Lab 2: Running a SCAP Scan Cybersecurity and Compliance Curriculum · 5:01 A hands-on walkthrough of running SCAP security scans using OpenSCAP on Linux virtual machines, teaching listeners how to identify vulnerabilities and apply security benchmarks using the SCAP Security Guide.
Acceptance Is Not Ignorance Cybersecurity and Compliance Curriculum · 3:24 Acceptance Is Not Ignorance dives into one of the most misunderstood concepts in risk management — the deliberate, documented decision to accept a known risk rather than ignore it. Listeners will learn how true risk acceptance requires careful analysis, accountability, and ongoing awareness, not passive neglect.
1 COSO 2013 Internal Control Cybersecurity and Compliance Curriculum · 4:44 Dive into the COSO 2013 Internal Control framework and its three core objectives — reliable reporting, compliance, and operational efficiency — while exploring how the 2017 update expanded the model to include strategic vision and risk appetite.
Poisoned Dependencies Cybersecurity and Compliance Curriculum · 4:19 A deep dive into the dangerous world of software supply chain attacks, where even trusted, widely-used libraries can become weapons when malicious code is secretly embedded by compromised maintainers or bad actors.
When ACE Breaks Down Cybersecurity and Compliance Curriculum · 4:21 Explore the critical limitations of Access Control Entries (ACE) when time-sensitive security requirements come into play, and discover why static rule-based systems struggle to handle dynamic concepts like Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
1 Defining Active-Active Cybersecurity and Compliance Curriculum · 4:14 Dive into the fundamentals of active-active architecture and discover how it differs from active-passive and active-standby models in keeping critical systems resilient and continuously available.
Adaptive Management Principles Cybersecurity and Compliance Curriculum · 3:14 Adaptive management principles come alive through the reality that effective crisis response demands decentralized decision-making and the confidence to act on incomplete information, teaching listeners how to move decisively when 60% certainty is enough to course-correct before conditions worsen.
4 Dual-Environment Workflow Cybersecurity and Compliance Curriculum · 3:15 Explore the architecture of a dual-environment cybersecurity workflow, where open lab environments foster innovation and AI-assisted development while sensitive Controlled Unclassified Information (CUI) and production systems remain protected within secure GovCloud infrastructure.
The Organizational Relationship After Compliance Cybersecurity and Compliance Curriculum · 3:15 Exploring what happens after a compliance audit concludes, this chapter reveals how cybersecurity teams can shift from a position of crisis-driven authority to building lasting, trust-based relationships within their organizations.
Exercise 3: Framework Mapping Cybersecurity and Compliance Curriculum · 3:47 A hands-on exercise in framework mapping walks through how common cybersecurity requirements like access controls, encryption, and multi-factor authentication align across SOC 2, CMMC, HIPAA, and ISO 27001, helping listeners identify overlapping controls and streamline compliance efforts.
IP Licensing Risk Management Cybersecurity and Compliance Curriculum · 4:39 A cautionary deep-dive into the hidden pitfalls of IP licensing agreements, revealing how startups and businesses can fall victim to cross-licensing traps, territorial restrictions, and audit clauses buried in the fine print.