CCT 354: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY episode artwork

EPISODE · Jun 1, 2026 · 37 MIN

CCT 354: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY

from CISSP Cyber Training Podcast - CISSP Training Program · host Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur

Send us Fan MailYour firewall can be patched tomorrow, but what about the place your system hides its real secrets today? We start with a timely warning about a serious Fortinet FortiGate vulnerability and why perimeter devices are still a make-or-break control, then we pivot into the deeper layer most people ignore until it’s too late: memory.We walk through CISSP Domain 3.4 by focusing on what memory protection is actually trying to achieve: confidentiality, integrity, and process isolation. From there, we unpack how modern operating systems enforce separation with paging, segmentation, and strict read, write, execute controls. You’ll hear why Meltdown and Spectre were such a big deal, how speculative execution can leak passwords and encryption keys from privileged memory, and why patching decisions are never just “apply everything” but a risk-based vulnerability management call that depends on visibility into what you run.Next, we connect memory protection to virtualization security. We break down hypervisors, guest and host isolation, Type 1 versus Type 2 designs, and the threats that keep security teams up at night: VM escape, side-channel leakage through shared CPU resources, and the operational hazards of memory overcommitment. Then we bring in hardware roots of trust through TPMs: secure boot, measured boot, key storage for full disk encryption, TPM 2.0 types, and how HSM-style key management shows up in cloud environments. We close with practical best practices, from firmware and microcode updates to choosing encryption controls that fit your actual risk.If you’re studying for the CISSP or building a real-world security strategy, subscribe, share this with a teammate, and leave a review so more security pros can find it.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Episode metadata supplied by the publisher feed · Published Jun 1, 2026

Embed this episode

Send us Fan Mail Your firewall can be patched tomorrow, but what about the place your system hides its real secrets today? We start with a timely warning about a serious Fortinet FortiGate vulnerability and why perimeter devices are still a make-or-break control, then we pivot into the deeper layer most people ignore until it’s too late: memory. We walk through CISSP Domain 3.4 by focusing on what memory protection is actually trying to achieve: confidentiality, integrity, and process isolat...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

CCT 354: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY

0:00 37:28

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of CISSP Cyber Training Podcast - CISSP Training Program?

This episode is 37 minutes long.

When was this CISSP Cyber Training Podcast - CISSP Training Program episode published?

This episode was published on June 1, 2026.

Can I download this CISSP Cyber Training Podcast - CISSP Training Program episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!