Jason Edwards
Certified: The ISC(2) ISSEP Audio Course
Certified: The ISC(2) ISSEP Certification Audio Course is built for security professionals who already speak the language of systems and risk, and now need to prove they can design security into real architectures. If you’re a practitioner moving toward security engineering, an architect who wants stronger security judgment, or a leader who has to validate designs before they ship, this course is for you. It assumes you’ve seen enterprise environments, you understand core security concepts, and you’re ready to connect them to architecture decisions that actually hold up under pressure. In Cert...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 54 — Maintain Traceability, Perform Trade-Off Studies, and Validate the Final Design 22.02.2026 14:17
This episode brings together traceability, trade-off studies, and design validation, because ISSEP expects you to defend why your final architecture is the right balance of security, cost, performance, and operational feasibility, and to prove it meets requirements with credible evidence. We define traceability as the ability to follow each requirement through design decisions to verification meth...
Episode 53 — Develop Security Design Components That Map Cleanly to Requirements 22.02.2026 16:20
This episode focuses on developing security design components that map cleanly to requirements, because ISSEP questions often test whether your design is traceable, defensible, and verifiable rather than merely “secure sounding.” We define a design component as an architectural element, control mechanism, or operational capability that implements one or more requirements, and we explain why clean...
Episode 52 — Create Functional Analysis and Allocation That Makes Security Implementable 22.02.2026 16:20
This episode explains functional analysis and allocation as the bridge between abstract requirements and implementable design, which is important for ISSEP because the exam expects you to translate security intent into system behavior that can be built and verified. We define functional analysis as identifying what the system must do, including security-relevant functions like authentication, auth...
Episode 51 — Analyze System Security Requirements to Catch Conflicts, Gaps, and Ambiguity 22.02.2026 17:16
This episode teaches how to analyze system security requirements so you can find contradictions, missing coverage, and ambiguous language before design work locks them in, which is a core ISSEP skill because many exam questions test whether you can recognize that the requirement set itself is the problem. We define requirement quality in practical terms: clarity, measurability, testability, feasib...
Episode 50 — Document a Security Requirements Baseline That Engineers Can Trace and Validate 22.02.2026 12:45
This episode explains how to document a security requirements baseline so it can be traced, implemented, and validated, which is central to ISSEP because the exam tests whether you can produce requirements that drive real engineering outcomes and credible assurance evidence. We define a baseline as the approved set of requirements and constraints that serves as the reference point for design, impl...
Episode 49 — Identify Functions and Build a Security Concept of Operations That Holds Up 22.02.2026 13:00
This episode teaches how to identify system functions and build a security concept of operations, because ISSEP expects you to connect what the system does to how it will be operated securely day after day, not just how it looks in a design document. We define functions as the capabilities the system must deliver, and we define a security CONOPS as the operational story of how people, processes, a...
Episode 48 — Develop System Security Context That Explains the Why Behind Requirements 22.02.2026 13:21
This episode explains how to develop system security context, because without a shared “why,” requirements become disconnected statements that teams interpret inconsistently, and ISSEP exam questions often test whether you can anchor requirements to mission, environment, and threat reality. We define system security context as the structured narrative of what the system is, what it protects, who u...
Episode 47 — Combine Layering, Separation, and Resiliency Into One Coherent Security Story 22.02.2026 13:21
This episode teaches how to combine layering, separation, and resiliency so your design reads as one coherent security story instead of a pile of unrelated controls, which is exactly the kind of synthesis ISSEP expects. We define layering as independent protective measures across identity, network, application, data, and monitoring planes, separation as boundaries that limit blast radius, and resi...
Episode 46 — Design Data Security Into Storage, Processing, and Movement Across the System 22.02.2026 14:49
This episode focuses on data security as an end-to-end engineering problem, because ISSEP questions frequently test whether you can protect data consistently across where it lives, how it’s processed, and how it moves between components and organizations. We define data states at rest, in transit, and in use, and we explain how confidentiality, integrity, availability, and lifecycle obligations li...
Episode 45 — Build Software Assurance Into Engineering Decisions, Not Just Testing Checklists 22.02.2026 13:48
This episode teaches software assurance as a lifecycle discipline that starts with design and requirements, not a last-minute testing activity, which aligns with ISSEP’s focus on traceability and defensible evidence. We define software assurance as the justified confidence that software behaves as intended under expected and adverse conditions, then connect assurance to decisions about architectur...
Episode 44 — Automate Threat Response and SecDevOps Without Handing Attackers the Keys 22.02.2026 15:14
This episode explains how to automate threat response and SecDevOps workflows safely, because ISSEP scenarios often test whether you can gain speed and consistency without creating a new privileged attack surface. We define threat response automation as actions triggered by signals, such as isolating hosts, rotating credentials, blocking identities, or rolling back deployments, and we define SecDe...
Episode 43 — Separate Interfaces, Functions, Services, and Roles to Contain Blast Radius 22.02.2026 13:56
This episode focuses on separation as an architectural tool for containment, and it shows why ISSEP questions often reward designs that limit blast radius through clean boundaries rather than relying on a single “strong control.” We define interfaces as the exposed points of interaction, functions as what the system does, services as deployable components that deliver functions, and roles as the h...
Episode 42 — Apply Least Privilege and Economy of Mechanism to Reduce Attack Surface 22.02.2026 15:40
This episode teaches how to apply least privilege and economy of mechanism as concrete design decisions, because ISSEP exam items frequently hinge on whether you reduce exposure at the source or just add controls after the fact. We define least privilege as granting only the permissions needed for a task, for the shortest practical time, and economy of mechanism as keeping designs simple enough to...
Episode 41 — Eliminate Single Points of Failure Before They Become Incident Headlines 22.02.2026 17:35
This episode explains how single points of failure show up in real architectures and why ISSEP questions often test whether you can spot them early, before they turn into outages, data loss, or uncontrolled privilege escalation. We define a single point of failure as any component, path, or dependency whose loss causes mission-impacting failure, then expand the idea to include “security SPOFs,” li...
Episode 40 — Choose Fail Open, Fail Secure, and Fail Closed Using Mission Logic 22.02.2026 15:55
This episode teaches how to choose fail open, fail secure, and fail closed behaviors based on mission logic, safety, and risk, which is a frequent ISSEP scenario because the “right” answer depends on context and consequences. We define each failure mode and explain what it implies for confidentiality, integrity, and availability when components break, networks partition, or dependencies time out....
Episode 39 — Apply Defense-in-Depth, Zero Trust, and Secure-by-Default in Real Designs 22.02.2026 15:26
This episode explains how to apply defense-in-depth, zero trust, and secure-by-default in practical architecture decisions, because ISSEP tests whether you can implement these concepts without turning them into slogans. We define defense-in-depth as layered controls that reduce dependence on any single barrier, zero trust as continuous verification and minimal implicit trust across boundaries, and...
Episode 38 — Engineer Resiliency With Redundancy and Diversity Without Creating New Weaknesses 22.02.2026 19:15
This episode teaches how to engineer resiliency using redundancy and diversity, while avoiding the classic failure where “more components” means “more ways to fail,” a tradeoff the ISSEP exam often probes through availability and mission-focused scenarios. We define redundancy as additional capacity or alternate paths that reduce single failures, and diversity as using different implementations or...
Episode 37 — Define Roles, Responsibilities, Constraints, Assumptions, and a Validation Plan 22.02.2026 14:24
This episode explains how to lock in the “rules of the system” early by defining roles, responsibilities, constraints, assumptions, and a validation plan, because ISSEP expects you to produce designs that can be proven correct and operated responsibly. We break down role and responsibility definitions so accountability is explicit for security decisions, approvals, operations, and incident handlin...
Episode 36 — Capture Stakeholder Requirements Without Losing Security Meaning in Translation 22.02.2026 17:46
This episode teaches how to capture stakeholder requirements so security meaning survives the trip from business language to engineering language, which the ISSEP exam tests through scenarios where vague needs turn into weak controls. We define stakeholder requirements as statements of need and constraint from business owners, operators, users, and compliance stakeholders, then show how to transla...
Episode 35 — Evaluate Operational Risk, Track Posture Changes, and Document Decisions 22.02.2026 15:28
This episode focuses on evaluating operational risk using evidence from production, then tracking how posture changes over time as controls age, systems evolve, and attackers adapt, which is core to ISSEP’s emphasis on continuous assurance. We define operational risk evaluation as estimating likelihood and impact based on real telemetry, known weaknesses, and recovery capability, not just theoreti...
Episode 34 — Identify Operational Threats, Events, Vulnerabilities, and Impacts That Matter 22.02.2026 14:20
This episode teaches how to identify operational threats and impacts with enough precision to drive decisions, because ISSEP questions often hinge on whether you can connect day-to-day system reality to credible threat events and measurable consequences. We review the difference between a threat source and a threat event in operational terms, then show how vulnerabilities often emerge from drift,...
Episode 33 — Establish Operational Risk Context for Production Systems and Mission Outcomes 22.02.2026 13:47
This episode explains how operational risk context differs from project-time risk context, and why ISSEP expects you to reason about real production constraints like uptime, staffing, and mission impact. We define operational context as the combination of business processes, service dependencies, user behavior, maintenance windows, detection capability, and recovery capacity that determines how ba...
Episode 32 — Turn Findings and Decisions Into Risk Documentation Leaders Will Defend 22.02.2026 15:53
This episode focuses on turning analysis into documentation that supports accountable decisions, which is heavily tested on ISSEP because the exam rewards clarity, traceability, and defensible rationale over vague statements. We cover what strong risk documentation includes: a clear risk statement, scope and assumptions, likelihood and impact rationale, chosen treatment, residual exposure, and the...
Episode 31 — Monitor Residual, Changed, and New Risks as System Reality Shifts 22.02.2026 16:40
This episode explains how risk monitoring works after initial decisions are made, because the ISSEP exam expects you to treat risk as a living condition that changes as systems, dependencies, and threat activity change. We define residual risk as what remains after controls, changed risk as what shifts due to modifications or environmental changes, and new risk as exposure introduced by new functi...
Episode 30 — Perform Inherent Risk Analysis, Risk Evaluation, and Document Risk Posture 22.02.2026 13:36
This episode explains how to perform inherent risk analysis and risk evaluation, then document risk posture in a way that supports decisions and holds up under review, which is exactly the type of reasoning the ISSEP exam rewards. We define inherent risk as exposure before controls, residual risk as what remains after controls, and risk posture as the documented picture of current exposure, treatm...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.