Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

ISC2 · Free, ad-free audio course

ISC2 CISSP

A structured audio course for professionals building broad security knowledge across risk, architecture, operations, software, identity, and governance.

Every Bare Metal Cyber audio course is free and 100% ad-free.

Companion Books

Study with the audio course, then reinforce it in print.

The study guide helps you organize and revisit the material. The flashcards book adds active recall and rapid review across the course objectives.

Complete Lesson Directory

Choose the exact subject you want to study.

Search by topic or narrow the directory by exam domain. Courses with multiple editions are organized below so every season remains easy to find. Each lesson includes its own audio player, full description, transcript when available, and previous-or-next navigation.

140 lessons available

S01E01Transcript

Getting Started

What Is the CISSP and Why It Matters

In this foundational episode, we introduce the Certified Information Systems Security Professional—better known as the CISSP.…

Transcript availableJune 22, 2025
S01E02Transcript

Getting Started

CISSP vs. Other Certifications: Which One’s Right for You?

Choosing the right cybersecurity certification can shape your career for years to come. In this episode, we compare the CISSP to other well-known certifications including CompTIA Security+, CISM, CRISC, and CEH.…

Transcript availableJune 22, 2025
S01E03Transcript

Getting Started

Career Impact of the CISSP: Roles, Salaries, Growth

The CISSP isn’t just a certification—it’s a powerful career accelerator. This episode breaks down how earning your CISSP can open doors to high-level roles, raise your earning potential, and give you access to new leadership opportunities in the cybersecurity field.…

Transcript availableJune 22, 2025
S01E05Transcript

Domain 1 · Security and Risk Management

The CIA Triad: Confidentiality, Integrity, Availability

Every cybersecurity professional must understand the CIA triad—confidentiality, integrity, and availability. These three pillars form the core of nearly every security strategy, policy, and control.…

Transcript availableJune 22, 2025
S01E06Transcript

Domain 1 · Security and Risk Management

Security Governance Principles: Frameworks and Strategy

Governance gives structure and direction to an organization’s cybersecurity efforts. In this episode, we explore what it means to build a security strategy aligned with business goals, risk appetite, and compliance obligations.…

Transcript availableJune 22, 2025
S01E07Transcript

Domain 1 · Security and Risk Management

Compliance Requirements: Legal, Regulatory, Contractual

Cybersecurity professionals must navigate a complex landscape of compliance obligations. This episode explains the differences between legal, regulatory, and contractual requirements, and how they impact your organization’s security posture.…

Transcript availableJune 22, 2025
S01E08Transcript

Domain 1 · Security and Risk Management

Organizational Roles and Responsibilities

Security is not the job of a single person or department—it’s a shared responsibility across the organization. In this episode, we examine the roles of executives, managers, security teams, end users, and third-party stakeholders in protecting assets and managing risk.…

Transcript availableJune 22, 2025
S01E09Transcript

Domain 1 · Security and Risk Management

Professional Ethics and (ISC)² Code of Ethics

Ethics are the backbone of trust in the cybersecurity profession. This episode explores the professional responsibilities outlined in the ISC² Code of Ethics, including the duty to protect society, act honorably, provide competent service, and advance the profession.…

Transcript availableJune 22, 2025
S01E11Transcript

Domain 1 · Security and Risk Management

Risk Response and Risk Appetite

Once a risk is identified and assessed, the next critical step is determining how to respond. In this episode, we examine the four primary risk response strategies: risk avoidance, risk mitigation, risk transference, and risk acceptance.…

Transcript availableJune 22, 2025
S01E12Transcript

Domain 1 · Security and Risk Management

Business Continuity Planning (BCP) Fundamentals

Business Continuity Planning, or BCP, is essential for maintaining operations during unexpected disruptions. This episode explores the key elements of a successful BCP strategy, including risk identification, business impact analysis, and recovery planning.…

Transcript availableJune 22, 2025
S01E14Transcript

Domain 1 · Security and Risk Management

Security Policies, Standards, Procedures, and Guidelines

A strong cybersecurity program is built on clear and well-documented policies. In this episode, we break down the four foundational types of documentation: policies, standards, procedures, and guidelines.…

Transcript availableJune 22, 2025
S01E15Transcript

Domain 1 · Security and Risk Management

Personnel Security: Background Checks, Policies, Termination

People are often the weakest link in cybersecurity, and managing personnel risk is a critical responsibility. In this episode, we discuss best practices for pre-employment screening, including background checks and reference validation.…

Transcript availableJune 22, 2025
S01E16Transcript

Domain 1 · Security and Risk Management

Security Awareness and Training Programs

Even the best technical defenses can fail if employees don’t understand their security responsibilities. This episode focuses on the development and delivery of effective security awareness and training programs.…

Transcript availableJune 22, 2025
S01E17Transcript

Domain 1 · Security and Risk Management

Third-Party Risk Management

Today’s organizations rely heavily on vendors, contractors, and service providers—but each relationship introduces potential risks. In this episode, we cover the principles of third-party risk management, including due diligence, contractual controls, and ongoing monitoring.…

Transcript availableJune 22, 2025
S01E18Transcript

Domain 1 · Security and Risk Management

Supply Chain Risk and Due Diligence

Supply chains extend far beyond traditional logistics—they now include digital components, cloud providers, software dependencies, and more. This episode explores how cyber threats enter through the supply chain and what due diligence processes are needed to prevent compromise.…

Transcript availableJune 22, 2025
S01E19Transcript

Domain 1 · Security and Risk Management

Privacy Principles and Data Protection (GDPR, CCPA)

Protecting personal data is not just a compliance requirement—it’s a trust imperative. In this episode, we dive into key privacy principles such as data minimization, purpose limitation, and transparency.…

Transcript availableJune 22, 2025
S01E20Transcript

Domain 1 · Security and Risk Management

Intellectual Property and Licensing Laws

Cybersecurity professionals must understand how to protect not only data but also intellectual property. This episode unpacks the key types of intellectual property—copyrights, trademarks, patents, and trade secrets—and how they apply in the digital world.…

Transcript availableJune 22, 2025
S01E21Transcript

Domain 1 · Security and Risk Management

Legal Systems and Cybercrime Laws Globally

Cybersecurity professionals operate in a legal landscape that spans continents, jurisdictions, and regulatory systems.…

Transcript availableJune 22, 2025
S01E22Transcript

Domain 1 · Security and Risk Management

Security Documentation and Governance Metrics

Effective security governance depends on clear documentation and measurable performance. This episode explains the structure and function of security documentation—including policies, standards, guidelines, and procedures—as well as how to manage these documents over time.…

Transcript availableJune 22, 2025
S01E23Transcript

Domain 2 · Asset Security

Information Lifecycle and Data Classification

Understanding how data flows through its lifecycle is essential for protecting it appropriately. This episode walks through the phases of the information lifecycle: creation, storage, usage, transmission, archival, and disposal.…

Transcript availableJune 22, 2025
S01E24Transcript

Domain 2 · Asset Security

Data Sensitivity and Labeling Requirements

Labeling data according to its sensitivity is one of the most overlooked but powerful techniques in cybersecurity.…

Transcript availableJune 22, 2025
S01E25Transcript

Domain 2 · Asset Security

Ownership and Stewardship Responsibilities

Every piece of information in an organization should have an assigned owner and one or more stewards. In this episode, we define what it means to be a data owner—someone accountable for the data’s use, classification, and protection.…

Transcript availableJune 22, 2025
S01E26Transcript

Domain 2 · Asset Security

Data Retention and Archival Strategies

Keeping data longer than necessary can increase your risk exposure, but disposing of it too early can create legal and operational gaps. This episode addresses how to build effective data retention and archival strategies that meet legal, regulatory, and business needs.…

Transcript availableJune 22, 2025
S01E27Transcript

Domain 2 · Asset Security

Privacy Protection and PII Handling

Personally Identifiable Information (PII) is one of the most regulated and targeted types of data in cybersecurity. This episode focuses on how organizations identify, handle, and protect PII throughout its lifecycle.…

Transcript availableJune 22, 2025
S01E28Transcript

Domain 2 · Asset Security

Data Remanence and Secure Disposal Techniques

Even when you delete a file, remnants can linger—posing serious security risks. This episode delves into the concept of data remanence and the techniques used to ensure secure data disposal.…

Transcript availableJune 22, 2025
S01E29Transcript

Domain 2 · Asset Security

Secure Data Handling in Transit and at Rest

Data is constantly on the move—or waiting to be accessed—and must be protected in both states. In this episode, we examine the best practices for securing data at rest (stored on disk or cloud) and data in transit (moving across networks).…

Transcript availableJune 22, 2025
S01E30Transcript

Domain 2 · Asset Security

Media Storage and Sanitization Methods

Digital media—whether it’s a hard drive, USB stick, or backup tape—requires special handling to ensure data remains protected throughout its lifecycle. This episode explores how to securely store, track, and sanitize various types of storage media.…

Transcript availableJune 22, 2025
S01E31Transcript

Domain 2 · Asset Security

Asset Inventory Management

You can’t protect what you don’t know you have. In this episode, we focus on the importance of maintaining a comprehensive and accurate inventory of all information assets—hardware, software, data, and even personnel.…

Transcript availableJune 22, 2025
S01E32Transcript

Domain 2 · Asset Security

Data Sovereignty and Jurisdictional Control

In a global digital economy, where your data resides can determine which laws apply to it. This episode explains data sovereignty—the principle that data is subject to the laws of the country in which it’s stored—and how jurisdictional control affects compliance, privacy, and access.…

Transcript availableJune 22, 2025
S01E33Transcript

Domain 2 · Asset Security

Secure Use of Cloud Storage and Shared Resources

Cloud services offer scalability and convenience, but they also introduce unique security risks—especially when sharing infrastructure with other tenants.…

Transcript availableJune 22, 2025
S01E34Transcript

Domain 2 · Asset Security

Backup Controls and Data Recovery

Backup and recovery plans are your insurance against data loss. In this episode, we explore the critical controls necessary to ensure backups are available, secure, and usable when needed.…

Transcript availableJune 22, 2025
S01E35Transcript

Domain 2 · Asset Security

Handling of Sensitive Systems and High-Value Assets

Some systems and data are too critical to treat like everything else. This episode focuses on how organizations identify, secure, and manage sensitive systems and high-value assets (HVAs), such as financial databases, intellectual property repositories, and industrial control systems.…

Transcript availableJune 22, 2025
S01E36Transcript

Domain 2 · Asset Security

Logging, Monitoring, and Metadata Retention for Assets

Without visibility, security is just guesswork. In this episode, we explore how logging and monitoring give security teams the information they need to detect, investigate, and respond to incidents.…

Transcript availableJune 22, 2025
S01E37Transcript

Domain 3 · Security Architecture and Engineering

Secure Design Principles: Defense in Depth, Least Privilege

Designing secure systems isn’t just about applying tools—it’s about embedding principles. This episode introduces two foundational security design concepts: defense in depth and least privilege.…

Transcript availableJune 23, 2025
S01E38Transcript

Domain 3 · Security Architecture and Engineering

Security Models: Bell-LaPadula, Biba, Clark-Wilson

Security models are theoretical frameworks that help define how systems enforce access control, integrity, and confidentiality.…

Transcript availableJune 23, 2025
S01E39Transcript

Domain 3 · Security Architecture and Engineering

Architecture Layers: OSI, System, Application

Security must be applied across all layers of a system, from the physical infrastructure to the application interface.…

Transcript availableJune 23, 2025
S01E40Transcript

Domain 3 · Security Architecture and Engineering

Secure Hardware Architecture and TPM

Security isn’t only about software—hardware matters too. This episode introduces key elements of secure hardware architecture, including trusted computing bases, secure boot processes, and hardware root of trust.…

Transcript availableJune 23, 2025
S01E41Transcript

Domain 3 · Security Architecture and Engineering

Virtualization and Cloud Infrastructure Considerations

Virtualization and cloud computing are cornerstones of modern IT, but they also introduce unique security challenges. In this episode, we examine the architecture and risks associated with virtual machines, hypervisors, containers, and cloud platforms.…

Transcript availableJune 23, 2025
S01E42Transcript

Domain 3 · Security Architecture and Engineering

Secure Baseline and Configuration Management

Systems don’t stay secure by accident—they stay secure through consistent configuration and control. In this episode, we cover the concepts of secure baselining and configuration management.…

Transcript availableJune 23, 2025
S01E43Transcript

Domain 3 · Security Architecture and Engineering

Common Security Flaws in Architecture

Flawed architecture is one of the most serious vulnerabilities in any system. In this episode, we explore common architectural security weaknesses, including insecure defaults, lack of isolation, poor trust boundaries, and insufficient input validation.…

Transcript availableJune 23, 2025
S01E44Transcript

Domain 3 · Security Architecture and Engineering

Cryptographic Concepts: Symmetric and Asymmetric

Cryptography is the backbone of digital security, and understanding its core principles is essential. In this episode, we explain the difference between symmetric and asymmetric encryption, along with their real-world applications.…

Transcript availableJune 23, 2025
S01E45Transcript

Domain 3 · Security Architecture and Engineering

Cryptographic Lifecycle: Algorithms, Strength, Obsolescence

Cryptographic tools aren’t set-and-forget solutions—they require lifecycle management. This episode explores how organizations select, deploy, and eventually retire cryptographic algorithms.…

Transcript availableJune 23, 2025
S01E46Transcript

Domain 3 · Security Architecture and Engineering

Hashing and Message Integrity

Hashing ensures that data remains unchanged during storage or transmission—a core requirement for integrity. In this episode, we explore how cryptographic hash functions like SHA-256 and SHA-3 are used to detect tampering, generate digital signatures, and verify file authenticity.…

Transcript availableJune 23, 2025
S01E47Transcript

Domain 3 · Security Architecture and Engineering

Key Management and Key Escrow

Cryptographic systems are only as secure as the keys they use—and how those keys are managed. In this episode, we delve into key management principles, including generation, storage, distribution, rotation, and destruction.…

Transcript availableJune 23, 2025
S01E48Transcript

Domain 3 · Security Architecture and Engineering

PKI, Digital Certificates, and Trust Models

Public Key Infrastructure (PKI) is essential for enabling secure communication and verifying digital identities. This episode breaks down how PKI works, including the roles of certificate authorities (CAs), registration authorities (RAs), and digital certificates.…

Transcript availableJune 23, 2025
S01E49Transcript

Domain 3 · Security Architecture and Engineering

Cryptanalysis and Attacks Against Crypto

No cryptographic system is immune to attack, and CISSPs must understand the methods used to break or weaken them. In this episode, we explore cryptanalysis techniques including brute-force, dictionary attacks, chosen plaintext attacks, and side-channel analysis.…

Transcript availableJune 23, 2025
S01E50Transcript

Domain 3 · Security Architecture and Engineering

Security Evaluations: Common Criteria, RMF, ISO/IEC

Security evaluations provide assurance that systems meet defined security requirements. In this episode, we examine key evaluation frameworks including Common Criteria (CC), the NIST Risk Management Framework (RMF), and the ISO/IEC 27000 series.…

Transcript availableJune 23, 2025
S01E51Transcript

Domain 3 · Security Architecture and Engineering

Security Boundaries and Isolation Techniques

Security boundaries are essential for creating logical separations between systems, users, and data flows. In this episode, we explore how boundaries are defined and enforced, using both physical and logical mechanisms.…

Transcript availableJune 23, 2025
S01E52Transcript

Domain 3 · Security Architecture and Engineering

Emerging Technologies and Security Architecture (e.g., IoT, AI)

Technological innovation continues to transform the security landscape. In this episode, we examine how emerging technologies such as the Internet of Things (IoT), Artificial Intelligence (AI), and machine learning are impacting security architecture.…

Transcript availableJune 23, 2025
S01E53Transcript

Domain 3 · Security Architecture and Engineering

SCADA and Embedded System Security

Supervisory Control and Data Acquisition (SCADA) systems and embedded devices operate some of the most critical infrastructure in the world—from energy grids to transportation systems.…

Transcript availableJune 23, 2025
S01E54Transcript

Domain 3 · Security Architecture and Engineering

Fault Tolerance, Redundancy, and High Availability

Downtime is not an option for mission-critical systems. In this episode, we dive into fault tolerance, redundancy, and high availability—design strategies that ensure continuity despite component failures or unexpected disruptions.…

Transcript availableJune 23, 2025
S01E55Transcript

Domain 4 · Communication and Network Security

Network Architecture: LAN, WAN, Internet

Understanding how networks are built and connected is foundational for any security professional. In this episode, we review core network architecture concepts, including the structure and purpose of Local Area Networks (LANs), Wide Area Networks (WANs), and the global Internet.…

Transcript availableJune 23, 2025
S01E56Transcript

Domain 4 · Communication and Network Security

OSI and TCP/IP Models Refresher

The OSI and TCP/IP models provide a layered approach to understanding how data is transmitted, received, and managed across networks. In this episode, we refresh your understanding of these models and their significance in network security.…

Transcript availableJune 23, 2025
S01E57Transcript

Domain 4 · Communication and Network Security

Secure Protocols: HTTPS, SSH, SFTP, SNMPv3

Secure communication protocols form the backbone of protected digital environments. In this episode, we explore widely used secure protocols like HTTPS, SSH, SFTP, and SNMPv3.…

Transcript availableJune 23, 2025
S01E58Transcript

Domain 4 · Communication and Network Security

Network Segmentation and Microsegmentation

Segmentation limits the spread of attacks and improves control over traffic flows within a network. In this episode, we examine both traditional network segmentation and microsegmentation techniques.…

Transcript availableJune 23, 2025
S01E59Transcript

Domain 4 · Communication and Network Security

Defense in Depth with Firewalls and DMZs

Layered security—known as defense in depth—is a core concept in cybersecurity architecture. This episode focuses on how firewalls and demilitarized zones (DMZs) serve as essential layers in protecting internal networks.…

Transcript availableJune 23, 2025
S01E60Transcript

Domain 4 · Communication and Network Security

Intrusion Detection and Prevention Systems

Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) are crucial for identifying and stopping threats in real time. This episode explores how these tools work, their deployment strategies, and how they integrate with broader security operations.…

Transcript availableJune 23, 2025
S01E61Transcript

Domain 4 · Communication and Network Security

Secure Routing and Switching

Secure routing and switching are foundational elements of network security. In this episode, we explore how routers and switches operate, and how attackers exploit their misconfigurations or weaknesses to gain access or disrupt communication.…

Transcript availableJune 23, 2025
S01E63Transcript

Domain 4 · Communication and Network Security

Wireless Network Security (WEP, WPA2/3, 802.1X)

Wireless networks present a unique set of vulnerabilities due to their reliance on open air transmission. In this episode, we examine wireless security protocols and controls, including WEP, WPA2, WPA3, and 802.1X.…

Transcript availableJune 23, 2025
S01E64Transcript

Domain 4 · Communication and Network Security

VOIP and Secure Communication Channels

Voice over IP (VOIP) technologies have replaced traditional telephony in many organizations, but they come with their own set of security concerns.…

Transcript availableJune 23, 2025
S01E65Transcript

Domain 4 · Communication and Network Security

Network Address Translation and Proxy Usage

NAT and proxy servers play important roles in hiding internal IP addresses, enforcing access policies, and controlling traffic flow. In this episode, we explore how Network Address Translation (NAT) works to conserve IP space and obscure internal architectures.…

Transcript availableJune 23, 2025
S01E66Transcript

Domain 4 · Communication and Network Security

Network Monitoring and Traffic Analysis

Continuous monitoring and traffic analysis are essential for detecting threats, performance issues, and policy violations. In this episode, we explore tools and techniques used to observe network behavior in real time.…

Transcript availableJune 23, 2025
S01E67Transcript

Domain 4 · Communication and Network Security

Zero Trust and Software-Defined Networking (SDN)

Zero Trust has emerged as a powerful model for modern cybersecurity, shifting the focus from perimeter defenses to granular, identity-centric control.…

Transcript availableJune 23, 2025
S01E68Transcript

Domain 4 · Communication and Network Security

Content Delivery Networks and Edge Security

Content Delivery Networks (CDNs) accelerate access to web content by distributing it across global edge nodes, but they also introduce new attack surfaces.…

Transcript availableJune 23, 2025
S01E69Transcript

Domain 4 · Communication and Network Security

Cloud Network Security (CASB, SASE, Virtual Firewalls)

As more organizations move to the cloud, network security must evolve. This episode focuses on cloud-native controls including Cloud Access Security Brokers (CASB), Secure Access Service Edge (SASE), and virtual firewalls.…

Transcript availableJune 23, 2025
S01E70Transcript

Domain 4 · Communication and Network Security

DDoS Protection and High Availability Networks

Distributed Denial of Service (DDoS) attacks are designed to overwhelm systems and take down critical services. In this episode, we explain how these attacks work—volumetric, protocol, and application-layer—and the techniques used to defend against them.…

Transcript availableJune 23, 2025
S01E71Transcript

Domain 5 · Identity and Access Management

Authentication Factors and Methods

Authentication is the process of verifying identity, and it forms the first line of defense in access control.…

Transcript availableJune 23, 2025
S01E72Transcript

Domain 5 · Identity and Access Management

Identity Proofing and Registration Processes

Before you can authenticate someone, you must first establish their identity through a process called identity proofing. In this episode, we cover how identity proofing works—from in-person validation and biometric capture to document verification and knowledge-based authentication.…

Transcript availableJune 23, 2025
S01E74Transcript

Domain 5 · Identity and Access Management

IAM Lifecycle and Governance

Identity and Access Management (IAM) is not just about technology—it’s a continuous lifecycle that requires strong governance. This episode walks through each stage of the IAM lifecycle: provisioning, access management, auditing, revalidation, and deprovisioning.…

Transcript availableJune 23, 2025
S01E75Transcript

Domain 5 · Identity and Access Management

Password Policy Design and Management

Passwords remain one of the most widely used—but frequently abused—authentication methods. In this episode, we explore how to design and manage effective password policies that balance usability with security.…

Transcript availableJune 23, 2025
S01E76Transcript

Domain 5 · Identity and Access Management

Biometric Authentication Strengths and Weaknesses

Biometric authentication uses unique physical or behavioral traits—like fingerprints, facial features, or voice—to verify identity.…

Transcript availableJune 23, 2025
S01E77Transcript

Domain 5 · Identity and Access Management

Federation and SSO: SAML, OAuth, OpenID

Federated identity systems allow users to authenticate across multiple platforms using a single identity, often enabling Single Sign-On (SSO). In this episode, we explain how standards like SAML, OAuth 2.0, and OpenID Connect enable cross-domain authentication.…

Transcript availableJune 23, 2025
S01E78Transcript

Domain 5 · Identity and Access Management

Privileged Access Management (PAM)

Privileged accounts have elevated access and are among the most targeted assets in any organization. In this episode, we examine Privileged Access Management (PAM) solutions, including vaulting, session recording, just-in-time provisioning, and approval workflows.…

Transcript availableJune 23, 2025
S01E79Transcript

Domain 5 · Identity and Access Management

Directory Services: LDAP, Active Directory

Directory services are centralized databases that store and manage user credentials, permissions, and group memberships.…

Transcript availableJune 23, 2025
S01E80Transcript

Domain 5 · Identity and Access Management

Multi-Factor Authentication and Implementation

Multi-Factor Authentication (MFA) significantly strengthens identity verification by requiring more than one authentication factor.…

Transcript availableJune 23, 2025
S01E81Transcript

Domain 5 · Identity and Access Management

Identity-as-a-Service (IDaaS) and Cloud IAM

Identity-as-a-Service (IDaaS) provides centralized identity and access management capabilities from the cloud.…

Transcript availableJune 23, 2025
S01E82Transcript

Domain 5 · Identity and Access Management

Credential Management and Recovery

Managing credentials securely is critical to preventing unauthorized access and ensuring business continuity. This episode explores techniques for secure credential issuance, storage, expiration, and revocation.…

Transcript availableJune 23, 2025
S01E83Transcript

Domain 5 · Identity and Access Management

Access Control Lists and Capability Tables

Access control mechanisms determine who can access what—and how. In this episode, we compare two classic models: Access Control Lists (ACLs) and capability tables. ACLs associate permissions with objects, while capability tables associate them with subjects.…

Transcript availableJune 23, 2025
S01E84Transcript

Domain 5 · Identity and Access Management

Access Recertification and Review

Access permissions tend to accumulate over time, creating a significant security risk if not reviewed regularly. This episode focuses on access recertification—the process of periodically validating that users still need the permissions they’ve been granted.…

Transcript availableJune 23, 2025
S01E85Transcript

Domain 5 · Identity and Access Management

Session Management and Timeout Policies

Controlling user sessions is a critical part of maintaining secure access. In this episode, we examine how session tokens are issued, maintained, and terminated—along with techniques to prevent hijacking and session fixation attacks.…

Transcript availableJune 23, 2025
S01E86Transcript

Domain 5 · Identity and Access Management

Threats to IAM: Replay, Pass-the-Hash, Credential Stuffing

Identity systems are high-value targets, and attackers use increasingly sophisticated techniques to exploit them. This episode examines key IAM-related attack vectors, including replay attacks, pass-the-hash, credential stuffing, brute-force, and phishing-based compromise.…

Transcript availableJune 23, 2025
S01E87Transcript

Domain 6 · Security Assessment and Testing

Assessment Types: Vulnerability Scans, Pen Testing, Audits

Security assessments come in many forms—each with a specific purpose. In this episode, we compare and contrast vulnerability scanning, penetration testing, and formal security audits.…

Transcript availableJune 23, 2025
S01E88Transcript

Domain 6 · Security Assessment and Testing

Planning a Security Assessment

Security assessments must be planned thoroughly to be effective, safe, and actionable. This episode walks through the planning phase of an assessment project, including goal setting, scope definition, timeline management, and stakeholder communication.…

Transcript availableJune 23, 2025
S01E89Transcript

Domain 6 · Security Assessment and Testing

Security Control Testing: Manual vs. Automated

Security controls are only effective if they’re working as designed. In this episode, we explore how to test those controls using both manual and automated methods.…

Transcript availableJune 23, 2025
S01E90Transcript

Domain 6 · Security Assessment and Testing

Code Review and Static/Dynamic Testing

Code is a frequent source of vulnerabilities, and reviewing it is essential for secure software development. In this episode, we discuss secure code review techniques—both manual and tool-assisted.…

Transcript availableJune 23, 2025
S01E91Transcript

Domain 6 · Security Assessment and Testing

Security Test Data and Environment Management

Security testing requires careful control over both the test environment and the data used within it. In this episode, we explore how to create and manage dedicated testing environments that accurately simulate production systems without risking real assets.…

Transcript availableJune 23, 2025
S01E92Transcript

Domain 6 · Security Assessment and Testing

Test Coverage and Measurement

How do you know your security testing is thorough? In this episode, we examine test coverage metrics and how they help evaluate the effectiveness and completeness of assessments.…

Transcript availableJune 23, 2025
S01E93Transcript

Domain 6 · Security Assessment and Testing

Risk Assessment and Gap Analysis

Risk assessments help prioritize security controls by identifying vulnerabilities, evaluating threats, and estimating potential impacts.…

Transcript availableJune 23, 2025
S01E94Transcript

Domain 6 · Security Assessment and Testing

Compliance Auditing and Evidence Collection

Audits provide assurance that an organization is following its security policies and regulatory obligations. In this episode, we explore how compliance audits are structured, conducted, and evaluated.…

Transcript availableJune 23, 2025
S01E95Transcript

Domain 6 · Security Assessment and Testing

Log Analysis for Forensics and Compliance

Logs are a goldmine of insight—but only if you know how to analyze them effectively. This episode dives into log collection, normalization, and correlation to support both forensic investigations and compliance reporting.…

Transcript availableJune 23, 2025
S01E96Transcript

Domain 6 · Security Assessment and Testing

Threat Hunting and Red Team Exercises

Proactive threat hunting involves searching for signs of compromise that automated tools may miss. In this episode, we explain how threat hunters use hypothesis-driven analysis, threat intelligence, and behavioral indicators to uncover hidden risks.…

Transcript availableJune 23, 2025
S01E97Transcript

Domain 6 · Security Assessment and Testing

Reporting Assessment Results Effectively

The value of a security assessment is only realized when the results are communicated clearly. In this episode, we discuss how to structure, write, and deliver effective reports for vulnerability scans, penetration tests, audits, and more.…

Transcript availableJune 23, 2025
S01E98Transcript

Domain 6 · Security Assessment and Testing

Metrics and KPIs for Security Performance

What gets measured gets managed—and security is no exception. This episode focuses on security metrics and key performance indicators (KPIs) that help organizations evaluate the effectiveness of their controls and programs.…

Transcript availableJune 23, 2025
S01E99Transcript

Domain 6 · Security Assessment and Testing

Continuous Monitoring and Feedback Loops

Security is not a one-time event—it’s a continuous process. In this episode, we explore how continuous monitoring helps organizations detect changes, uncover risks, and maintain compliance in dynamic environments.…

Transcript availableJune 23, 2025
S01E100Transcript

Domain 6 · Security Assessment and Testing

Assessing Third-Party and Vendor Risk

Vendors and service providers often have privileged access to your data and systems—making them a potential weak link. This episode focuses on third-party risk management, including how to evaluate a vendor's security posture before and after engagement.…

Transcript availableJune 23, 2025
S01E101Transcript

Domain 7 · Security Operations

Daily Operations: Procedures, Monitoring, Checklists

Security operations are built on consistency, structure, and clear documentation. In this episode, we explore the daily tasks that keep cybersecurity programs running—such as log reviews, system checks, user access reviews, and patch verification.…

Transcript availableJune 23, 2025
S01E102Transcript

Domain 7 · Security Operations

Logging, Event Correlation, and SIEM

Capturing events is only the beginning—making sense of them is where the real value lies. This episode covers how organizations collect, normalize, and correlate logs from various systems and devices using Security Information and Event Management (SIEM) platforms.…

Transcript availableJune 23, 2025
S01E103Transcript

Domain 7 · Security Operations

Incident Management: Preparation and Response

Incidents are inevitable, and how you respond can determine the scale of impact. In this episode, we walk through the phases of incident management—preparation, identification, containment, eradication, recovery, and lessons learned.…

Transcript availableJune 23, 2025
S01E104Transcript

Domain 7 · Security Operations

Digital Forensics and Chain of Custody

Preserving and analyzing digital evidence requires precision, consistency, and legal awareness. This episode explores the fundamentals of digital forensics—from identifying and collecting evidence to maintaining a documented chain of custody.…

Transcript availableJune 23, 2025
S01E105Transcript

Domain 7 · Security Operations

Evidence Acquisition and Preservation

The reliability of evidence hinges on how it’s handled. In this episode, we dive deeper into the principles and techniques for acquiring and preserving digital evidence.…

Transcript availableJune 23, 2025
S01E106Transcript

Domain 7 · Security Operations

Disaster Recovery Planning: RTO, RPO

When disaster strikes, organizations must restore operations quickly—and with minimal data loss. This episode focuses on Disaster Recovery Planning (DRP), particularly the metrics used to guide recovery strategies: Recovery Time Objective (RTO) and Recovery Point Objective (RPO).…

Transcript availableJune 23, 2025
S01E107Transcript

Domain 7 · Security Operations

Business Continuity Testing and Tabletop Exercises

Plans are only useful if they’re tested. In this episode, we explore the various methods for testing business continuity and disaster recovery plans—including walkthroughs, simulations, functional tests, and tabletop exercises.…

Transcript availableJune 23, 2025
S01E108Transcript

Domain 7 · Security Operations

Patch Management and Configuration Control

Unpatched systems are one of the leading causes of successful cyberattacks. In this episode, we explore the role of patch management and configuration control in maintaining secure and reliable systems.…

Transcript availableJune 23, 2025
S01E109Transcript

Domain 7 · Security Operations

Change Control and Approval Processes

Security isn’t just about stopping bad changes—it’s about managing all changes effectively.…

Transcript availableJune 23, 2025
S01E110Transcript

Domain 7 · Security Operations

Secure Disposal and Media Sanitization

Data doesn’t disappear just because you delete it. In this episode, we focus on how to securely dispose of media and sanitize storage devices to prevent data recovery.…

Transcript availableJune 23, 2025
S01E111Transcript

Domain 7 · Security Operations

Endpoint Detection and Response (EDR)

Endpoints remain a primary target for cyberattacks, and protecting them requires more than traditional antivirus solutions. This episode explores Endpoint Detection and Response (EDR), a modern approach to securing laptops, desktops, servers, and mobile devices.…

Transcript availableJune 23, 2025
S01E112Transcript

Domain 7 · Security Operations

Insider Threat Identification and Mitigation

Not all threats come from the outside. Insider threats—whether malicious or accidental—pose a significant risk to organizational security. In this episode, we examine how to identify, monitor, and respond to threats from employees, contractors, or partners with legitimate access.…

Transcript availableJune 23, 2025
S01E113Transcript

Domain 7 · Security Operations

Malware Analysis and Containment

Understanding malware is essential for effective defense. This episode explores how security teams analyze and contain malicious software, including viruses, worms, ransomware, and trojans.…

Transcript availableJune 23, 2025
S01E114Transcript

Domain 7 · Security Operations

Physical Security Operations: Locks, Guards, Cameras

Cybersecurity extends into the physical world, where threats like unauthorized access, theft, and sabotage can bypass digital defenses.…

Transcript availableJune 23, 2025
S01E115Transcript

Domain 7 · Security Operations

Personnel Security Controls and Separation of Duties

People are at the heart of every security program—and also one of its greatest vulnerabilities. In this episode, we examine personnel security controls that mitigate human-based risks.…

Transcript availableJune 23, 2025
S01E116Transcript

Domain 7 · Security Operations

Security Operations Center (SOC) Best Practices

The Security Operations Center (SOC) is the nerve center of cybersecurity monitoring and incident response. In this episode, we explore SOC roles, responsibilities, staffing models, tools, and key performance indicators.…

Transcript availableJune 23, 2025
S01E117Transcript

Domain 8 · Software Development Security

Software Development Lifecycle (SDLC) Models

Secure software doesn’t happen by accident—it’s the result of disciplined development practices.…

Transcript availableJune 23, 2025
S01E118Transcript

Domain 8 · Software Development Security

Waterfall vs. Agile vs. DevOps Approaches

Development methodologies have a direct impact on how security is integrated into software projects. This episode compares three major approaches—Waterfall, Agile, and DevOps—and how each handles risk, testing, and control.…

Transcript availableJune 23, 2025
S01E119Transcript

Domain 8 · Software Development Security

Secure Design and Secure Coding Guidelines

Secure applications start with secure design. In this episode, we explore how to incorporate security into architecture and code from the very beginning. Topics include threat modeling, input validation, secure defaults, and fail-safe mechanisms.…

Transcript availableJune 23, 2025
S01E120Transcript

Domain 8 · Software Development Security

Input Validation and Output Encoding

User input is one of the most common vectors for exploitation in modern applications. In this episode, we focus on two critical programming techniques: input validation and output encoding.…

Transcript availableJune 23, 2025
S01E121Transcript

Domain 8 · Software Development Security

OWASP Top 10 Threats and Controls

The OWASP Top 10 is a widely recognized list of the most critical security risks to web applications. In this episode, we walk through each entry—from injection and broken authentication to cross-site scripting, insecure deserialization, and insufficient logging.…

Transcript availableJune 23, 2025
S01E122Transcript

Domain 8 · Software Development Security

Buffer Overflows, SQL Injection, and Common Flaws

Many devastating cyberattacks originate from well-known coding flaws. This episode examines classic vulnerabilities including buffer overflows, SQL injection, and other input-related attacks.…

Transcript availableJune 23, 2025
S01E123Transcript

Domain 8 · Software Development Security

Security Testing: SAST, DAST, IAST

Security testing helps ensure software behaves as intended under hostile conditions.…

Transcript availableJune 23, 2025
S01E124Transcript

Domain 8 · Software Development Security

Code Repositories and Access Controls

Source code repositories are central to modern software development—and to software security. This episode covers the security considerations for using platforms like GitHub, GitLab, Bitbucket, and internal repositories.…

Transcript availableJune 23, 2025
S01E125Transcript

Domain 8 · Software Development Security

Configuration Management and CI/CD Pipelines

Secure development doesn't stop at writing code—it includes how that code is built, tested, and deployed. In this episode, we explore configuration management and continuous integration/continuous delivery (CI/CD) pipelines.…

Transcript availableJune 23, 2025
S01E126Transcript

Domain 8 · Software Development Security

Version Control and Code Integrity

Version control systems track changes to code—but they also need to be protected themselves. This episode explores how tools like Git help enforce code integrity, collaboration, and traceability across development teams.…

Transcript availableJune 23, 2025
S01E127Transcript

Domain 8 · Software Development Security

Application Whitelisting and Sandboxing

Not all applications should be allowed to run in your environment. This episode explores application control mechanisms like whitelisting and sandboxing.…

Transcript availableJune 23, 2025
S01E128Transcript

Domain 8 · Software Development Security

Mobile Application Security and Reverse Engineering

Mobile apps introduce unique risks due to their widespread use, diverse platforms, and limited control over user devices. In this episode, we explore mobile app security concerns, including insecure storage, weak authentication, exposed APIs, and code tampering.…

Transcript availableJune 23, 2025
S01E129Transcript

Domain 8 · Software Development Security

Secure APIs and Service Integration

APIs enable system integration but can expose your infrastructure to serious vulnerabilities if not secured properly. This episode focuses on how to design and manage secure APIs.…

Transcript availableJune 23, 2025
S01E130Transcript

Domain 8 · Software Development Security

DevSecOps Culture and Continuous Assurance

DevSecOps is not just a toolset—it’s a culture that integrates security into every phase of the software development lifecycle. In this episode, we explore how DevSecOps breaks down silos between development, operations, and security teams.…

Transcript availableJune 23, 2025
S01E131Transcript

Exam Strategy and Review

Top 10 Hardest CISSP Concepts Demystified

Some CISSP topics consistently challenge even experienced professionals. In this episode, we break down ten of the most difficult concepts on the exam—ranging from cryptographic key lifecycle and security models to risk calculations and legal frameworks.…

Transcript availableJune 23, 2025
S01E133Transcript

Exam Strategy and Review

How to Deconstruct CISSP Questions

CISSP exam questions are known for being complex, layered, and sometimes intentionally confusing. In this episode, we teach you how to break questions apart to find the real point being tested.…

Transcript availableJanuary 17, 2026
S01E136Transcript

Exam Strategy and Review

How to Deconstruct CISSP Questions

CISSP exam questions are known for being complex, layered, and sometimes intentionally confusing. In this episode, we teach you how to break questions apart to find the real point being tested.…

Transcript availableJune 23, 2025
S01E138Transcript

Exam Strategy and Review

Adaptive Testing Tips and Time Management

The CISSP exam uses Computerized Adaptive Testing (CAT), which means question difficulty and test length vary based on your performance. In this episode, we demystify the CAT format, explain how scoring works, and share strategies to manage your time across the exam.…

Transcript availableJune 23, 2025
S01E139Transcript

Exam Strategy and Review

What Comes After the CISSP: Career and Certification Roadmap

Earning your CISSP opens new doors—but where you go next depends on your goals. In this episode, we explore the post-CISSP landscape, including leadership roles like CISO, and technical specializations like cloud security and digital forensics.…

Transcript availableJune 23, 2025
S01E140Transcript

Exam Strategy and Review

What to Do If You Fail the CISSP

Not everyone passes on the first try—but failure doesn’t define your journey. In this episode, we guide you through a structured plan for recovery if you don’t pass the CISSP exam.…

Transcript availableJune 23, 2025

A Practical Study Routine

Listen, read, and review in the order that works for you.

01

Listen

Use the free audio course during a commute, walk, workout, or focused study session.

02

Read

Use the study guide to organize the material, annotate key ideas, and build a reference you can return to.

03

Review

Use the flashcards book to practice active recall and quickly revisit weak areas.

Related Cyber Wiki

Continue with the concepts behind the course.

ATT&CK Campaign Analysis

2015 Ukraine Electric Power Attack (C0028)

A defensive guide to the Enterprise ATT&CK campaign record C0028, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2015 campaign that disrupted Ukrainian electric-power substations using BlackEnergy and KillDisk.

ATT&CK Campaign Analysis

2016 Ukraine Electric Power Attack (C0025)

A defensive guide to the Enterprise ATT&CK campaign record C0025, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2016 campaign that disrupted Ukrainian electric-power distribution using Industroyer.

ATT&CK Campaign Analysis

2022 Ukraine Electric Power Attack (C0034)

A defensive guide to the Enterprise ATT&CK campaign record C0034, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2022 campaign against a Ukrainian electric utility that combined malware and living-off-the-land behavior to issue unauthorized SCADA commands.

ATT&CK Campaign Analysis

2025 Poland Wiper Attacks (C0063)

A defensive guide to the Enterprise ATT&CK campaign record C0063, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing destructive December 2025 attacks against Polish energy infrastructure involving Windows and PowerShell wipers.

ATT&CK Campaign Analysis

3CX Supply Chain Attack (C0057)

A defensive guide to the Enterprise ATT&CK campaign record C0057, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a cascading supply-chain compromise that moved from a trojanized trading application into 3CX build environments.

AI audit

AI Audit Overreliance Safeguards

AI audit overreliance safeguards keep auditors responsible for scoping, evidence evaluation, judgment, challenge, and conclusions even when AI performs analysis or drafting.