CCT 360: SSA Whistleblower and the Thumb Drive: What CISSP Asset Security Tells Us About This Disaster episode artwork

EPISODE · Jul 6, 2026 · 23 MIN

CCT 360: SSA Whistleblower and the Thumb Drive: What CISSP Asset Security Tells Us About This Disaster

from CISSP Cyber Training Podcast - CISSP Training Program · host Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur

Send us Fan MailImagine hearing a claim that the most sensitive identity data in the United States could be sitting on a personal thumb drive. That allegation is still unverified and under investigation, but it gives us a rare chance to see CISSP Domain 2 asset security in real time, with consequences that go far beyond a typical data breach.I walk through what’s being reported about Social Security Administration data access and potential copying, then I put on the Domain 2 lens: data classification and handling requirements, who the true data owner is, what custodians should be enforcing, and how processors should be limited by scope, purpose, and time. We talk about why “high” impact data under FIPS 199 should automatically trigger stricter controls, and how failures in encryption, logging, and data loss prevention can let sensitive datasets slip outside organizational boundaries.We also dig into the part most teams get wrong: the data lifecycle. If you cannot execute secure disposal and verify it, you cannot “close Pandora’s box.” Using NIST SP 800-88, we break down clear, purge, and destroy, connect it to real operational controls like removable media restrictions, and turn the whole story into practical exam guidance and CISO-level program lessons you can use with leadership.Subscribe for more CISSP-ready breakdowns, share this with someone studying Domain 2, and leave a review so more security pros can find the show. What is the first control you would fix in your own environment?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Episode metadata supplied by the publisher feed · Published Jul 6, 2026

Embed this episode

Send us Fan Mail Imagine hearing a claim that the most sensitive identity data in the United States could be sitting on a personal thumb drive. That allegation is still unverified and under investigation, but it gives us a rare chance to see CISSP Domain 2 asset security in real time, with consequences that go far beyond a typical data breach. I walk through what’s being reported about Social Security Administration data access and potential copying, then I put on the Domain 2 lens: data cla...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

CCT 360: SSA Whistleblower and the Thumb Drive: What CISSP Asset Security Tells Us About This Disaster

0:00 23:28

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of CISSP Cyber Training Podcast - CISSP Training Program?

This episode is 23 minutes long.

When was this CISSP Cyber Training Podcast - CISSP Training Program episode published?

This episode was published on July 6, 2026.

Can I download this CISSP Cyber Training Podcast - CISSP Training Program episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!