Skip to main content
Should Podcasts Be on Your CPE Plan?Risk Assessment & Treatment
4 min readFor Information Security Officers

Should Podcasts Be on Your CPE Plan?

Compliance professionals face a recurring problem: frameworks evolve, new threats emerge weekly, and your certification body expects you to document continuing professional education (CPE) hours while you're managing three audits and a gap assessment. You need to stay current, but reading another 47-page NIST publication at 9 PM isn't sustainable.

Audio learning has become a legitimate professional development channel. The ISACA Podcast alone has logged 599.9K downloads across 319 episodes, suggesting practitioners are already integrating this format into their routines. The question isn't whether podcasts are useful, it's whether you're using them strategically enough to count as structured learning.

This checklist helps you evaluate and integrate podcast-based learning into your compliance development plan without compromising the rigor your role demands.

Prerequisites

Before you start tracking podcast hours as professional development:

  • Verify your certification body's CPE requirements. ISACA, (ISC)², and IAPP have different rules about self-directed learning. Know what qualifies before you commit time.
  • Identify your knowledge gaps. Review your last audit findings, upcoming framework changes like ISO/IEC 27001:2022 control restructuring, or areas where your team struggled. Your listening plan should target these gaps.
  • Set up a tracking system. CPE audits require documentation. Whether it's a spreadsheet or a dedicated app, you need to log episode titles, dates, durations, and key takeaways before you listen.

Checklist Items

1. Choose podcasts with verifiable subject matter expertise.

Review the host credentials and guest backgrounds. Are they practicing auditors, certification body members, or framework contributors? Can you verify their claims against published standards?

Good looks like: The host is a Lead Auditor for ISO/IEC 27001 or holds a CISA/CISM, and guests include people who've authored guidance documents or sit on technical committees.

2. Map episodes to specific framework requirements.

Don't just listen passively. Before each episode, identify which controls, clauses, or risk domains it addresses. For example, an episode on vendor security maps to ISO/IEC 27001 Clause 5.19 (Information Security in Supplier Relationships) and SOC 2 CC9 (Vendor Management).

Good looks like: Your CPE log shows "Episode: Third-Party Risk" → "ISO/IEC 27001 Clause 5.19, SOC 2 CC9.2" → "45 minutes" → "Key takeaway: contract language for subprocessor notification."

3. Cross-reference claims against primary sources.

Podcasts move fast. If a host claims "the new NIST framework requires X," pause and verify against the actual publication. Audio formats don't include citations the way written guidance does.

Good looks like: You hear a claim about ISO/IEC 27001:2022 Annex A changes, you pull up the standard, confirm the control number and description, then note any discrepancies in your log.

4. Document actionable changes to your control environment.

Professional development only matters if it changes your practice. After each episode, write one specific action: a control you'll update, a risk you'll reassess, or a procedure you'll revise.

Good looks like: "Episode on access review automation → Action: Evaluate our quarterly review process against ISO/IEC 27001 Clause 5.18 → Due: before Q2 review cycle."

5. Balance informal learning with structured training.

Podcasts complement certification courses and framework training; they don't replace them. If you're pursuing ISO/IEC 27001 Lead Auditor certification, you still need the accredited course. Use podcasts to maintain currency between formal training cycles.

Good looks like: Your annual CPE plan shows 20 hours of accredited training, 15 hours of conference sessions, and 10 hours of documented podcast learning, not 45 hours of podcasts alone.

6. Validate episode content against your auditor's interpretation.

Frameworks leave room for interpretation. Your external auditor might disagree with a podcast host's reading of a control. When you hear guidance that contradicts your audit experience, flag it and discuss with your assessor during the next planning call.

Good looks like: You note "Podcast suggested quarterly penetration testing satisfies ISO/IEC 27001 Clause 8.8; our auditor requires annual plus targeted tests post-change. Confirmed our approach remains compliant."

7. Use episodes to prepare for audit conversations.

Auditors ask why you made specific risk treatment decisions. Podcasts that explore real-world control trade-offs help you articulate your rationale. Listen for how experienced practitioners justify their choices.

Good looks like: During your SOC 2 readiness review, you explain your encryption approach by referencing the same risk-based logic you heard in an episode on FIPS-Validated Cryptography implementation, demonstrating you've considered industry perspectives.

Common Mistakes

Treating podcasts as background noise. If you're half-listening while doing email, you're not retaining enough to claim CPE hours. Active listening means taking notes and pausing to verify claims.

Skipping the documentation step. Your certification body might audit your CPE log. "I listened to some podcasts about ISO/IEC 27001" won't pass. You need episode titles, dates, durations, and learning outcomes.

Ignoring the lag between recording and release. A podcast recorded six months ago might reference outdated guidance. Always check publication dates and verify current requirements.

Confusing familiarity with competence. Hearing about a control doesn't mean you can implement it. Use podcasts to identify what you need to learn formally, not as a substitute for hands-on practice or accredited training.

Next Steps

Start with one episode per week mapped to a current gap in your program. Log it immediately after listening. After four weeks, review your notes and identify one control improvement you can implement. If you can't point to a specific change in your ISMS or control environment, the time doesn't qualify as professional development, it's just consumption.

Your CPE plan should show intentionality. Podcasts work when they're part of a structured learning strategy that includes reading primary sources, attending formal training, and applying what you learn to your actual control environment. The format is legitimate; the discipline is on you.

You Might Also Like