1 Defense in Depth Compliance and Security Frameworks · 3:32 Exploring the foundational cybersecurity strategy of Defense in Depth, this chapter breaks down how layering administrative, technical, and physical controls creates a far more resilient security posture than relying on any single line of defense.
2 Separation of Duties Compliance and Security Frameworks · 3:44 A deep dive into the critical security principle of Separation of Duties, exploring how concentrating too much control in one person creates dangerous vulnerabilities and opportunities for fraud within business processes.
3 Least Privilege Compliance and Security Frameworks · 3:39 Exploring the principle of least privilege through the story of an accounting employee with overly broad system access, this chapter teaches why users should only have access to the specific resources required for their role — and the security risks that arise when that boundary isn't enforced.
4 Fail-Safe Defaults Compliance and Security Frameworks · 4:10 Exploring the principle of "default deny" in system security, this song teaches listeners how to build safer systems by starting with zero access and deliberately granting only what's necessary.
5 Accountability Compliance and Security Frameworks · 3:36 Accountability in digital environments takes center stage as listeners learn why individual ownership of actions—from unique logins to personal credentials—is essential for maintaining traceable, auditable security practices.
6 Proportionality Compliance and Security Frameworks · 3:07 Exploring the principle of proportionality in data security, this track breaks down how protection measures should be scaled to match the actual sensitivity and value of the data being secured — saving resources while keeping what matters most safe.
1 SOC 2 Trust Services Criteria Compliance and Security Frameworks · 3:38 A deep dive into SOC 2's five Trust Services Criteria, exploring how security, availability, processing integrity, confidentiality, and privacy form the foundation of enterprise compliance and control design.
2 CMMC (Cybersecurity Maturity Model Certification) Compliance and Security Frameworks · 3:39 Dive into the structure of the Cybersecurity Maturity Model Certification (CMMC), breaking down its 14 domains, three maturity levels, and 110 practices drawn from NIST 800-171 that defense contractors must implement to achieve compliance.
3 HIPAA Security Rule Compliance and Security Frameworks · 4:06 Diving into the HIPAA Security Rule, this chapter breaks down the three core safeguard categories — Administrative, Physical, and Technical — and clarifies the critical distinction between required and addressable implementation standards for protecting patient data.
5 NIST SP 800-53 Compliance and Security Frameworks · 4:57 Dive into the world of NIST SP 800-53 and its twenty families of security controls, from Access Control to Supply Chain Risk Management. You'll learn how controls are organized, numbered, and applied across Low, Moderate, and High security baselines to match your organization's needs.
6 PIPEDA and Canadian Privacy Requirements Compliance and Security Frameworks · 3:49 Dive into Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and discover how its ten fair information principles — from accountability to consent — shape the way organizations must handle personal data.
1 NIST 800-171 and CMMC Level 2 Compliance and Security Frameworks · 3:36 Dive into the foundational requirements of NIST 800-171 and CMMC Level 2, exploring the 110 security controls of revision two, the upcoming changes in revision three, and how organizations can choose between self-assessment or third-party certification pathways.
2 CPCSC (Canadian Program for Cyber Security Certification) Compliance and Security Frameworks · 3:32 Dive into Canada's CPCSC framework, exploring how Level Two certification aligns with America's CMMC to create a unified North American defense contractor compliance standard built on NIST foundations with Canadian sovereignty in mind.
3 STIG Hardening Compliance and Security Frameworks · 3:40 Dive into the world of Security Technical Implementation Guides (STIGs) and discover how severity categories — CAT One, Two, and Three — help prioritize and remediate security findings to keep systems locked down and compliant.
4 FIPS 140-2/140-3 Cryptography Compliance and Security Frameworks · 5:48 Dive into the world of FIPS 140-2 and 140-3 cryptographic standards, uncovering the critical distinction between simply complying with security specifications and achieving full validation through certified modules that meet the government's most rigorous testing requirements.
5 FedRAMP and Cloud Authorization Compliance and Security Frameworks · 4:04 Dive into FedRAMP, the federal government's cloud security authorization framework, and learn how its Low, Moderate, and High impact levels determine compliance requirements for government systems, including how the DoD aligns its own security tiers with this essential standard.
6 Container Supply Chain Security Compliance and Security Frameworks · 5:04 Diving deep into container supply chain security, this chapter explores how to source and build trustworthy container images, from leveraging hardened repositories like Iron Bank to establishing secure custom build practices that keep your deployments battle-ready.
1 System Security Plan (SSP) Compliance and Security Frameworks · 3:19 A deep dive into the System Security Plan (SSP), covering how to document system purpose, define boundaries, and establish authorization controls as the foundation of any solid compliance framework.
4 Risk Management Compliance and Security Frameworks · 3:27 Dive into the essentials of risk management, where you'll learn how to identify hidden threats, build a risk register, and use likelihood-impact grids to assess and mitigate dangers before they derail your projects.
3 Continuous Monitoring and Continuous ATO Compliance and Security Frameworks · 3:59 Continuous monitoring and Continuous ATO (Authorization to Operate) revolutionize how organizations maintain security compliance, replacing lengthy traditional approval cycles with automated, real-time validation that integrates seamlessly into DevSecOps pipelines.
Regulatory Context (Common) Compliance and Security Frameworks · 2:58 Covering six essential compliance frameworks including SOC 2, HIPAA, and CMMC, this track breaks down the regulatory landscape that software and security professionals must navigate to keep systems protected and audit-ready.
Standard-Setting Bodies and Process Compliance and Security Frameworks · 3:59 Explore the key organizations that shape financial reporting standards, including IASB, FASB, and IOSCO, and learn how each body plays a distinct role in creating the rules that govern how companies document and disclose their financial information.
Policies Compliance and Security Frameworks · 3:29 Diving into the foundational role of workplace policies, this track explores how a Code of Conduct and clear behavioral expectations help organizations protect their interests and guide employees from day one.