Jason Edwards

Certified: The PCI Qualified Security Assessor (QSA) Audio Course

Certified: The PCI QSA Certification Audio Course is an audio-first training program built for working security and compliance professionals who need to understand what it really means to operate as a PCI Qualified Security Assessor. If you’re moving into payment security, supporting PCI DSS assessments, or stepping up from “PCI helper” to “PCI lead,” this course is designed for you. It assumes you already speak basic security and risk, but it does not assume you already know PCI inside and out. You’ll get the context, the vocabulary, and the practical judgment that separates box-checking from...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 23, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 33 — Conduct Penetration Tests and Prove Segmentation Effectiveness. 23.02.2026

 This episode explains penetration testing through a QSA lens, with special attention to how PCI expectations differ from generic “we did a pen test” claims that lack scope clarity and proof of meaningful coverage. You’ll learn how to define test boundaries, objectives, and methodologies that align to the environment and the purpose of validation, including external testing, internal testing, and...

Episode 32 — Execute ASV Scans That Pass and Provide Value. 23.02.2026

 This episode teaches how Approved Scanning Vendor scanning fits into PCI validation, and why QSA exams test whether you understand scope, frequency, remediation cycles, and the meaning of “passing” beyond a PDF report. You’ll learn how to confirm that the right IP ranges and external-facing assets are included, how to prevent blind spots caused by incomplete inventories or cloud sprawl, and how t...

Episode 31 — Validate E-Commerce and Web Payments Without Surprises. 23.02.2026

This episode focuses on the e-commerce paths that create the most confusion on the QSA exam and in real assessments, because small design choices can drastically change scope, data exposure, and control responsibilities. You’ll learn how to distinguish common models such as fully outsourced payment pages, embedded iFrames, direct post methods, hosted fields, and merchant-hosted checkout flows, and...

Episode 30 — Govern the Program So Security Becomes Routine. 23.02.2026

This episode ties the technical domains together by focusing on governance and operational sustainability, because the exam expects QSAs to recognize that stable compliance comes from repeatable processes, defined ownership, and evidenceable oversight. You’ll learn how to evaluate policies and procedures as living controls, including how they are approved, communicated, reviewed, and tied to daily...

Episode 29 — Test Security Regularly and Prove It Works 23.02.2026

This episode covers the testing mindset that QSAs must apply to validate that controls remain effective over time, including vulnerability management activities, internal checks, and independent testing that confirms the environment matches its documented security posture. You’ll learn how to interpret testing requirements as a system: identify what must be tested, how often, what triggers additio...

Episode 28 — Log and Monitor Access Events That Matter Most. 23.02.2026

This episode focuses on logging and monitoring as an operational capability, not just a configuration checkbox, because QSA exams often test whether you can connect log requirements to detection, response, and accountability. You’ll learn what events must be captured, which systems are in scope for logging, and why centralized visibility and retention are critical for proving control operation ove...

Episode 27 — Control Physical Access With Tight, Auditable Measures. 23.02.2026

This episode explains physical security controls through the QSA lens, because the exam expects you to treat physical access as a direct path to system compromise, data exposure, and control bypass. You’ll learn how to identify which facilities, rooms, and storage locations matter based on scope, including data centers, server rooms, network closets, backup media storage, and areas where payment d...

Episode 26 — Strengthen User Authentication So Only the Right People In. 23.02.2026

This episode dives into authentication strength and management, focusing on how QSAs validate that identities are unique, credentials are protected, and authentication mechanisms resist common attacks. You’ll learn how to interpret requirements related to password policy, multi-factor authentication, account lockout, session controls, and how administrative access changes the risk profile and the...

Episode 25 — Limit Access Strictly to Business Need to Know. 23.02.2026

This episode covers access control at the principle level, because QSA exams repeatedly test whether you can apply “need to know” and least privilege across systems, applications, and data stores without confusing intent with implementation. You’ll learn how to define roles, permissions, and authorization boundaries in a way that maps to real job functions, then validate that access grants match t...

Episode 24 — Run a Secure Software Lifecycle That Delivers. 23.02.2026

This episode teaches secure software development and change practices in the way the QSA exam expects: as a system of controls that reduces risk across planning, building, testing, and deployment, not as a single tool or training event. You’ll learn how to evaluate governance, secure coding standards, developer training, code review expectations, and how organizations manage third-party components...

Episode 23 — Prevent and Detect Malware Before It Wrecks You 23.02.2026

 This episode focuses on malware controls from a QSA validation perspective, because the exam expects you to understand both prevention and detection, and to recognize that coverage and operational effectiveness matter more than brand names. You’ll learn how to define the systems that require malware protection based on exposure and function, including endpoints, servers, jump hosts, and administr...

Episode 22 — Encrypt Cardholder Data in Transit End to End. 23.02.2026

This episode teaches how QSAs evaluate data-in-transit protections, with emphasis on understanding what “strong cryptography” means in practice and how exam questions often hinge on where encryption begins and ends. You’ll learn to map transit paths across internal networks, external connections, APIs, and third-party integrations, then verify that the chosen protocols and configurations actually...

Episode 21 — Protect Stored Account Data With Zero Doubt. 23.02.2026

This episode covers the storage side of payment security, because PCI QSA exams routinely test whether you can distinguish what may be stored, what must never be stored, and what protections are required when account data exists in any form. You’ll define cardholder data versus sensitive authentication data, then work through practical storage locations that catch teams off guard, such as applicat...

Episode 20 — Enforce Secure System Configurations Across Every Platform. 23.02.2026

 This episode teaches secure configuration management as an operational discipline that must be consistent across servers, endpoints, network devices, and cloud workloads, and it explains how QSAs validate that discipline through evidence and testing. You’ll learn what configuration standards are expected to include, how baselines relate to hardening guides, and why exceptions must be controlled,...

Episode 19 — Architect Network Security Controls That Actually Hold. 23.02.2026

 This episode covers the network security foundations that QSAs must assess, including how segmentation, rule management, and boundary protections support the integrity of the CDE over time. You’ll learn how to interpret network security control intent, what “restrict” means in practical terms, and why the exam often emphasizes validation methods rather than product names. We explain how to evalua...

Episode 18 — Write ROCs and AOCs That Read Crystal Clear. 23.02.2026

This episode focuses on reporting as an assessment skill, because the exam and the profession both expect you to communicate scope, test methods, and conclusions without ambiguity. You’ll learn what makes ROC writing defensible, including precise scope language, consistent terminology, clear test procedures, and evidence statements that connect control intent to observed reality. We discuss how AO...

Episode 17 — Plan Interviews That Surface Clear, Defensible Evidence. 23.02.2026

 This episode teaches interviews as a validation technique, not a casual conversation, and it explains how QSAs use interviews to confirm ownership, operating effectiveness, and real-world workflow alignment with documented controls. You’ll learn how to design interview questions that map to requirement intent, how to avoid leading prompts that produce unreliable answers, and how to capture statem...

Episode 16 — Select the Right SAQ or ROC Path Confidently. 23.02.2026

This episode helps you choose between SAQs and a full ROC path without confusion, and it explains why the exam tests this decision through scoping logic, transaction types, and reliance on third parties. You’ll learn what drives eligibility, how acceptance channels and storage or transmission behaviors influence the appropriate validation method, and how a wrong selection can create compliance gap...

Episode 15 — Slash Scope Using Tokenization and True P2PE. 23.02.2026

This episode explains how tokenization and point-to-point encryption can reduce exposure, reduce scope, and reduce operational risk, but only when the design and evidence support the claim. You’ll learn the practical differences between tokenization, encryption, truncation, and masking, and why the exam expects you to understand where cardholder data still exists even after a “scope reduction” pro...

Episode 14 — Navigate Cloud and Virtualization Scope Like a Pro. 23.02.2026

This episode focuses on scoping and evidence in cloud and virtualized environments, where abstractions can hide connectivity, storage, and administrative paths that quietly pull systems into scope. You’ll learn how to reason about shared infrastructure, management planes, identity services, logging pipelines, and network constructs so you can determine what is truly part of the CDE and what can be...

Episode 13 — Govern Third-Party Service Providers Without Blind Spots. 23.02.2026

 This episode teaches how to assess and manage service provider reliance in a way that protects the merchant, clarifies responsibility boundaries, and holds up during QSA review. You’ll learn how third parties can expand scope through shared systems, admin access, hosting, support tools, and data flows, even when the business believes the provider “handles PCI.” We define what evidence typically d...

Episode 12 — Manage Compensating Controls the Right Way Every Time. 23.02.2026

 This episode covers compensating controls as a structured method for meeting the intent of a requirement when the stated approach cannot be implemented, and it explains how QSAs are expected to evaluate them with discipline. You’ll learn the core definition, the conditions that must be true for a compensating control to be acceptable, and why “we do something else” is never enough without a clear...

Episode 11 — Perform Targeted Risk Analyses That Stand Up. 23.02.2026

 This episode explains how targeted risk analysis works in PCI DSS practice and why it shows up on QSA exams as a test of judgment, not memorization. You’ll learn what “targeted” really means: a documented, requirement-specific decision process that justifies how often a control activity occurs, based on threat likelihood, impact, and the environment’s realities. We walk through the anatomy of a d...

Episode 10 — Choose Defined or Customized Approaches With Precision. 23.02.2026

 This episode addresses a decision point that can reshape an assessment: selecting and applying a defined approach versus a customized approach, and understanding what each choice demands from planning, testing, and documentation. You’ll learn the practical meaning of these approaches, how they affect what evidence is required, and why the exam tends to test your ability to recognize when “custom”...

Episode 9 — Apply Smart Sampling and Bulletproof Evidence Strategies. 23.02.2026

This episode covers how QSAs think about evidence and sampling so your conclusions reflect reality, and so your work stands up during review and quality assurance. You’ll learn what “sufficient and appropriate” means in an assessment context, including the difference between policy statements, screenshots, system outputs, tickets, interviews, and observed behavior, and why the exam expects you to...

Listen to the Certified: The PCI Qualified Security Assessor (QSA) Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.