Jason Edwards

Certified: The ISC(2) ISSMP Audio Course

Certified: The ISC(2) ISSMP Certification Audio Course is an audio-first study program for experienced security professionals who are ready to step into security management leadership. If you already understand core security concepts and you now need to lead programs, influence stakeholders, and make decisions that hold up under pressure, this course is built for you. It’s designed for practitioners moving into manager, lead, architect, or program roles, and for leaders who want a structured path toward the ISSMP credential without living in a textbook. You’ll hear the “why” behind common mana...

Author

Jason Edwards

Category

Technology

Podcast website

issmp.baremetalcyber.com

Latest episode

Feb 22, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 94 — Facilitate DRP Development With Time, Resource, and Verification Requirements 22.02.2026

This episode focuses on facilitating disaster recovery plan development with realistic time, resource, and verification requirements, because ISSMP scenarios often test whether you can align technical recovery actions with business needs and governance expectations. You’ll learn how DRP scope differs from BCP scope, how to define recovery strategies for infrastructure, platforms, and applications,...

Episode 93 — Facilitate BCP Development With Time, Resource, Verification, and BIA Constraints 22.02.2026

This episode explains how to facilitate business continuity plan development when time, resources, verification capacity, and BIA constraints limit what can be built, because ISSMP expects managers to produce workable plans rather than idealized documents. You’ll learn how to structure BCP scope around prioritized business services, define continuity strategies that match real staffing and technol...

Episode 92 — Facilitate Resiliency Planning Inputs: COOP, External Factors, Laws, and BIA 22.02.2026

This episode teaches how to facilitate resiliency planning inputs that shape continuity outcomes, with emphasis on how COOP considerations, external factors, legal and regulatory expectations, and business impact analysis results must be translated into actionable requirements. You’ll learn how external dependencies like utilities, upstream providers, critical SaaS platforms, and regional disrupti...

Episode 91 — Conduct Root Cause Analysis That Drives Control Improvements and Prevention 22.02.2026

This episode explains how to conduct root cause analysis in a way that produces durable control improvements instead of superficial “fix the symptom” remediation, because the ISSMP exam often tests whether you can turn incidents and repeated findings into governance-backed prevention. You’ll learn how to separate the initiating event from the deeper conditions that allowed it, such as weak identit...

Episode 90 — Quantify and Report Incident Impact to Stakeholders Without Speculation 22.02.2026

This episode teaches how to quantify and report incident impact to stakeholders without speculation, because ISSMP questions frequently test whether you can communicate clearly under uncertainty while still providing leaders the information they need to make decisions. You will learn how to measure impact across dimensions such as operational disruption, data exposure potential, financial cost dri...

Episode 89 — Establish Investigation Processes That Support Root Cause and Legal Needs 22.02.2026

This episode focuses on establishing investigation processes that support root cause analysis and legal needs, which is important for ISSMP because investigations must be defensible, properly documented, and coordinated with legal and privacy requirements when regulated data or external reporting obligations are involved. You will learn how to define investigation scope, preserve relevant evidence...

Episode 88 — Build Incident Handling Processes From Intake Through Containment and Recovery 22.02.2026

This episode teaches how to build incident handling processes from intake through containment and recovery, because ISSMP expects leaders to ensure incidents are handled consistently, quickly, and with evidence that supports audits and post-incident accountability. You will learn how intake criteria determine when an event becomes an incident, how severity classification drives escalation and comm...

Episode 87 — Apply Incident Management Methodologies That Scale Under Pressure 22.02.2026

This episode explains how to apply incident management methodologies that scale under pressure, because ISSMP questions often test whether you can impose structure on chaos without slowing necessary actions. You will learn how standardized methodologies provide consistent phases, decision points, communication routines, and documentation expectations, enabling the team to manage parallel work stre...

Episode 86 — Establish an Incident Response Team With Roles, Authority, and Coverage 22.02.2026

This episode teaches how to establish an incident response team with clear roles, authority, and coverage, which is central to ISSMP because response effectiveness depends on governance, decision rights, and coordination across business and technical stakeholders. You will learn how to define core roles such as incident commander, technical leads, communications, legal and privacy liaisons, and bu...

Episode 85 — Build Incident Case Management Processes That Preserve Evidence and Momentum 22.02.2026

This episode focuses on building incident case management processes that preserve evidence and momentum, because ISSMP scenarios often test whether you can keep investigations organized, defensible, and progressing toward containment and recovery. You will learn how case management structures timelines, tasks, ownership, evidence collection, approvals, and stakeholder communication so work is not...

Episode 84 — Establish Incident Program Documentation That Drives Consistent Response 22.02.2026

This episode explains how to establish incident program documentation that drives consistent response, because ISSMP expects leaders to create repeatable, auditable handling that does not collapse under stress or rely on individual heroics. You will learn what documentation must exist to enable predictable outcomes, including incident definitions and severity levels, escalation paths, communicatio...

Episode 83 — Define Actionable Alerts That Reduce Noise and Increase Analyst Confidence 22.02.2026

This episode teaches how to define actionable alerts that reduce noise and increase analyst confidence, which matters for ISSMP because operational effectiveness is measured by how reliably the team detects real threats without drowning in false positives. You will learn how to set alert criteria that incorporate context, baselines, and risk tiering, so alerts represent meaningful deviations tied...

Episode 82 — Correlate Security Events and Threat Data Into Coherent, Prioritized Cases 22.02.2026

This episode focuses on how to correlate security events and threat data into coherent, prioritized cases, because ISSMP exam scenarios frequently test whether you can move from scattered alerts to a defensible incident narrative that supports containment decisions and executive reporting. You will learn how correlation uses context such as asset criticality, identity roles, known change windows,...

Episode 81 — Identify and Categorize Attacks to Improve Response Speed and Accuracy 22.02.2026

This episode teaches how an ISSMP-level security manager ensures attacks are identified and categorized in ways that improve response speed and accuracy, because incident decisions often depend on quickly recognizing what type of activity is occurring and which playbooks, stakeholders, and evidence requirements apply. You will connect attack categorization to triage outcomes by distinguishing cate...

Episode 80 — Conduct Threat Modeling to Anticipate Attacks and Strengthen Defenses 22.02.2026

This episode explains how to conduct threat modeling to anticipate attacks and strengthen defenses, because ISSMP expects leaders to guide proactive security decisions that reduce exposure before incidents occur. You will learn how to model threats by identifying assets and trust boundaries, mapping data flows, considering attacker goals, and evaluating likely attack paths against current controls...

Episode 79 — Detect and Analyze Anomalous Behavior Patterns for Actionable Security Triage 22.02.2026

This episode teaches how to detect and analyze anomalous behavior patterns so security triage becomes actionable rather than chaotic, which is critical for ISSMP because operational response quality depends on disciplined analysis and clear escalation criteria. You will learn how to evaluate anomalies using context such as identity role, asset criticality, known change windows, control expectation...

Episode 78 — Baseline Network, Data, and User Behavior to Make Detection Credible 22.02.2026

This episode focuses on baselining network, data, and user behavior so detection is credible, because ISSMP scenarios often hinge on distinguishing real anomalies from normal operational patterns and avoiding alert fatigue that blinds the organization. You will learn how baselines should be defined by system purpose and risk tier, how to account for seasonality and business cycles, and how to inco...

Episode 77 — Aggregate Threat Intelligence From Multiple Sources Into Usable Context 22.02.2026

This episode teaches how to aggregate threat intelligence from multiple sources and convert it into usable context, which matters for ISSMP because the exam tests whether you can guide prioritization and readiness without confusing raw feeds for actionable insight. You will learn how intelligence sources differ, how to validate reliability, and how to translate information into impacts on your env...

Episode 76 — Establish and Maintain a Security Operations Center With Essential Documentation 22.02.2026

This episode explains how to establish and maintain a security operations center with essential documentation, because ISSMP expects security managers to deliver consistent operational outcomes that are auditable, measurable, and resilient under pressure. You will learn what foundational documentation enables repeatable operations, including monitoring scope definitions, alert triage criteria, esc...

Episode 75 — Monitor and Report Control Effectiveness and Coverage for Decision-Makers 22.02.2026

This episode teaches how to monitor and report control effectiveness and coverage in a way that supports decision-makers, because ISSMP questions often test whether you can translate control performance into governance-ready insights rather than operational noise. You will learn how to select a small set of high-signal indicators, track trends over time, and connect results to business impact, ris...

Episode 74 — Evaluate Control Coverage, Gaps, and Overlap Across the Control Portfolio 22.02.2026

This episode explains how to evaluate control coverage, gaps, and overlap across the control portfolio, a common ISSMP competency because mature programs avoid both blind spots and wasteful duplication while still maintaining defense in depth. You will learn how to view controls as a portfolio aligned to business services, data classifications, and key risk scenarios, then assess where coverage is...

Episode 73 — Identify Risk Controls and Determine Control Effectiveness With Evidence 22.02.2026

This episode focuses on identifying risk controls and determining control effectiveness using evidence, because ISSMP expects you to manage security by verifying what is working, not by assuming policy statements automatically become reality. You will learn how to map risks to preventive, detective, and corrective controls, then evaluate whether controls are designed appropriately and operating as...

Episode 72 — Perform Risk Analysis With Repeatable Methods and Defensible Results 22.02.2026

This episode teaches how to perform risk analysis using repeatable methods that produce defensible results, which is essential for ISSMP because governance bodies, auditors, and incident reviews all expect risk decisions to be traceable and consistent over time. You will learn how to structure risk statements, evaluate likelihood and impact using defined criteria, and account for existing controls...

Episode 71 — Identify Risk Factors and Pick the Right Risk Assessment Approach 22.02.2026

This episode explains how to identify meaningful risk factors and select the right risk assessment approach for the situation, because the ISSMP exam regularly tests whether you understand that risk assessment is not one-size-fits-all. You will learn how factors like asset criticality, data classification, threat landscape, regulatory exposure, operational dependency, and control maturity influenc...

Episode 70 — Monitor and Review Supply Chain Risks as Dependencies and Threats Change 22.02.2026

This episode teaches how to monitor and review supply chain risks as dependencies and threats change, because ISSMP expects leaders to manage supply chain risk as a living program that adapts to new integrations, service changes, and evolving attacker behavior. You will learn how to establish review triggers such as vendor scope expansion, new data types, subcontractor changes, incidents, audit fi...

Listen to the Certified: The ISC(2) ISSMP Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.