Cloud 22.02.2026

 This episode clarifies what “security architecture” means across different contexts, and how to set scope so designs are complete without being unrealistic, a core ISSAP competency when questions mix enterprise, application, and cloud concerns. You’ll define key architecture types, including enterprise security architecture, solution architecture, and security design for specific services, then l...

Episode 16 — Advise Risk Treatment Options With Clear Rationale and Decision Traceability 22.02.2026

 This episode teaches you how to recommend risk treatment strategies—mitigate, transfer, avoid, or accept—using clear architectural rationale that holds up in executive conversations and exam scenarios alike. You’ll learn how ISSAP questions often test whether you can select the “best” option given constraints, rather than the most secure option in theory, and how to articulate the reasoning that...

Episode 15 — Incorporate Risk Assessment Artifacts Into Architecture Choices and Tradeoffs 22.02.2026

 This episode shows how architects use risk assessment outputs to make design choices that are transparent and defensible, which is central to ISSAP questions that ask you to prioritize controls and justify tradeoffs. You’ll review how to interpret risk registers, impact assessments, threat statements, and control gap analyses, then learn how to translate those artifacts into architecture constrai...

Episode 14 — Design for Auditability, Segregation, Forensics, and High-Assurance Requirements 22.02.2026

 This episode explains how auditability changes architecture decisions, especially when requirements include strong separation of duties, provable change control, and forensic readiness. You’ll connect ISSAP objectives to practical design choices like privileged access boundaries, dual control for sensitive operations, and independent logging paths that remain trustworthy even if a system is compr...

Episode 13 — Engineer Compliance Evidence Flows That Survive Audits and Incident Scrutiny 22.02.2026

 This episode teaches you how to architect evidence collection as a designed system, not an afterthought, which the ISSAP exam often probes through questions about traceability, control validation, and audit defensibility. You’ll learn how to define what counts as evidence, how to ensure evidence is complete and time-aligned, and how to build workflows that preserve integrity from event generation...

Episode 12 — Design Monitoring and Reporting for Vulnerability Management and Audit Readiness 22.02.2026

This episode focuses on how architects design monitoring and reporting that supports vulnerability management at scale, including how evidence is collected, normalized, and presented so it is useful to both operators and auditors. You’ll review why ISSAP questions often test the difference between detection capability and reporting maturity, then learn how to define what must be monitored, where s...

Listen to the Certified: The ISC(2) ISSAP Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.