Jason Edwards
Certified: The PCI-DSS Internal Security Assessor (ISA) Audio Course
Certified: The PCI ISA Certification Audio Course is built for security and compliance professionals who touch payment environments and want to earn the PCI Internal Security Assessor credential without turning study time into a second job. If you’re a security analyst, compliance lead, auditor-in-training, IT manager, or someone responsible for PCI DSS readiness inside your organization, this course is designed for you. You don’t need to be a full-time PCI specialist to start, but you should be comfortable with basic security concepts, common enterprise systems, and the idea of documenting ev...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 33 — Govern cryptography across its complete lifecycle 22.02.2026 14:17
This episode teaches cryptography governance as a lifecycle discipline, because the ISA exam expects you to evaluate not only whether encryption exists, but whether the organization manages cryptography in a way that stays secure over time. You’ll define cryptographic governance in practical terms, including algorithm selection, protocol choices, approved use cases, configuration standards, and th...
Episode 32 — Harden databases and sensitive data repositories thoroughly 22.02.2026 15:43
This episode focuses on database security and sensitive repositories because ISA exam scenarios often hinge on whether you can connect stored data risk to concrete controls like access restriction, configuration hardening, monitoring, and evidence quality. You’ll define what counts as a sensitive data repository in payment environments, including relational databases, NoSQL stores, object storage,...
Episode 31 — Deploy, tune, and govern web application firewalls 22.02.2026 18:08
This episode explains how web application firewalls fit into PCI-aligned security and why the ISA exam treats them as a control that must be governed and validated, not simply purchased and enabled. You’ll define what a WAF does, what it does not do, and how it differs from network firewalls by focusing on application-layer behavior, request patterns, and common exploit techniques. We’ll connect W...
Episode 30 — Lock down web applications and exposed APIs 22.02.2026 13:37
This episode focuses on web applications and APIs because payment environments increasingly rely on browser-based flows and service-to-service integrations, and the ISA exam often tests how you assess exposure, authentication strength, and input handling under real constraints. You’ll define what it means for an application or API to be “exposed,” including public endpoints, partner integrations,...
Episode 29 — Embed secure software development practices teams follow 22.02.2026 14:19
This episode teaches secure software development as an operational discipline that PCI expects to be consistent, measurable, and integrated into how teams build and maintain payment-related applications. You’ll define secure development practices in the context of PCI, including requirements management, secure coding standards, peer review, security testing, and controlled deployment, then connect...
Episode 28 — Manage change and configuration with disciplined workflows 22.02.2026 14:16
This episode explains change management and configuration control as the system that keeps PCI controls true over time, which is why ISA exam questions often test whether you can connect governance steps to technical outcomes. You’ll define change management in practical terms, including request submission, impact review, approvals, testing, implementation, and rollback planning, then connect thos...
Episode 27 — Validate segmentation effectiveness with rigorous testing 22.02.2026 14:25
This episode dives deeper into segmentation by focusing on testing, because the ISA exam commonly uses scenarios where segmentation is claimed, diagrams look clean, but the evidence fails under validation. You’ll define what segmentation testing is trying to prove, including that unauthorized traffic cannot traverse into the cardholder data environment and that administrative pathways are constrai...
Episode 26 — Execute penetration testing with meaningful risk-based scope 22.02.2026 13:41
This episode covers penetration testing from the ISA perspective, emphasizing what the exam often tests: whether you understand intent, scope selection, methodology, and how results translate into risk reduction rather than a one-time report. You’ll define penetration testing in contrast to vulnerability scanning, then explain why risk-based scoping must still be defensible when payment systems, s...
Episode 25 — Conduct internal and external vulnerability scans effectively 22.02.2026 14:16
This episode explains internal and external vulnerability scanning as a measurable control cycle that the ISA exam expects you to evaluate end to end, from scope accuracy to remediation validation. You’ll define what distinguishes internal versus external scanning, why vantage point matters, and how scanning frequency, asset coverage, and credential use change the quality of results. We’ll discuss...
Episode 24 — Monitor security events and tune actionable alerts 22.02.2026 13:50
This episode builds on centralized logging by teaching monitoring as a process that produces action, which is exactly the kind of applied understanding the PCI ISA exam targets in scenarios about detections, response, and ongoing effectiveness. You’ll define security event monitoring in terms of goals and coverage, then connect it to alert logic, triage procedures, escalation paths, and proof that...
Episode 23 — Centralize logging and retain credible forensic evidence 22.02.2026 15:40
This episode explains logging as an assessment-grade control, not just a technical feature, because ISA exam questions often test whether you can connect log collection, retention, integrity, and access control into a defensible evidence trail. You’ll define what “centralized logging” means operationally, including forwarding from endpoints, servers, network devices, cloud services, and critical a...
Episode 22 — Control physical access to sensitive facilities reliably 22.02.2026 17:16
This episode focuses on physical security controls because the PCI ISA exam expects you to understand how physical access can defeat strong logical controls when attackers or unauthorized staff can reach devices, network ports, or media. You’ll define what “sensitive facilities” means in PCI terms by connecting it to in-scope systems, storage locations for account data, and areas that could affect...
Episode 21 — Secure remote access and hardened administrative pathways 22.02.2026 16:44
This episode covers remote access as one of the highest-risk control surfaces in PCI programs and a frequent focus of PCI ISA exam scenarios because it blends authentication, network paths, logging, and vendor governance in a single decision. You’ll define what counts as remote access in practical terms, including VPN, zero trust portals, bastion hosts, remote support tools, cloud consoles, and “i...
Episode 20 — Require strong multifactor authentication across all users 22.02.2026 15:50
This episode focuses on multifactor authentication in a way the ISA exam expects, including where MFA is required, what counts as a factor, and how implementation details determine whether the control is actually effective. You’ll define MFA, then apply it to common PCI-relevant pathways such as administrative access to systems in scope, remote access into environments that can impact the CDE, and...
Episode 19 — Enforce least-privilege and true need-to-know access 22.02.2026 15:47
This episode builds your least-privilege toolkit for the ISA exam by turning a familiar concept into an assessable, testable control strategy. You’ll define least privilege and need to know in operational terms, then learn how they apply across identities, roles, systems, and data stores inside and adjacent to the cardholder data environment. We’ll discuss how organizations implement role-based ac...
Episode 18 — Run vulnerability management continuously without blind spots 22.02.2026 17:22
This episode explains vulnerability management as an ongoing program, not a quarterly scramble, and shows how the ISA exam tests your ability to connect scanning outputs to remediation and risk decisions. You’ll define vulnerability scanning, authenticated versus unauthenticated coverage, and the difference between finding weaknesses and actually reducing exposure. We’ll cover how asset inventory...
Episode 17 — Prevent, detect, and contain malware before impact 22.02.2026 17:14
This episode covers malware defense as a layered control set that includes prevention, detection, and response, which is exactly how ISA exam questions tend to frame it. You’ll define malware broadly, explain why PCI cares about both traditional endpoints and servers that “shouldn’t get malware,” and connect the topic to common payment environment realities like admin workstations, jump hosts, and...
Episode 16 — Encrypt data in transit everywhere, every time 22.02.2026 18:53
This episode focuses on encryption in transit and the practical judgment the ISA exam expects when you’re evaluating “secure transmission” across mixed environments. You’ll define what it means for data to be encrypted in transit, how strong protocols and configurations differ from weak or misconfigured ones, and why “we use HTTPS” is not sufficient evidence by itself. We’ll connect encryption to...
Episode 15 — Protect stored account data from unauthorized exposure 22.02.2026 15:32
This episode explains how PCI thinks about protecting stored account data, with a focus on what the ISA exam expects you to verify: where the data lives, who can reach it, and what controls prevent misuse. You’ll review the definitions and handling rules around PAN, sensitive authentication data, and data retention, then learn how storage protections are validated through design and evidence rathe...
Episode 14 — Enforce secure configuration baselines without configuration drift 22.02.2026 17:20
This episode covers secure configuration baselines as a living control set, because the ISA exam frequently tests whether you understand ongoing enforcement rather than one-time hardening. You’ll define what a baseline is, what sources typically drive it, and how organizations translate baseline requirements into standards for operating systems, network devices, databases, and cloud services. We’l...
Episode 13 — Implement robust network security controls that hold 22.02.2026 16:41
This episode teaches the network security control concepts the ISA exam expects you to apply, not just recognize, including boundary protection, traffic restriction, and proof of enforcement. You’ll connect the idea of “only what is necessary” to practical rule design, and you’ll learn how to evaluate whether firewall rules, ACLs, security groups, and routing controls actually support PCI intent....
Episode 12 — Engineer compensating controls assessors actually approve 22.02.2026 17:19
This episode focuses on compensating controls, which the ISA exam often tests through scenarios that look reasonable on the surface but fail the strict criteria in practice. You’ll define what a compensating control is, when it is allowed, and why it cannot be used as a convenient workaround for cost or inconvenience. We’ll cover the expected structure of compensating control documentation, includ...
Episode 11 — Perform Targeted Risk Analyses that drive decisions 22.02.2026 17:29
This episode explains Targeted Risk Analysis in PCI DSS terms and shows how it becomes a scored, defensible decision point on the ISA exam. You’ll define what makes a risk analysis “targeted,” how it differs from broad enterprise risk work, and why PCI expects you to document assumptions, threats, likelihood, impact, and the control objective you are protecting. We’ll walk through how targeted ana...
Episode 10 — Apply the PCI Customized Approach correctly, decisively 22.02.2026 12:37
This episode explains the PCI Customized Approach in a way that supports both exam success and real program execution, focusing on when it is appropriate and how to do it without creating assessment chaos. You’ll define the Customized Approach versus the Defined Approach, then learn the core expectation: you must demonstrate that your control objective is met through a documented, defensible metho...
Episode 9 — Govern service providers and shared responsibility rigorously 22.02.2026 12:46
This episode covers service provider governance, an area the ISA exam tests heavily because misunderstandings here cause real incidents and failed assessments. You’ll define what PCI considers a service provider, what shared responsibility actually means, and why “the vendor does PCI” is never a complete control statement. We’ll cover how to evaluate and document responsibilities for hosting provi...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.