Jason Edwards

Certified: The ISC(2) ISSMP Audio Course

Certified: The ISC(2) ISSMP Certification Audio Course is an audio-first study program for experienced security professionals who are ready to step into security management leadership. If you already understand core security concepts and you now need to lead programs, influence stakeholders, and make decisions that hold up under pressure, this course is built for you. It’s designed for practitioners moving into manager, lead, architect, or program roles, and for leaders who want a structured path toward the ISSMP credential without living in a textbook. You’ll hear the “why” behind common mana...

Author

Jason Edwards

Category

Technology

Podcast website

issmp.baremetalcyber.com

Latest episode

Feb 22, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 44 — Choose and Apply Agile, Waterfall, Lean, and Hybrid Methods With Security Fit 22.02.2026

This episode teaches how to choose and apply agile, waterfall, lean, and hybrid delivery methods in a way that preserves security outcomes, which matters for ISSMP because the exam often presents project constraints and asks for the management approach that keeps risk controlled without blocking delivery. You will learn the strengths and limitations of each method, how requirements and evidence ar...

Episode 43 — Incorporate Security Throughout the Product Lifecycle From Concept to Retirement 22.02.2026

This episode explains how to incorporate security throughout the full product lifecycle, from initial concept through design, build, release, support, and retirement, because ISSMP questions frequently test whether you can manage security as a continuous program responsibility rather than a last-minute review. You will learn how lifecycle phases create different security decision needs, such as de...

Episode 42 — Integrate Security Controls Into Business Processes With Minimal Disruption 22.02.2026

This episode teaches how to integrate security controls into business processes so they are adopted naturally and produce evidence consistently, which is central to ISSMP because leaders are evaluated on making security workable at scale. You will learn how to identify the right insertion points in procurement, onboarding, change control, SDLC, service delivery, and incident workflows, then choose...

Episode 41 — Identify Communication Bottlenecks and Remove Barriers to Security Execution 22.02.2026

This episode explains how an ISSMP-level security manager identifies communication bottlenecks that slow security execution and then removes those barriers without creating new friction, because exam scenarios often hinge on why “good” security decisions fail to land in operations. You will learn to recognize breakdown points such as unclear ownership, competing priorities, missing escalation path...

Episode 40 — Resolve Conflicts Between Security and Stakeholders Without Losing Ground 22.02.2026

This episode focuses on resolving conflicts between security and stakeholders without losing ground, a common ISSMP exam scenario because disagreements about risk, timelines, cost, and control impact are inevitable in real organizations. You will learn how to diagnose the real conflict—scope, authority, incentives, misunderstanding, or competing risk tolerance—then guide the conversation toward de...

Episode 39 — Build Cross-Functional Relationships That Keep Security Embedded and Trusted 22.02.2026

This episode explains how to build cross-functional relationships that keep security embedded and trusted, which ISSMP emphasizes because influence and partnership are often more effective than authority alone. You will learn how to establish working alliances with IT operations, development, product, procurement, legal, privacy, and business leaders by aligning security objectives to their goals...

Episode 38 — Create Team Accountability That Works in Real Organizational Friction 22.02.2026

This episode teaches how to create team accountability that holds up under real organizational friction, a core ISSMP skill because security programs fail when accountability exists only on paper. You will learn how to set expectations using clear outcomes, measurable deliverables, and governance-backed decision rights, while recognizing that teams operate under competing priorities, legacy constr...

Episode 37 — Define Security Roles and Responsibilities Across Teams and Third Parties 22.02.2026

This episode focuses on defining security roles and responsibilities across internal teams and third parties, which ISSMP tests because unclear accountability is a major root cause of control failures, audit findings, and slow incident response. You will learn how to establish ownership for governance, risk acceptance, control operation, evidence production, and remediation, and how to clarify bou...

Episode 36 — Manage and Report Financial Responsibilities With Credibility and Clarity 22.02.2026

This episode explains how an ISSMP-level security manager handles financial responsibilities and reporting with credibility, because exam questions often test whether you can manage budgets, justify spend, and communicate financial impacts in a governance-appropriate way. You will learn how to track expenditures against plan, manage vendor spend, evaluate cost versus risk reduction, and report fin...

Episode 35 — Adjust Budget Requests as Risks and Threats Shift Mid-Year 22.02.2026

This episode teaches how to adjust budget requests when risks and threats shift mid-year, which matters for ISSMP because effective security management requires adaptive planning, credible communication, and governance-aligned decision-making during change. You will learn how to recognize triggers such as material incidents, emerging threat patterns, regulatory changes, major business initiatives,...

Episode 34 — Prepare and Secure the Annual Security Budget Under Competing Priorities 22.02.2026

This episode focuses on preparing and securing the annual security budget under competing priorities, a frequent ISSMP theme because program leaders must justify investments using risk, strategy alignment, and operational realities rather than fear or vague claims. You will learn how to translate the security roadmap into costed initiatives, differentiate run versus change spend, and connect budge...

Episode 33 — Use Metrics to Drive Security Program and Operations Improvements That Last 22.02.2026

This episode explains how to use metrics as a management tool to drive durable improvements in both security programs and security operations, which is central to ISSMP because the exam expects leaders to close the loop from measurement to action to verified outcomes. You will learn how to interpret trends, identify root causes, and convert findings into initiatives such as process changes, toolin...

Episode 32 — Tie Security Metrics to Risk Posture and What Leadership Actually Cares About 22.02.2026

This episode teaches how to connect security metrics to risk posture in a way that leaders can understand and act on, which ISSMP tests because security managers must translate technical realities into business decisions about risk treatment, funding, and priorities. You will learn how to map metrics to risk scenarios, critical business services, and risk appetite statements, then present them as...

Episode 31 — Identify KPI and KRI Metrics That Reflect Security Performance and Exposure 22.02.2026

This episode explains how to select KPIs and KRIs that accurately reflect security performance and risk exposure, which is heavily tested in ISSMP because leadership decisions depend on metrics that are defensible, actionable, and tied to governance outcomes rather than technical trivia. You will learn the difference between activity counts and outcome indicators, how KRIs signal increasing exposu...

Episode 30 — Monitor, Evaluate, and Report Training Effectiveness With Meaningful Evidence 22.02.2026

This episode teaches how to monitor, evaluate, and report training effectiveness using evidence that supports governance decisions, because ISSMP expects leaders to prove that training changes outcomes rather than merely tracking attendance. You will learn the difference between completion metrics and effectiveness indicators, and how to connect training objectives to measurable behaviors such as...

Episode 29 — Identify Training Needs and Implement Programs by Role and Target Segment 22.02.2026

This episode focuses on identifying training needs and implementing programs by role and target segment, because ISSMP tests whether you understand that effective training is contextual, measurable, and tied to real behaviors. You will learn how to segment audiences such as executives, managers, developers, IT operations, help desk staff, and general users, then define training objectives that map...

Episode 28 — Promote Security Programs to Stakeholders Using Their Language and Incentives 22.02.2026

This episode teaches how to promote security programs to stakeholders by speaking their language and aligning to their incentives, which ISSMP emphasizes because program adoption is largely a leadership and communication problem. You will learn how to tailor messages for executives, product leaders, operations, developers, finance, and HR by connecting security work to what they care about: revenu...

Episode 27 — Monitor and Enforce Contractual Security Commitments Without Creating Drag 22.02.2026

This episode explains how an ISSMP-level security manager monitors and enforces contractual security commitments without creating unnecessary operational drag, because the exam expects you to balance assurance, efficiency, and relationship management. You will learn how to define ongoing oversight activities such as periodic attestations, performance reviews, evidence sampling, security metrics re...

Episode 26 — Embed Regulatory Compliance Requirements Into Contracts and Service Agreements 22.02.2026

This episode teaches how to embed regulatory and compliance requirements into contracts and service agreements so obligations are enforceable, measurable, and evidence-driven, which matters for ISSMP because compliance failures often stem from weak contracting rather than missing technical controls. You will learn how to translate external requirements into vendor obligations for data handling, br...

Episode 25 — Manage Security Impact of Mergers, Acquisitions, Outsourcing, and Reorgs 22.02.2026

This episode focuses on managing security during major organizational change—mergers, acquisitions, outsourcing, and reorganizations—because ISSMP tests your ability to preserve governance, visibility, and control coverage when everything is moving at once. You will learn how changes affect identity and access, data classification, incident response, vendor obligations, policy consistency, and aud...

Episode 24 — Govern Managed Services and Cloud Services With Security Built In 22.02.2026

This episode explains how to govern managed services and cloud services so security responsibilities are clear, measurable, and continuously enforced, a critical ISSMP domain because many exam questions test shared responsibility and oversight failures. You will learn to identify which controls remain internal, which are provided by the vendor, and which require joint implementation, then translat...

Episode 23 — Evaluate Service Management Agreements for Risk, Cost, and Accountability 22.02.2026

This episode teaches how to evaluate service management agreements through a security management lens, because ISSMP expects you to understand how operational services, responsibilities, and evidence requirements shape real risk. You will learn how agreements define service scope, uptime and recovery expectations, incident and escalation handling, access controls, logging and monitoring responsibi...

Episode 22 — Develop Procedures, Standards, Guidelines, and Baselines That Operate Together 22.02.2026

This episode explains how procedures, standards, guidelines, and baselines complement policy and translate governance intent into repeatable operational behavior, which matters on the ISSMP exam because many questions require you to pick the correct level of documentation for a given need. You will define each artifact type, then learn how they fit as a hierarchy: policy states what must be true,...

Episode 21 — Advocate for Policy Adoption and Secure Organization-Wide Commitment 22.02.2026

This episode focuses on how an ISSMP-level security manager drives real policy adoption rather than producing documents that sit on a shelf, because the exam frequently tests whether you understand policy as a governance mechanism that requires communication, ownership, and enforceability. You will learn how to position policy as a shared operational agreement, clarify who must comply and why, and...

Episode 20 — Establish Internal Policies That Are Clear, Enforceable, and Auditable 22.02.2026

This episode teaches how to establish internal security policies that people can follow, leaders can enforce, and auditors can validate, which is central to ISSMP because policy is a governance instrument that drives consistent, defensible security decisions. You will learn how to write policy statements that define scope, intent, required behaviors, and authority, while avoiding vague language th...

Listen to the Certified: The ISC(2) ISSMP Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.