Jason Edwards
Certified: The PCI Qualified Security Assessor (QSA) Audio Course
Certified: The PCI QSA Certification Audio Course is an audio-first training program built for working security and compliance professionals who need to understand what it really means to operate as a PCI Qualified Security Assessor. If you’re moving into payment security, supporting PCI DSS assessments, or stepping up from “PCI helper” to “PCI lead,” this course is designed for you. It assumes you already speak basic security and risk, but it does not assume you already know PCI inside and out. You’ll get the context, the vocabulary, and the practical judgment that separates box-checking from...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 58 — Lightning Recap of Core Controls and Must-Knows. 23.02.2026 18:05
This final episode reinforces the high-yield concepts that appear across QSA exam questions by tying scoping, evidence, testing, and reporting into one coherent mental model you can recall quickly under time pressure. You’ll review the foundational decisions that drive everything else, including defining the CDE, validating segmentation, tracing data flows, selecting appropriate assessment approa...
Episode 57 — Avoid Classic ROC Writing Pitfalls Examiners Hate. 23.02.2026 13:33
This episode focuses on the reporting mistakes that consistently create review friction, because the exam and the QSA profession both expect you to write with clarity, precision, and alignment between what was tested and what is claimed. You’ll learn how to avoid vague statements, contradictory scope language, and conclusions that are not supported by the documented testing steps, and you’ll pract...
Episode 56 — Handle Evidence and Documentation Safely and Systematically. 23.02.2026 15:39
This episode focuses on evidence handling as a security and professionalism requirement, because PCI assessments involve sensitive artifacts and the exam expects you to understand how evidence quality and protection affect defensibility. You’ll learn how to request evidence efficiently, confirm authenticity, and maintain a clear chain from requirement intent to test method to observed result, whil...
Episode 55 — Scope Serverless and Containerized Workloads Without Gaps. 23.02.2026 17:22
This episode teaches scoping in modern architectures where ownership boundaries and infrastructure layers can be abstracted, because the exam expects you to apply PCI principles even when there are no “traditional servers” to point at. You’ll learn how to reason about serverless functions, managed runtimes, container platforms, orchestration, and CI/CD pipelines, with emphasis on where cardholder...
Episode 54 — Compare Tokenization and Encryption to Choose Wisely. 23.02.2026 17:02
This episode clarifies a common decision area where exam questions like to trap candidates: when tokenization is the right tool, when encryption is the right tool, and when a design uses both but teams misunderstand what each one actually protects. You’ll learn how to define tokenization in practical terms, including what the token represents, where the real PAN is stored, and how detokenization i...
Episode 53 — Meet the QSA QA Program With Confidence. 23.02.2026 15:49
This episode prepares you for the quality assurance expectations that shape QSA work, because the exam and the profession assume you understand that assessments are reviewed, challenged, and measured against consistency standards. You’ll learn what QA is trying to ensure, including disciplined scoping, traceable evidence, clear testing descriptions, and reporting that matches what was actually val...
Episode 52 — Set Data Retention and Purging That Reduces Scope. 23.02.2026 18:17
This episode focuses on retention and deletion because PCI scope often stays large simply because data lingers in places nobody monitors, and the QSA exam tests whether you can connect minimization decisions to evidence and control outcomes. You’ll learn how to define retention requirements based on business need, legal obligations, and risk, then translate those decisions into enforceable rules...
Episode 51 — Build Clear Shared Responsibility Matrices That Work. 23.02.2026 16:34
This episode explains shared responsibility as a scoping and evidence discipline, because PCI assessments often fail when teams assume “the provider handles it” without proving who owns which controls and where those controls operate. You’ll learn how to build a responsibility matrix that is specific enough to guide testing, including how to map controls to the merchant, the service provider, and...
Episode 50 — Manage Certificates and TLS Lifecycles Without Expiry Drama. 23.02.2026 12:06
This episode teaches certificate and TLS lifecycle management as an operational control that impacts encryption reliability, service availability, and the defensibility of data-in-transit protections, making it a frequent exam target. You’ll learn how to build and validate a certificate inventory, define ownership, and ensure issuance, renewal, revocation, and replacement are controlled and docum...
Episode 49 — Protect Payment Pages and Kill Malicious Script Skimmers. 23.02.2026 12:00
This episode addresses payment page protection, a high-visibility topic where the exam expects you to understand how client-side scripts can exfiltrate data even when everything “behind the page” looks secure. You’ll learn what makes a payment page sensitive, how modern e-commerce relies on third-party scripts, tags, and integrations, and why supply chain risk and script integrity are central to...
Episode 48 — Assess Mobile and Contactless Payments for Hidden Risks. 23.02.2026 12:16
This episode tackles mobile and contactless payment patterns that can confuse scope and responsibilities, because modern payment flows often involve device ecosystems, tokenization layers, and third-party components that change where data is handled. You’ll learn how to reason about NFC tap-to-pay, mobile wallets, QR-based payment journeys, and in-app payments, with emphasis on identifying what da...
Episode 47 — Verify Payment Terminals Meet PTS the Smart Way. 23.02.2026 11:41
This episode focuses on payment terminals and PIN entry devices, explaining how QSAs evaluate device security in a way that aligns with PCI PTS expectations and real-world operational controls. You’ll learn what PTS is intended to address, how device approval and lifecycle management fit into a broader PCI program, and why the exam often tests whether you can distinguish “approved device model” fr...
Episode 46 — Control Vendor and Support Access With Guardrails. 23.02.2026 12:24
This episode teaches how QSAs evaluate third-party and support access because these pathways routinely bypass standard controls, expand scope, and create high-impact risk when they are not tightly governed. You’ll learn how to define vendor access models, including remote support tools, bastion hosts, privileged access management, temporary accounts, and break-glass workflows, then validate that e...
Episode 45 — Harden Databases and Mask PAN Everywhere It Lives. 23.02.2026 13:23
This episode focuses on databases because they are one of the most common places cardholder data ends up lingering, replicating, and leaking into unexpected corners, and the exam expects QSAs to reason about both configuration and data handling hygiene. You’ll learn how to validate database hardening practices such as removing defaults, restricting administrative access, enforcing secure authenti...
Episode 44 — Synchronize System Time Reliably Across the Environment. 23.02.2026 12:05
This episode covers time synchronization as a foundational control that quietly impacts log integrity, incident response, and the credibility of audit trails, making it a frequent “hidden dependency” topic on QSA exams. You’ll learn why inconsistent time undermines correlation across systems, complicates investigations, and can make evidence unreliable even when controls are otherwise strong. We d...
Episode 43 — Implement File Integrity Monitoring That Catches the Drift. 23.02.2026 14:23
This episode explains file integrity monitoring as a practical detection and accountability control, not just a compliance artifact, and it shows why the exam expects you to understand scope selection and operational evidence. You’ll learn what types of files and directories typically matter most in a PCI context, including system binaries, configuration files, security settings, payment applicati...
Episode 42 — Control Change and Release Pipelines Without Chaos. 23.02.2026 14:57
This episode teaches change control as a control system that protects PCI outcomes, because the QSA exam frequently tests whether you can connect “significant change” events to required testing, documentation, and governance follow-through. You’ll learn how to evaluate change management from request to approval to implementation, including how to confirm that changes affecting the CDE are assessed...
Episode 41 — Validate Wireless and Remote Access Without Weak Links. 23.02.2026 16:54
This episode focuses on two areas where PCI assessments often uncover “quiet” scope expansion and real risk: wireless connectivity and remote access pathways. You’ll learn how QSAs evaluate whether wireless networks are properly segmented from the CDE, how to validate that segmentation claims hold up in practice, and what evidence proves wireless security settings are managed rather than improvise...
Episode 40 — Align Testing Frequencies and Triggers to Reality. 23.02.2026 14:44
This episode focuses on how organizations decide “how often” controls are performed and tested, because QSA exams frequently probe your understanding of frequency requirements, trigger events, and what evidence proves the cadence is real. You’ll learn how to align activities like vulnerability scanning, access reviews, log reviews, key rotation, and segmentation validation to both PCI expectations...
Episode 39 — Calibrate Vulnerability Severity and Prioritize Real Risk. 23.02.2026 15:23
This episode teaches vulnerability severity as a decision discipline, because PCI programs often live or die on how well teams distinguish urgent exposure from background noise, and the exam tests whether you can reason about impact and likelihood with evidence. You’ll learn how severity is determined in practice, how CVSS and vendor ratings are used, and why context like exploitability, exposure...
Episode 38 — Triage Common Noncompliance Findings With Calm Authority. 23.02.2026 14:58
This episode prepares you for the findings patterns that show up repeatedly in PCI assessments and on QSA exams, where the challenge is not spotting a gap but deciding how to validate it, describe it, and drive it toward resolution. You’ll learn how to classify findings based on control intent and risk, how to confirm whether a gap is systemic or isolated, and how to avoid both over-reporting and...
Episode 37 — Make Compliance Truly Business-as-Usual All Year. 23.02.2026 14:01
This episode explains how mature programs avoid the annual scramble by building controls that run continuously and generate reliable evidence as a natural byproduct of operations. You’ll learn how to translate PCI requirements into steady rhythms like weekly change review, monthly access review, quarterly testing, and continuous monitoring, and how to document those rhythms so a QSA can validate t...
Episode 36 — Prepare Incident Response and Forensics That Deliver Clarity. 23.02.2026 16:03
This episode teaches incident response as a capability that must be planned, tested, and evidenced, because PCI expectations focus on readiness and learning, not just the existence of a document. You’ll learn how to validate that incident response procedures cover roles, communications, containment, eradication, recovery, and post-incident review, and how those procedures integrate with logging,...
Episode 35 — Monitor Effectively With SIEM, Alerts, and Triage. 23.02.2026 15:53
This episode focuses on turning monitoring into action, because the QSA exam expects you to recognize that log collection without analysis is not an operating control. You’ll learn how a SIEM, SOAR, or centralized monitoring platform supports PCI goals by enabling detection, investigation, and timely response for events that matter in and around the CDE. We define the practical building blocks of...
Episode 34 — Operate Cryptographic Key Management With Zero Missteps. 23.02.2026 17:40
This episode goes deep on key management because QSA exams regularly test whether you understand that encryption strength depends as much on key handling as on algorithms. You’ll learn how to define the key lifecycle, including generation, distribution, storage, use, rotation, backup, escrow, revocation, and destruction, and how to validate that each step is controlled and documented. We explain p...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.