That forgotten cloud storage you stopped thinking about months ago can become a real attack path today. We start with a simple but dangerous scenario: abandoned AWS S3 buckets and other orphaned cloud storage that can be re-registered, repurposed, and used to serve malicious content to systems that still “trust” the old source. We walk through why this turns into a supply chain-style problem, what signals to look for, and the practical mitigations that matter most: proper decommissioning, continuous monitoring, tight access control, and disciplined cloud asset inventories.
From there, we shift into CISSP Domain 6.1 and the real work of designing and validating assessment, test, and audit strategies. We explain how we approach building a security assessment and testing program from the ground up: clear objectives, tight scope, risk-based prioritisation, stakeholder alignment, and baselines grounded in frameworks like NIST CSF, ISO 27001, CIS Benchmarks, and NIST SP 800-53. The aim is simple: identify vulnerabilities, validate security controls, and turn findings into remediation that leadership can act on.
We also break down core security testing methods you will see on the CISSP and in real organisations: vulnerability assessment, penetration testing (white box, black box, gray box), fuzz testing, SAST and DAST for application security, plus red team, blue team, and purple team collaboration. Finally, we demystify SOC 1 vs SOC 2 and Type 1 vs Type 2 reports, why they matter for third-party risk management, and how cyber resilience thinking (including the Cyber Resiliency Index) ties everything back to continuity and trust. If this helps, subscribe, share the show with a colleague studying CISSP, and leave a review with the topic you want next.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Podden och tillhörande omslagsbild på den här sidan tillhör
Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur. Innehållet i podden är skapat av Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur och inte av,
eller tillsammans med, Poddtoppen.