Skip to content
PodcastsCoursesCertified: The ISC(2) ISSAP Audio Course

Certified: The ISC(2) ISSAP Audio Course

Jason Edwards
Certified: The ISC(2) ISSAP Audio Course
Latest episode

87 episodes

  • Certified: The ISC(2) ISSAP Audio Course

    Episode 86 — Align IAM Logging With Policies and Regulations Including PCI DSS and GDPR

    2026/02/22 | 23 mins.
    This episode ties identity and access logging to policy and regulatory expectations, showing how to design evidence that satisfies both security outcomes and compliance requirements, which ISSAP frequently tests by mixing audit language with real-world architecture constraints. You’ll learn how to align IAM log content, retention, access controls, and reporting to organizational policies and to common regulatory drivers, focusing on accountability, least privilege enforcement, and proof that access to sensitive systems and data is monitored and reviewed. We’ll cover practical examples such as logging administrative actions on payment systems, tracking access to personal data repositories, documenting access reviews and exceptions, and ensuring logs are protected as sensitive data themselves under privacy rules. Troubleshooting considerations include collecting more personal data than necessary in logs, missing required events because integrations were incomplete, and retention settings that conflict across legal, privacy, and security needs. This is the last episode in the series, and it brings the logging and IAM threads together into a single defensible approach you can apply on the exam and in real architecture reviews. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
  • Certified: The ISC(2) ISSAP Audio Course

    Episode 85 — Build Log Analysis and Reporting That Connects IAM Events to Business Risk

    2026/02/22 | 22 mins.
    This episode teaches how to analyze and report IAM-related log data in a way that connects technical events to business risk, which is central to ISSAP because the exam expects architects to communicate impact, not just produce dashboards. You’ll learn how to design analysis that highlights identity-driven attack paths, such as credential stuffing, MFA fatigue patterns, privilege escalation, service account misuse, and risky third-party app consent events, then translate those findings into risk statements leadership can act on. We’ll cover how to build reports that show trends, control effectiveness, and high-risk exceptions, including how to segment by business unit, data sensitivity, or application criticality so you can prioritize remediation. Practical examples include correlating authentication anomalies with sensitive data access, identifying persistent admin access outside approved windows, and reporting on joiners-movers-leavers failures that create orphan access. Troubleshooting considerations include incomplete context fields that prevent meaningful correlation, reports that focus on volume instead of risk, and metrics that can be gamed because they do not align to actual control outcomes. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
  • Certified: The ISC(2) ISSAP Audio Course

    Episode 84 — Engineer Log Retention and Integrity Controls That Hold Up in Court

    2026/02/22 | 17 mins.
    This episode explains how to design log retention and integrity so evidence remains trustworthy when it matters most, including legal discovery, regulatory review, and post-incident investigations, which ISSAP questions often probe through chain-of-custody and tamper-resistance scenarios. You’ll learn how to define retention periods by data type and risk, then design storage that preserves logs against deletion, alteration, and unauthorized access, including the use of write-once storage patterns, cryptographic integrity checks, and strict separation between log producers, log administrators, and investigators. We’ll cover how time synchronization, consistent identifiers, and controlled access auditing contribute to evidentiary value, not just operational convenience. Practical examples include protecting privileged activity logs from the same admins who hold infrastructure rights, ensuring cloud control-plane logs are retained beyond default windows, and building a defensible export process for legal teams. Troubleshooting considerations include retention gaps caused by cost pressure, integrity controls that fail because key management was overlooked, and evidence handling that breaks credibility due to undocumented access or incomplete timelines. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
  • Certified: The ISC(2) ISSAP Audio Course

    Episode 83 — Establish Log Alerts and Notifications That Support Rapid Response and Investigation

    2026/02/22 | 17 mins.
    This episode focuses on turning logs into actionable alerts that reduce response time without creating alert fatigue, which is a common ISSAP theme when questions ask how to detect meaningful security events and respond with confidence. You’ll learn how to design alerting based on threat scenarios and control objectives, including high-signal identity events like repeated failed logins with successful authentication, impossible travel patterns, privilege assignment changes, new MFA enrollments, and anomalous token usage. We’ll cover how to tune thresholds, add context, and route notifications to the right responders with escalation paths that match business impact and operational coverage. Practical examples include separating “investigate soon” alerts from “contain now” alerts, using correlation across IAM and endpoint events to reduce false positives, and building runbooks that specify the first verification steps so analysts do not waste time. Troubleshooting considerations include noisy rules that train teams to ignore alerts, missing context that prevents triage, and notification pipelines that fail during incidents because they depend on the same identity or email systems under attack. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
  • Certified: The ISC(2) ISSAP Audio Course

    Episode 82 — Define Audit Events That Matter Without Flooding Storage and Analysts

    2026/02/22 | 18 mins.
    This episode teaches how to decide which audit events must be captured to satisfy exam objectives, investigations, and compliance evidence, without creating a logging firehose that hides the signals you actually need. You’ll learn how to categorize events by risk and purpose, including identity lifecycle changes, authentication and session activity, authorization decisions, privileged actions, data access to sensitive repositories, configuration changes, and security control health signals. We’ll connect event selection to architecture by showing how to define consistent event schemas, capture key context like actor identity and system identifiers, and avoid gaps caused by distributed services, proxies, and cloud abstractions. Practical examples include choosing events that reveal privilege escalation, detecting unusual access to regulated data, and recording administrative changes that alter monitoring or security policies. Troubleshooting considerations include over-logging low-value events, under-logging the actions that matter most, and inconsistent event fields that make correlation unreliable even when “everything is logged.” Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
More Courses podcasts
About Certified: The ISC(2) ISSAP Audio Course
Certified: The ISC(2) ISSAP Certification Audio Course is an audio-first study and skills program for security architects who need to design, justify, and lead real-world security architecture work. It’s built for experienced practitioners who already understand core security concepts and now want to operate at the architecture level—people moving from engineer to architect, senior analysts stepping into design authority, consultants who must defend decisions, and managers who need to evaluate architecture proposals with confidence. If you work with requirements, risk, controls, and design tradeoffs—and you want a clear path to advanced architecture mastery—this course is for you. You’ll learn how to translate business goals into security requirements, build architecture models that stand up to scrutiny, and make design choices that balance risk, cost, and operational reality. The teaching style is direct, practical, and designed for listening: short explanations, clear definitions, and decision-focused walkthroughs that sound natural and stick. Because it’s audio-first, you can learn in the gaps of a busy week—commutes, workouts, or between meetings—without losing the thread or needing to stare at a screen to make progress. What sets this course apart is that it treats security architecture as a working discipline, not a pile of theory. You’ll practice how architects think: framing problems, selecting patterns, tracing impacts, and communicating the “why” behind a design to technical teams and executives. Success looks like being able to walk into an architecture review and lead it—asking sharper questions, spotting weak assumptions, and proposing alternatives that fit the organization. When you finish, you won’t just recognize the right terms—you’ll be ready to apply them.
Podcast website

Listen to Certified: The ISC(2) ISSAP Audio Course, EconTalk and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Certified: The ISC(2) ISSAP Audio Course: Podcasts in Family
  • Podcast Certified - CompTIA IT Fundamentals+ Audio Course
    Certified - CompTIA IT Fundamentals+ Audio Course
    Courses, Education, Technology
  • Podcast Certified - AWS Certified Cloud Practitioner Audio Course
    Certified - AWS Certified Cloud Practitioner Audio Course
    Courses, Education, Technology