Skip to main content

Selected GRC Work

Explore the reports, registers, controls, and recommendations behind my portfolio.

Internal Audit

Internal Cybersecurity Audit

An internal assessment that reviewed security controls, documented gaps, and produced a prioritized remediation roadmap.

NIST CSFCIS ControlsISO 27001
View case study

Risk Management

Enterprise Risk Assessment

A risk assessment project documenting assets, threats, likelihood, impact, and treatment options for management review.

CIS RAMNIST CSFISO 27001
View case study

Vendor Risk

Third-Party Risk Assessment

A vendor review workflow covering due diligence, control questions, risk scoring, and onboarding recommendations.

NIST CSFISO 27001CIS Controls
View case study

Incident Response

Incident Response Program Plan

A response planning project defining roles, escalation paths, communications, and post-incident improvement activities.

NIST CSFCIS Controls
View case study

Awareness Training

Cybersecurity Awareness Program

A training and communications plan designed to improve employee security awareness through practical scenarios.

CIS ControlsNIST CSF
View case study

Security Operations Support

Vulnerability Management Review

A governance-focused review of vulnerability intake, prioritization, remediation ownership, and reporting cadence.

CIS ControlsNIST CSF
View case study

Framework Mapping

Cybersecurity Framework Mapping

A mapping exercise connecting control requirements across ISO 27001, NIST CSF, and CIS Controls.

ISO 27001NIST CSFCIS Controls
View case study

Business Continuity

Business Continuity & Disaster Recovery Plan

A continuity planning project focused on critical processes, recovery priorities, roles, and resilience documentation.

ISO 27001NIST CSFBusiness Continuity
View case study