CISSP Cyber Training Podcast - CISSP Training Program
CISSP Cyber Training Podcast - CISSP Training Program
Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur
CCT 362: Security Assessment Strategies & Abandoned Cloud Storage Risks (CISSP 6.1) - REPLAY
34 minutes Posted Jul 20, 2026 at 11:00 am.
Welcome And Podcast Mission
Abandoned S3 Buckets As Attack Vectors
CISSP Domain 6.1 Overview
Building An Assessment Program From Scratch
Security Baselines And Testing Methods
Vulnerability Scans And Pen Testing Types
Assessments And Framework Choices
Audit Process And Evidence Handling
SOC 1 SOC 2 Plus Type 1 Type 2
Audit Standards And Common Challenges
Cyber Resiliency Index And Wrap Up
0:00
34:00
Download MP3
Show notes
Send us Fan Mail That forgotten cloud storage you stopped thinking about months ago can become a real attack path today. We start with a simple but dangerous scenario: abandoned AWS S3 buckets and other orphaned cloud storage that can be re-registered, repurposed, and used to serve malicious content to systems that still “trust” the old source. We walk through why this turns into a supply chain-style problem, what signals to look for, and the practical mitigations that matter most: proper dec...