Skip to content
PodcastsCoursesCertified: The ISC(2) ISSMP Audio Course

Certified: The ISC(2) ISSMP Audio Course

Jason Edwards
Certified: The ISC(2) ISSMP Audio Course
Latest episode

120 episodes

  • Certified: The ISC(2) ISSMP Audio Course

    Episode 119 — Obtain Authorized Risk Waivers With Proper Approval and Traceable Records

    2026/02/22 | 12 mins.
    This episode teaches how to obtain authorized risk waivers with proper approval and traceable records, because ISSMP scenarios frequently hinge on who can accept risk, what evidence must exist, and how to ensure waivers do not become invisible risk debt. You will learn how risk waivers differ from operational exceptions, how to confirm decision authority and delegated limits, and how to document the risk statement, impacts, likelihood drivers, compensating controls, and time bounds so the waiver can be reviewed and revoked if conditions change. Scenarios include approving a vendor exception for a critical service, waiving a control requirement for a short-term launch, and accepting residual risk when remediation is not feasible, emphasizing the need for governance-aligned approvals and audit-ready evidence. Best practices include formal review cadence, monitoring of waiver conditions, and clear ownership for remediation planning, while troubleshooting covers “shadow waivers,” missing executive signatures, and waivers that outlive their rationale. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
  • Certified: The ISC(2) ISSMP Audio Course

    Episode 118 — Document Compliance Exceptions With Controls, Workarounds, and Risk Context

    2026/02/22 | 12 mins.
    This episode explains how to document compliance exceptions with the controls, workarounds, and risk context needed to remain defensible, because ISSMP often tests whether you understand that exceptions must be governed, time-bounded, and evidence-supported rather than informal permission slips. You will learn how to define the exact requirement being excepted, the scope and duration, the business rationale, the residual risk statement, and the compensating controls that reduce exposure while the exception exists. Scenarios include legacy systems that cannot meet baseline requirements, vendor limitations that constrain logging or encryption, and urgent business timelines that require phased control adoption, showing how exception documentation protects both governance and operational clarity. Best practices include specifying owners, review cadence, termination criteria, and monitoring indicators, while troubleshooting covers vague exceptions, missing approvals, and exceptions that spread beyond their intended scope. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
  • Certified: The ISC(2) ISSMP Audio Course

    Episode 117 — Monitor and Validate Remediation Actions Until Risk Is Truly Reduced

    2026/02/22 | 12 mins.
    This episode teaches how to monitor and validate remediation actions until risk is truly reduced, which ISSMP emphasizes because remediation is not complete when a ticket is closed, but when control performance and evidence prove the weakness is no longer present. You will learn how to track remediation by risk tier, define acceptance criteria and validation tests, and ensure owners deliver durable fixes that survive normal change activity. We apply this to scenarios like patch remediation that regresses after updates, access governance improvements that are inconsistently applied, and logging gaps that reappear during platform changes, showing how to build verification routines that detect backsliding. Best practices include remediation dashboards with aging and blockage visibility, periodic sampling for evidence quality, and escalation paths for stalled actions, while troubleshooting covers optimistic status reporting, resource constraints, and “temporary compensating controls” that become permanent. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
  • Certified: The ISC(2) ISSMP Audio Course

    Episode 116 — Evaluate and Validate Findings and Build Responses That Address Root Causes

    2026/02/22 | 13 mins.
    This episode explains how to evaluate and validate audit findings and then build responses that address root causes, because ISSMP questions often test whether you can move beyond superficial fixes and produce remediation that actually reduces risk and improves control operation. You will learn how to confirm the finding’s scope, determine whether evidence was misunderstood or incomplete, identify the real breakdown point in people, process, or technology, and craft a response that includes corrective actions, owners, deadlines, and verification steps. Scenarios include findings driven by incomplete access reviews, inconsistent configuration baselines, weak vendor evidence, and missing incident response documentation, showing how to avoid “close it on paper” remediation that fails the next audit. Best practices include clear narrative responses, measurable action plans, and governance-aligned risk framing, while troubleshooting covers disputed findings, ambiguous requirements, and organizational resistance to disruptive fixes. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
  • Certified: The ISC(2) ISSMP Audio Course

    Episode 115 — Coordinate Audit Activities and Maintain Evidence Readiness Year-Round

    2026/02/22 | 16 mins.
    This episode teaches how to coordinate audit activities and maintain evidence readiness year-round, because ISSMP expects leaders to run compliance as a continuous program capability rather than a seasonal event. You will learn how to organize evidence repositories, define evidence standards, assign owners, and create regular routines that keep artifacts current, complete, and traceable to specific controls and requirements. We cover practical scenarios such as staff turnover during an audit cycle, teams changing tools that affect logs and reports, and recurring evidence gaps that reappear every year, showing how to build durable processes that reduce audit stress. Best practices include clear evidence ownership, periodic internal checks, version control for policies and procedures, and reporting that reveals readiness trends and blocked areas. Troubleshooting focuses on “evidence debt,” inconsistent artifacts across teams, and last-minute data extraction that cannot be defended, with methods to stabilize evidence production and validation. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
More Courses podcasts
About Certified: The ISC(2) ISSMP Audio Course
Certified: The ISC(2) ISSMP Certification Audio Course is an audio-first study program for experienced security professionals who are ready to step into security management leadership. If you already understand core security concepts and you now need to lead programs, influence stakeholders, and make decisions that hold up under pressure, this course is built for you. It’s designed for practitioners moving into manager, lead, architect, or program roles, and for leaders who want a structured path toward the ISSMP credential without living in a textbook. You’ll hear the “why” behind common management choices, not just the definitions, so you can connect the exam objectives to the work you do in real organizations. Across Certified: The ISC(2) ISSMP Certification Audio Course, you’ll learn how security managers plan, govern, and run security programs in a way that aligns to business goals. We break down governance and policy, program and project management, risk management and metrics, incident and crisis leadership, and the day-to-day realities of building and sustaining a security team. Everything is taught in a clear spoken format, with tight explanations, practical framing, and examples that are easy to picture without needing slides. Because it’s audio-first, you can learn during commutes, workouts, or between meetings, turning small pockets of time into steady progress. What makes Certified: The ISC(2) ISSMP Certification Audio Course different is that it treats the ISSMP as a leadership exam, not a vocabulary test. You’ll get the mental models that help you choose the best answer when multiple options seem plausible, along with the language and reasoning patterns that show up in management-level questions. Success here means more than finishing episodes—it means you can explain tradeoffs, defend decisions, and map security work to outcomes a business cares about. By the end, you should feel comfortable translating strategy into execution, communicating risk clearly, and approaching the ISSMP with a calm, methodical plan.
Podcast website

Listen to Certified: The ISC(2) ISSMP Audio Course, The Hillsdale College Online Courses Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Certified: The ISC(2) ISSMP Audio Course: Podcasts in Family
  • Podcast Certified - CompTIA IT Fundamentals+ Audio Course
    Certified - CompTIA IT Fundamentals+ Audio Course
    Courses, Education, Technology