Skip to main content

Enterprise Risk Assessment

A risk assessment project documenting assets, threats, likelihood, impact, and treatment options for management review.

Organization
Cybersecurity Internship Portfolio
Duration
3 weeks
Project Type
Risk Management
CIS RAMNIST CSFISO 27001

Objective

Conduct a structured cybersecurity risk assessment using CIS RAM methodology.

CIS RAMNIST CSFISO 27001

Step-by-Step Execution

  1. Step 1

    Asset Identification

    • Identified relevant data, systems, and business processes.
  2. Step 2

    Threat Identification

    • Documented threats including malware, insider misuse, phishing, and supply chain attacks.
  3. Step 3

    Vulnerability Analysis

    • Reviewed weak controls, outdated systems, and policy gaps.
  4. Step 4

    Risk Scoring

    • Assessed likelihood and impact.
  5. Step 5

    Risk Register Creation

    • Created a structured risk register for review and decision-making.
  6. Step 6

    Risk Treatment Planning

    • Documented treatment options including mitigation, transfer, acceptance, and avoidance.

Deliverables

Risk Management

Risk Register

Documented risks, ratings, owners, treatment options, and review cadence.

Creates a reusable decision record for cybersecurity risk governance.

Executive Reporting

Risk Summary Brief

Management-focused summary of top risks and recommended actions.

Helps stakeholders understand which risks need attention first.

Skills & Insights Gained

Practical CIS RAM applicationBusiness-focused risk assessmentRisk prioritizationDecision-making

Continue exploring

Governance

Governance Policy Development

A structured policy development engagement aligning security expectations with business objectives and recognized frameworks.

ISO 27001NIST CSFCIS Controls
View case study

Internal Audit

Internal Cybersecurity Audit

An internal assessment that reviewed security controls, documented gaps, and produced a prioritized remediation roadmap.

NIST CSFCIS ControlsISO 27001
View case study

Vendor Risk

Third-Party Risk Assessment

A vendor review workflow covering due diligence, control questions, risk scoring, and onboarding recommendations.

NIST CSFISO 27001CIS Controls
View case study