Certified: The GIAC GCCC Audio Course cover art

All Episodes

Certified: The GIAC GCCC Audio Course — 60 episodes

#
Title
1

Welcome to the GIAC GCCC Audio Course

2

Episode 59 — Validate resilience after fixes with retesting and durable closure evidence

3

Episode 58 — Translate pen test findings into remediation priorities and measurable control improvements

4

Episode 57 — Plan penetration tests safely: scope control, rules of engagement, and reporting clarity

5

Episode 56 — Improve response capability with lessons learned and continuous program refinement

6

Episode 55 — Execute incident response under pressure: detection, containment, and evidence handling

7

Episode 54 — Build incident response readiness with roles, playbooks, and communications discipline

8

Episode 53 — Reinforce skills over time with role-based focus, coaching, and timely feedback

9

Episode 52 — Measure training effectiveness with metrics tied to real risk reduction outcomes

10

Episode 51 — Build awareness programs that change behavior, not just complete training requirements

11

Episode 50 — Monitor third-party risk continuously with signals, assessments, and escalation triggers

12

Episode 49 — Enforce provider accountability through contracts, controls, and ongoing assurance reviews

13

Episode 48 — Evaluate service providers with due diligence that matches risk and criticality

14

Episode 47 — Detect and remediate weaknesses with testing evidence, prioritization, and closure proof

15

Episode 46 — Reduce application risk by managing dependencies and patching weak components quickly

16

Episode 45 — Secure the software lifecycle end-to-end: design, build, deploy, and operate safely

17

Episode 44 — Prove recoverability with restore tests, integrity checks, and documented results

18

Episode 43 — Protect backups as high-value targets: access controls, encryption, and isolation strategy

19

Episode 42 — Define recovery objectives that fit business reality: RPO, RTO, and scope decisions

20

Episode 41 — Retain and dispose of data safely with automation, approvals, and audit evidence

21

Episode 40 — Protect data with access boundaries, encryption decisions, and controlled sharing patterns

22

Episode 39 — Classify data in practice: sensitivity tiers, handling rules, and real-world exceptions

23

Episode 38 — Confirm email and browser protections work with testing and measurable outcomes

24

Episode 37 — Harden web browsing with technical safeguards and safer execution pathways

25

Episode 36 — Reduce phishing success with email controls that block, warn, and verify safely

26

Episode 35 — Improve monitoring outcomes with tuning, validation, and gap-driven coverage fixes

27

Episode 34 — Detect threats faster with triage workflows, escalation rules, and response coordination

28

Episode 33 — Design network visibility that matters: telemetry selection and baseline behavior modeling

29

Episode 32 — Control network changes safely with baselines, approvals, and rollback discipline

30

Episode 31 — Harden network device management planes to reduce takeover and tampering risk

31

Episode 30 — Inventory network infrastructure: devices, services, dependencies, and ownership clarity

32

Episode 29 — Validate malware defenses with testing, tuning, and incident-driven improvement loops

33

Episode 28 — Contain malware spread with segmentation, privilege limits, and rapid isolation routines

34

Episode 27 — Prevent malware execution using layered controls across endpoints and servers

35

Episode 26 — Turn logs into outcomes: alerting strategy, review routines, and noise reduction

36

Episode 25 — Centralize and normalize logs for correlation, retention integrity, and fast search

37

Episode 24 — Decide what to log and why: events that power detection and investigations

38

Episode 23 — Close vulnerabilities with verification evidence, rollback planning, and durable tracking

39

Episode 22 — Prioritize vulnerabilities with risk context, exploitability, and exposure-driven triage

40

Episode 21 — Build continuous vulnerability management: coverage, scan cadence, and owner assignment

41

Episode 20 — Validate access control effectiveness with reviews, testing, and corrective action

42

Episode 19 — Build authorization models that match real work without privilege creep

43

Episode 18 — Strengthen authentication foundations: factors, session controls, and identity assurance

44

Episode 17 — Deprovision accounts cleanly to eliminate orphaned access and lingering entitlements

45

Episode 16 — Provision accounts safely with approvals, role fit, and minimum privilege intent

46

Episode 15 — Clarify account types and lifecycles: user, admin, service, shared, and temporary

47

Episode 14 — Prove configuration compliance with sampling, evidence, and exception governance

48

Episode 13 — Control configuration drift with monitoring, remediation workflows, and change discipline

49

Episode 12 — Design secure configuration baselines that are measurable, repeatable, and realistic

50

Episode 11 — Prevent unapproved execution with allowlisting logic and tightly governed exceptions

51

Episode 10 — Detect unauthorized software quickly using discovery signals, baselines, and change patterns

52

Episode 9 — Establish software asset authority: approved lists, licensing realities, and control points

53

Episode 8 — Validate enterprise asset inventory quality with drift checks and audit-ready evidence

54

Episode 7 — Discover enterprise assets continuously using multiple sources and reconciliation discipline

55

Episode 6 — Define enterprise asset scope: what counts, why it matters, who owns accuracy

56

Episode 5 — Operationalize CIS Controls governance: owners, metrics, reporting, and accountability

57

Episode 4 — Map CIS Controls to major security standards and governance expectations

58

Episode 3 — Understand CIS Controls v8 history, purpose, and how the model is organized

59

Episode 2 — Build an audio-first study plan: recall cycles, review rhythm, and exam-day flow

60

Episode 1 — Decode the GCCC blueprint: domains, scoring, pacing, and what 71% demands