Jason Edwards

Certified: The ISC(2) ISSMP Audio Course

Certified: The ISC(2) ISSMP Certification Audio Course is an audio-first study program for experienced security professionals who are ready to step into security management leadership. If you already understand core security concepts and you now need to lead programs, influence stakeholders, and make decisions that hold up under pressure, this course is built for you. It’s designed for practitioners moving into manager, lead, architect, or program roles, and for leaders who want a structured path toward the ISSMP credential without living in a textbook. You’ll hear the “why” behind common mana...

Author

Jason Edwards

Category

Technology

Podcast website

issmp.baremetalcyber.com

Latest episode

Feb 22, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 69 — Verify and Validate Supply Chain Controls and Confirm They Actually Work 22.02.2026

This episode focuses on verifying and validating supply chain controls and confirming they actually work, because ISSMP questions often hinge on the difference between vendor promises and evidence-backed assurance. You will learn how to determine which controls require independent validation, how to evaluate attestations and reports in context, and how to test operational realities such as access...

Episode 68 — Integrate Third-Party Risks Into Enterprise Risk Management End to End 22.02.2026

This episode explains how to integrate third-party risks into enterprise risk management end to end, which matters for ISSMP because vendor risks must be expressed, treated, and reported in the same governance language as internal risks. You will learn how to capture third-party risk statements with clear ownership, map them to business services and data flows, and ensure risk treatment decisions...

Episode 67 — Manage Supply Chain Risk Objectives Across Vendors, Suppliers, and Partners 22.02.2026

This episode teaches how to manage supply chain risk objectives across vendors, suppliers, and partners, because ISSMP scenarios often test whether you can extend governance beyond your perimeter and maintain accountability when dependencies multiply. You will learn how to define supply chain objectives tied to confidentiality, integrity, availability, and resiliency, then translate those objectiv...

Episode 66 — Test, Monitor, and Report Risks and Issues With Operational Follow-Through 22.02.2026

This episode explains how to test, monitor, and report risks and issues with operational follow-through, because ISSMP expects risk management to produce measurable action, not static registers and periodic presentations. You will learn how to define monitoring indicators for risk drivers, validate whether treatments are working, and build reporting that highlights trend direction, emerging concen...

Episode 65 — Document and Manage Agreed Risks, Issues, Treatments, and Accountability 22.02.2026

This episode focuses on documenting and managing agreed risks, issues, treatments, and accountability so decisions remain traceable and enforceable, because ISSMP questions frequently test whether you can create governance artifacts that survive audits, incidents, and leadership turnover. You will learn how to record risk statements with clear scope, owners, impact descriptions, likelihood conside...

Episode 64 — Choose Risk Treatment Options and Perform Cost-Benefit Analysis That Persuades 22.02.2026

This episode teaches how to choose among risk treatment options—mitigate, transfer, avoid, or accept—and perform cost-benefit analysis that persuades leadership, which is a core ISSMP skill because decisions must be justified with tradeoffs, not intuition. You will learn how to compare options using business impact, likelihood reduction, residual risk, implementation cost, operational burden, and...

Episode 63 — Analyze Organizational Risks and Select Countermeasures and Compensating Controls 22.02.2026

This episode explains how to analyze organizational risks and select countermeasures and compensating controls that fit real constraints, because ISSMP expects leaders to choose workable risk reductions that preserve business outcomes and remain auditable. You will learn how to frame risk in terms of threat, vulnerability, likelihood, impact, and existing control environment, then select counterme...

Episode 62 — Build and Verify Asset Inventory Inputs That Make Risk Analysis Reliable 22.02.2026

This episode teaches how to build and verify the asset inventory inputs that make risk analysis reliable, because ISSMP scenarios routinely fail candidates who assume perfect inventories, ignore data owners, or miss dependencies that change impact. You will learn what “asset” means in a program context, including systems, applications, data sets, identities, third-party services, and business proc...

Episode 61 — Identify Risk Tolerance and Appetite and Translate It Into Real Decisions 22.02.2026

This episode explains how to identify organizational risk tolerance and risk appetite and then translate those concepts into concrete security decisions, because ISSMP questions often test whether you can align control choices, exception handling, and prioritization to what the business has actually agreed to accept. You will learn how appetite and tolerance differ, how they are expressed through...

Episode 60 — Define Risk Program Objectives With Owners, Stakeholders, and Clear Scope 22.02.2026

This episode teaches how to define risk program objectives with clear owners, stakeholders, scope boundaries, and success measures, because ISSMP questions often test whether you can build a risk program that produces decisions instead of paperwork. You will learn how to establish what the risk program covers, how risk is identified and analyzed, who has authority to accept or treat risk, and how...

Episode 59 — Ensure Ongoing Policy Compliance Through Continuous Monitoring Practices 22.02.2026

This episode explains how to ensure ongoing policy compliance through continuous monitoring practices, because ISSMP expects leaders to maintain security posture over time rather than assume compliance is permanent after a one-time review. You will learn how to translate policy requirements into monitorable controls, define evidence sources, and build routines that detect drift in configurations,...

Episode 58 — Coordinate Stakeholders and Manage Change Documentation and Tracking Cleanly 22.02.2026

This episode focuses on stakeholder coordination and clean change documentation, because ISSMP exam scenarios often punish unclear ownership, missing approvals, and weak evidence when something goes wrong and the organization needs to reconstruct what happened. You will learn how to manage change records that capture scope, risk tier, required security checks, approvals, test evidence, rollback pl...

Episode 57 — Conduct Security Impact Analysis That Prevents Change-Driven Incidents 22.02.2026

This episode teaches how to conduct security impact analysis that prevents change-driven incidents, a key ISSMP capability because many real-world failures occur when teams change systems without understanding how controls, dependencies, and monitoring will be affected. You will learn how to analyze proposed changes for effects on access control, data exposure, logging, availability, recovery, and...

Episode 56 — Integrate Security Requirements Into Change Control Without Slowing Delivery 22.02.2026

This episode explains how to integrate security requirements into change control so changes remain fast, safe, and auditable, because ISSMP questions often test whether you can embed governance into operations without becoming a bottleneck. You will learn how to tier changes by risk, define security checks that match each tier, and use automation and standard patterns to reduce manual review overh...

Episode 55 — Monitor and Report Vulnerabilities With Actionable, Executive-Ready Signal 22.02.2026

This episode teaches how to monitor and report vulnerability posture with signal that leaders can act on, which ISSMP tests because managers must communicate exposure, progress, and obstacles without drowning stakeholders in technical noise. You will learn how to build reporting that highlights trends, aging, coverage, and risk concentration by critical assets, while separating operational metrics...

Episode 54 — Drive Mitigation and Remediation to Closure Without Endless Re-Openings 22.02.2026

This episode focuses on how to drive mitigation and remediation to true closure, because ISSMP scenarios often include recurring findings caused by unclear ownership, weak verification, or temporary fixes that quietly expire. You will learn how to assign accountable owners, define acceptance criteria, validate fixes with evidence, and manage exceptions and compensating controls without creating pe...

Episode 53 — Manage Security Testing Across Scanning, Pen Testing, and Threat Analysis 22.02.2026

This episode explains how to manage security testing as a coordinated program across automated scanning, penetration testing, and threat analysis, because ISSMP expects you to choose the right method for the right question and then act on the results. You will learn what each testing approach is designed to reveal, how scope and rules of engagement affect findings, and how to avoid misusing result...

Episode 52 — Prioritize Threats and Vulnerabilities Based on Risk, Impact, and Likelihood 22.02.2026

This episode teaches how an ISSMP-level leader prioritizes threats and vulnerabilities by connecting likelihood and impact to real business services, rather than treating every critical CVSS as equally urgent. You will learn how to evaluate exploitability, attacker capability, exposure paths, control coverage, and compensating mitigations, then combine those factors into risk-informed queues and t...

Episode 51 — Build Vulnerability Programs: Asset Criticality, Classification, and Prioritization 22.02.2026

This episode explains how to build a vulnerability management program that starts with what matters most, because ISSMP questions often test whether you prioritize remediation based on business impact instead of raw severity scores. You will learn how asset criticality, data classification, exposure, and dependency mapping shape which findings become urgent, which can be scheduled, and which requi...

Episode 50 — Address How Organizational Initiatives Shift Security Posture and Risk 22.02.2026

This episode focuses on how organizational initiatives shift security posture and risk, because ISSMP expects leaders to anticipate second-order effects when the business changes direction, technology changes shape, or operating models evolve. You will learn how initiatives such as rapid growth, cloud migration, outsourcing, new product lines, or geographic expansion change attack surface, data fl...

Episode 49 — Implement Core Security Principles Across Initiatives and Emerging Technology 22.02.2026

This episode teaches how to implement core security principles consistently across initiatives and emerging technology, which matters for ISSMP because exam scenarios often present new platforms or delivery models and test whether you can apply foundational principles rather than chase tool-specific details. You will reinforce principles such as least privilege, defense in depth, secure defaults,...

Episode 48 — Oversee Security Configuration Management Processes That Prevent Drift 22.02.2026

This episode explains how an ISSMP-level security manager oversees security configuration management processes that prevent drift, because the exam expects you to understand how secure states degrade over time through unmanaged change, inconsistent builds, and operational shortcuts. You will learn how configuration management supports governance by establishing approved baselines, controlling chan...

Episode 47 — Implement Security Controls Throughout the System Lifecycle With Traceability 22.02.2026

This episode teaches how to implement security controls across the system lifecycle with traceability that supports governance, audit, and incident response, because ISSMP often tests whether you can connect “what should be true” to “what is actually deployed” with evidence. You will learn how to maintain traceability from requirements to design decisions, configurations, testing results, and oper...

Episode 46 — Integrate Security Decision Points and Requirements Across the System Lifecycle 22.02.2026

This episode focuses on integrating security decision points and requirements across the system lifecycle so decisions are made at the right time, by the right authority, with evidence that can be validated later, which aligns directly with ISSMP expectations for governance-driven execution. You will learn how to define lifecycle decision points such as initiation approval, architecture validation...

Episode 45 — Analyze Project Scope, Timelines, Quality, and Budget Through a Security Lens 22.02.2026

This episode explains how an ISSMP-level leader analyzes project scope, timelines, quality expectations, and budget constraints through a security lens, because many exam questions test tradeoff decisions where security must be integrated into delivery planning. You will learn how to evaluate whether scope includes critical security requirements, whether timelines allow for necessary design and ve...

Listen to the Certified: The ISC(2) ISSMP Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.