<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet href="https://rss.buzzsprout.com/styles.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:psc="http://podlove.org/simple-chapters" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <atom:link href="https://rss.buzzsprout.com/2611440.rss" rel="self" type="application/rss+xml" />
  <atom:link href="https://pubsubhubbub.appspot.com/" rel="hub" xmlns="http://www.w3.org/2005/Atom" />
  <title>The Digital Risk Brief</title>

  <lastBuildDate>Sat, 18 Apr 2026 01:05:09 -0400</lastBuildDate>
    <language>en-us</language>
  <copyright>© 2026 The Digital Risk Brief</copyright>
  <podcast:locked>yes</podcast:locked>
    <podcast:guid>eb1848e4-b91a-5097-96b8-5a10938cc4f8</podcast:guid>
  <itunes:author>Emmanuel</itunes:author>
  <itunes:type>episodic</itunes:type>
  <itunes:explicit>false</itunes:explicit>
  <description><![CDATA[<p>&nbsp;A podcast that talks about cybersecurity, AI, and digital risk in simple, useful ways. It breaks down new threats, data privacy, and technology trends.&nbsp;</p>]]></description>
  <generator>Buzzsprout (https://www.buzzsprout.com)</generator>
  <itunes:owner>
    <itunes:name>Emmanuel</itunes:name>
  </itunes:owner>
  <item>
    <itunes:title>Mastering the Maze: A Deep Dive into SOC 2, PCI DSS 4.0, and Audit Readiness</itunes:title>
    <title>Mastering the Maze: A Deep Dive into SOC 2, PCI DSS 4.0, and Audit Readiness</title>
    <itunes:summary><![CDATA[ This episode provides a deep dive into information security compliance, focusing on real-world auditing practices and key regulatory frameworks. It explains SOC reporting fundamentals, including the difference between SOC 1 and SOC 2 and how Type 1 assesses control design at a point in time while Type 2 evaluates operating effectiveness over a defined period. It also breaks down the five SOC 2 Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Pr...]]></itunes:summary>
    <description><![CDATA[<p> This episode provides a deep dive into information security compliance, focusing on real-world auditing practices and key regulatory frameworks. It explains SOC reporting fundamentals, including the difference between SOC 1 and SOC 2 and how Type 1 assesses control design at a point in time while Type 2 evaluates operating effectiveness over a defined period. It also breaks down the five SOC 2 Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy, and explores the shared responsibility model, highlighting how organizations must implement internal controls such as access management, change control, and log monitoring even when using cloud providers. Additionally, it covers PCI DSS 4.0 requirements for protecting cardholder data and explains merchant levels based on transaction volume. The discussion further illustrates audit procedures, including how exceptions are identified and addressed through remediation efforts using practical analogies to distinguish between control design and testing effectiveness, with the overall goal of helping professionals better understand compliance frameworks for audits and career readiness. </p>]]></description>
    <content:encoded><![CDATA[<p> This episode provides a deep dive into information security compliance, focusing on real-world auditing practices and key regulatory frameworks. It explains SOC reporting fundamentals, including the difference between SOC 1 and SOC 2 and how Type 1 assesses control design at a point in time while Type 2 evaluates operating effectiveness over a defined period. It also breaks down the five SOC 2 Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy, and explores the shared responsibility model, highlighting how organizations must implement internal controls such as access management, change control, and log monitoring even when using cloud providers. Additionally, it covers PCI DSS 4.0 requirements for protecting cardholder data and explains merchant levels based on transaction volume. The discussion further illustrates audit procedures, including how exceptions are identified and addressed through remediation efforts using practical analogies to distinguish between control design and testing effectiveness, with the overall goal of helping professionals better understand compliance frameworks for audits and career readiness. </p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2611440/episodes/19035226-mastering-the-maze-a-deep-dive-into-soc-2-pci-dss-4-0-and-audit-readiness.mp3" length="24639695" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/2bg4v0sfr532pacevp6qzpkpr51h?.jpg" />
    <itunes:author>Emmanuel</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19035226</guid>
    <pubDate>Sat, 18 Apr 2026 01:00:00 -0400</pubDate>
    <itunes:duration>2050</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
</channel>
</rss>
