Jason Edwards

Certified: The SSCP Audio Course

The SSCP Audio Course from BareMetalCyber.com delivers a complete, exam-ready learning experience for cybersecurity professionals who prefer to learn on the go. Each episode breaks down complex security concepts into plain English, aligning directly with the official (ISC)² Systems Security Certified Practitioner domains. Listeners gain a clear understanding of the core principles—access controls, risk management, cryptography, network defense, and incident response—through real-world examples that tie theory to practice. Every topic is designed to reinforce what matters most on exam day: how...

Author

Jason Edwards

Category

Technology

Podcast website

baremetalcyber.com

Latest episode

Mar 11, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 21 — Apply Access Control Models to Real-World Scenarios 11.11.2025

Access control models translate policy into predictable, auditable decisions, and the SSCP exam often tests whether you can pick the simplest model that truly fits the scenario. This episode contrasts discretionary access control (DAC), mandatory access control (MAC), role-based access control (RBAC), and attribute/claims-based access control (ABAC), clarifying what each optimizes for and how they...

Episode 20 — Orchestrate Identity Lifecycle From Proofing to Deprovisioning 11.11.2025

Identity lifecycle management turns policy into predictable access outcomes, and exam scenarios frequently hinge on whether accounts follow a controlled birth-to-death path. We outline the stages: identity proofing, account creation, role assignment, periodic review, change events, and termination. You’ll learn how to design joiner-mover-leaver workflows that anchor access to job functions, enforc...

Episode 19 — Secure Third-Party Connectivity and External Integrations 11.11.2025

Third-party links expand capability and risk, and the exam expects you to reason across legal, technical, and operational safeguards. We start by framing integration types—site-to-site VPNs, partner portals, API exchanges, managed service access—and the minimum controls each requires. Topics include least-privilege network exposure, authentication and authorization for machines and people, encrypt...

Episode 18 — Map Trust Boundaries and Network Security Zones Clearly 11.11.2025

Clear trust boundaries make designs understandable and testable, which the SSCP exam rewards in scenario questions. This episode defines zones (public, DMZ, partner, production, management, and restricted data enclaves) and explains how data classification and threat models drive segmentation choices. We discuss the difference between north-south and east-west traffic, why default-deny policy and...

Episode 17 — Leverage Single Sign-On and Federation for Usability 11.11.2025

Single Sign-On (SSO) and federation reduce password sprawl while improving control, and exam items often test whether you can match the right protocol and trust model to a scenario. We define SSO within a domain versus cross-domain federation, outline roles (identity provider, service provider, relying party), and compare common protocols such as SAML, OAuth 2.0, and OpenID Connect at a conceptual...

Episode 16 — Harden User and Device Authentication Against Attacks 11.11.2025

Strong authentication blocks a large share of real-world compromises and appears frequently on the SSCP exam. This episode clarifies the difference between identification, authentication, and authorization; distinguishes factors (something you know, have, are); and explains assurance concepts like resistance to phishing, replay, and credential stuffing. We compare passwords, passphrases, tokens, m...

Episode 15 — Recap Core Security Concepts for Rapid Retention 11.11.2025

Midway through preparation, a structured recap boosts confidence and reveals gaps. This episode consolidates foundational ideas—risk, threats, vulnerabilities, controls, and assurance—into a compact mental model you can apply under time pressure. We revisit confidentiality, integrity, availability, and accountability, tying them to policy choices and technical mechanisms so you can quickly map que...

Episode 14 — Coordinate Seamlessly With Physical Security Stakeholders 11.11.2025

Cyber and physical security must operate as one system, and the exam expects you to recognize where they intersect. We map key touchpoints—badging and identity proofing, visitor management, surveillance integration, evidence storage, and incident response—to show how information flows across teams. You’ll learn how zones, guard procedures, and access reviews interact with logical controls like pri...

Episode 13 — Drive Engaging Security Awareness Programs People Remember 11.11.2025

Awareness programs succeed when they change behavior, not just deliver slides. This episode explains how to align messages with real threats, job roles, and measurable outcomes. We discuss building blocks such as a content calendar, role-specific modules, micro-learning nudges, and reinforcement through leadership and peer norms. You’ll learn how to pair required topics—acceptable use, phishing re...

Episode 12 — Run Change and Configuration Management Without Chaos 11.11.2025

Change and configuration management prevent outages and security regressions, and the exam expects you to know their purpose and artifacts. We distinguish configuration baselines from desired state, explain how inventory and versioning tie to risk, and show how approvals, impact analysis, and back-out plans reduce unintended consequences. You’ll see how emergency changes differ from standard and n...

Episode 11 — Handle Data Retention, Archiving, and Secure Destruction 11.11.2025

Effective data management protects the organization legally and technically, and it is a frequent theme on the SSCP exam. This episode clarifies the differences among retention, archiving, and disposal so you can choose the action that aligns with business, regulatory, and evidentiary needs. We define retention as keeping data accessible for a prescribed period, archiving as moving data to long-te...

Episode 10 — Manage the Full Asset Inventory and Lifecycle 11.11.2025

Accurate asset inventories make every other control possible. We define assets broadly—hardware, software, data, services, identities—and explain lifecycle stages from procurement and onboarding to maintenance, reassignment, and secure disposal. The episode connects inventory discipline to exam-relevant tasks like vulnerability coverage, license compliance, data classification, and incident scopin...

Episode 9 — Document Functional Control Types With Real Examples 11.11.2025

Understanding control types helps you choose the most effective safeguard and justify it clearly. We distinguish preventive, detective, and corrective controls; physical, technical, and administrative forms; and compensating controls used when preferred options are not feasible. The episode explains how exam questions often hinge on identifying the control type needed to meet a stated objective or...

Episode 8 — Administer Administrative Controls and Prove Compliance 11.11.2025

Administrative controls turn policy into consistent behavior and auditable evidence. We define the role of governance artifacts—policies, standards, procedures, and guidelines—and explain how they cascade into training, background screening, segregation of duties, and formal approvals. The episode ties these concepts to exam items that test whether you can recognize the right administrative step t...

Episode 7 — Apply Robust Physical Security Safeguards Across Facilities 11.11.2025

Physical security underpins every logical control because attackers who reach hardware can bypass software assumptions. We organize safeguards into deterrence, detection, delay, and response, then show how exam scenarios embed these layers in offices, data centers, branch sites, and temporary spaces. You’ll review barriers, lighting, locks, and surveillance; visitor management and badging; secured...

Episode 6 — Implement Technical Security Controls That Actually Work 11.11.2025

Technical controls only deliver value when they are mapped to clear objectives and verified in operation. This episode frames control selection around threats, assets, and required assurance levels, then ties each control to the pillar it primarily supports. We clarify baseline concepts—default-deny, least privilege, segmentation, secure configuration, and defense-in-depth—and explain how they app...

Welcome to the SSCP Audio Course! 11.11.2025
Episode 5 — Master Confidentiality, Integrity, Availability and Accountability 11.11.2025

CIA plus accountability forms the backbone of control selection and exam reasoning. We define confidentiality safeguards that restrict unauthorized disclosure, integrity measures that prevent unauthorized alteration, and availability protections that keep services dependable. Accountability ties actions to identities through logging, nonrepudiation, and auditable processes. You’ll learn how these...

Episode 4 — Live the Code of Ethics in Daily Decisions 11.11.2025

The SSCP Code of Ethics is more than a pledge—it is a decision framework that shows up in questions and real work. We unpack the canon, its priorities, and how it interacts with organizational policy, law, and contractual duties. You’ll see how principles like protecting society and acting honorably guide choices when requirements collide. We explain the difference between confidentiality and secr...

Episode 3 — Understand Exam Rules, Policies, and Test Logistics 11.11.2025

Clarity on rules and logistics protects your focus on test day. This episode explains registration steps, identification requirements, reschedule policies, accommodation requests, and the professional ethics you agree to when you sit for the exam. We cover what is permitted in the testing room, how breaks work, how the adaptive engine handles pacing, and what happens when technical issues occur. Y...

Episode 2 — Build a Practical, Realistic SSCP Study Path 11.11.2025

A study plan is only effective if it fits real life and the exam’s domain weights. We begin by translating the blueprint into a calendar, balancing heavier domains with spaced repetition and short daily reviews for lighter areas. You’ll learn how to set outcome-based goals for each week, choose primary references, and tag notes with domain IDs so retrieval practice targets what the exam values. We...

Episode 1 — Decode the SSCP Exam Landscape and Requirements 11.11.2025

Success on the SSCP begins with seeing the whole playing field clearly. This episode explains how the exam blueprint maps to core domains, how items are weighted, and what “job-task” orientation means for the kinds of questions you will face. We outline eligibility requirements, experience waivers, continuing professional education expectations, and the endorsement process so there are no surprise...

Listen to the Certified: The SSCP Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.