Artwork for Certified: The CISM Audio Course
Education

Certified: The CISM Audio Course

Dr. Jason Edwards

The Bare Metal Cyber CISM Audio Course is your comprehensive, exam-focused audio companion for mastering the Certified Information Security Manager (CISM) certification. Designed to guide aspiring security leaders through all four domains of the CISM exam, this prepcast translates complex risk, governance, and incident response concepts into clear, structured, and easy-to-follow episodes. Whether you're transitioning from a technical role or already managing security programs, the series offers over 70 expertly crafted sessions to reinforce key principles, strengthen exam readiness, and accelerate your journey to certification. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • 72 episodes
  • Updated Oct 14, 2025

Episodes72

  • Jul 6, 2025 · 18 min

    Episode 52: Incident Response Communications: Reporting, Notification, and Escalation

    Incident response is only effective if the right people are informed at the right time. In this episode, we explore how to build a communication plan that includes internal reporting, external notifications, and stakeholder escalation. CISM candidates must understand how to handle communication flow under pressure. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 18 min

    Episode 51: Effective Incident Containment Methods

    Containment is a critical phase in incident response—and a highly tested concept in Domain 4. This episode covers the strategies and decision points for containing incidents, from isolating affected systems to segmenting networks and communicating quickly. Learn how to apply containment while minimizing operational disruption. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 17 min

    Episode 50: Digital Forensics and Evidence Collection Basics

    You don’t have to be a forensic analyst—but you do need to understand the basics. This episode explains how evidence is collected, preserved, and documented during an incident. We also explore the chain of custody, admissibility, and the role of forensic data in investigations—high-value knowledge for the exam. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 18 min

    Episode 49: Incident Investigation Methodologies

    CISM candidates must understand how to manage an incident investigation. This episode covers how to gather evidence, document timelines, identify root causes, and follow structured investigative methods. You’ll learn how to support legal compliance and continuous improvement—all key areas of Domain 4. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 16 min

    Episode 48: Incident Management Tools and Techniques

    Tools can streamline detection, coordination, and resolution during incidents. In this episode, we explore common technologies used in incident management, from SIEM platforms to communication systems. Learn what ISACA wants you to know about selecting, deploying, and using these tools strategically. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 17 min

    Episode 47: Training, Testing, and Evaluating Your Incident Management Capabilities

    Your incident response plan is only as strong as your ability to execute it. This episode covers how to train staff, conduct simulations, and evaluate performance to ensure your organization is prepared for real-world incidents. These lifecycle elements are important for both the exam and maturing your security function. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 16 min

    Episode 46: Incident Classification and Categorization Methods

    Classifying incidents accurately enables proper response. In this episode, we discuss how to build an incident classification system based on impact, type, and severity—key for escalation and prioritization. These concepts are frequently tested in Domain 4 and appear in both technical and business-aligned scenarios. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 20 min

    Episode 45: Testing, Maintenance, and Improvement of Your DRP

    A DRP must be tested, maintained, and improved over time to remain effective. This episode explains how to schedule recovery tests, evaluate outcomes, and implement improvements based on performance data. These lifecycle management concepts show up across multiple CISM domains and often appear in scenario-based questions. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 18 min

    Episode 44: Designing Your Disaster Recovery Plan (DRP)

    Disaster recovery planning ensures technology and data availability during a crisis. In this episode, we break down how to design and document a DRP that complements your BCP and incident response plan. You'll learn key recovery metrics, backup strategies, and restoration procedures—vital for the exam and real-world execution. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 19 min

    Episode 43: Building Your Business Continuity Plan (BCP)

    Business continuity is broader than disaster recovery—and the CISM exam knows it. This episode explains how to build a BCP that supports organizational resilience, continuity of operations, and stakeholder assurance. Learn the difference between continuity and crisis management and how ISACA frames these within Domain 4. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 18 min

    Episode 42: Conducting Business Impact Analysis (BIA

    CISM Domain 4 expects you to know how to conduct a business impact analysis. In this episode, we walk through how to identify critical functions, assess downtime impacts, and define recovery objectives like RTO and RPO. BIA supports planning for continuity, disaster recovery, and incident response—all tested areas on the exam. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 19 min

    Episode 41: Maintaining and Updating Your Incident Response Plan

    An outdated incident response plan is a liability. This episode teaches you how to maintain IR documentation over time, incorporate lessons learned, and update plans to reflect changes in business structure, threat landscape, or regulatory requirements. Expect exam questions that test your ability to keep IR plans relevant and effective. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 19 min

    Episode 40: Designing and Documenting the Incident Response Plan

    Domain 4 begins here. This episode walks you through how to design a comprehensive incident response plan—from defining roles and escalation paths to documenting procedures for detection, containment, and recovery. These are foundational skills for managing security incidents and passing the exam. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 19 min

    Episode 39: Communications and Reporting for the Information Security Program

    Strong security programs communicate effectively. In this episode, we explain how to report program performance, risks, and control status to senior leaders, stakeholders, and technical staff. You’ll learn how to tailor your message and present strategic metrics—skills often tested in scenario-based exam questions. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 20 min

    Episode 38: Contractual Security Requirements and Ongoing Vendor Monitoring

    Once a vendor is onboarded, the work doesn’t stop. This episode covers how to include security clauses in contracts, define SLAs, and monitor vendor compliance over time. We also address continuous assessment techniques and escalation procedures—high-yield content for your exam and real-world leadership. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 19 min

    Episode 37: Vendor Risk Assessment and Selection

    Third-party vendors can expand capabilities—or introduce serious risk. This episode explains how to evaluate vendors before selection by conducting security assessments, verifying compliance, and aligning third-party practices with internal governance. These are must-know processes for Domain 3 and 4 questions. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 18 min

    Episode 36: Developing Engaging Information Security Awareness and Training Programs

    Security programs fail without user participation. This episode explores how to build training and awareness initiatives that promote secure behavior and reinforce governance. You’ll learn how to design, deliver, and evaluate training that supports strategic goals and satisfies exam objectives in Domain 3. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 18 min

    Episode 35: Techniques for Information Security Control Testing and Evaluation

    Testing controls is how you validate effectiveness—and it’s a must-know area for the exam. In this episode, we walk through test design, performance validation, and how to evaluate controls in both technical and organizational contexts. If you’re studying Domain 3, this is essential listening. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 18 min

    Episode 34: Implementing and Integrating Information Security Controls

    CISM candidates must know how to implement controls—not just select them. This episode covers how to plan, deploy, and integrate security controls across the enterprise. You’ll also learn about common integration challenges, stakeholder alignment, and performance tracking. This is a high-impact Domain 3 topic. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.

  • Jul 6, 2025 · 17 min

    Episode 33: Designing and Selecting Effective Information Security Controls

    Controls are at the heart of any security program. This episode shows you how to choose the right controls based on risk assessments, business impact, and regulatory requirements. We also explain how control selection is tested on the exam and how to approach questions with a governance mindset. Ready to start your journey with confidence? Learn more at BareMetalCyber.com.