HomePortfolio
Portfolio · Applied GRC Work

Cybersecurity GRC

Eight applied portfolio projects spanning ISMS design, AI governance, LLM threat modelling, NIST CSF maturity assessment, third-party and AI vendor risk, and infrastructure-as-code governance. Each document is built against named frameworks and structured for executive, engineering, and audit audiences. Every project is tagged with the phase of GRC it evidences.

8
Portfolio Projects
84
Total Pages
11
Frameworks Applied
Filter by Framework
01
ISMS · ISO 27001Learn · Align

ISO/IEC 27001:2022 Risk Assessment and Statement of Applicability

Portfolio Project 1 of 8 · 17 pages · July 2026

A complete, audit-ready ISO/IEC 27001:2022 risk assessment and Statement of Applicability for Stark Industries Inc., a fictional SaaS marketing platform hosted on AWS. Covers Clauses 6.1.2 and 6.1.3 in full: five-asset inventory with CIA ratings, five risk scenarios scored on a 5×5 likelihood-impact scale, a risk treatment plan with selected Annex A controls, and a full 93-control SoA with applicability justifications and exclusion rationale. Residual risk is scored post-treatment and presented for management sign-off.

Key Deliverables
  • Five-asset ISMS scope with CIA classification (source code, AWS EC2, CI/CD, endpoint, data)
  • Risk register: 5 scenarios scored L×I — 3 High, 2 Medium
  • Risk treatment plan with Annex A control mapping per risk
  • Full 93-control Statement of Applicability: 65 applicable, 28 excluded with justification
PDF Document
17 pages
02
AI Governance · GRCAlign

AI Governance Program Blueprint

Portfolio Project 2 of 8 · 8 pages · July 2026

A complete AI governance blueprint for a composite energy-sector enterprise. Covers governance structure and RACI accountability, a standards crosswalk across NIST AI RMF, ISO/IEC 42001, and the EU AI Act, a ten-entry scored risk register, and a four-quarter phased implementation roadmap. Demonstrates how named frameworks translate into an operating committee, a control set, and a risk register a real organization could adopt.

Key Deliverables
  • RACI matrix for AI Governance Committee
  • Standards crosswalk: NIST AI RMF × ISO/IEC 42001 × EU AI Act
  • Scored AI risk register (10 entries, 5-point L × I scale)
  • Phased rollout roadmap with AI incident runbook
PDF Document
8 pages
03
Threat Modeling · AI SecurityLearn

LLM Threat Model and Security Assessment

Portfolio Project 3 of 8 · 7 pages · July 2026

A threat model for a specific, named LLM-based customer support copilot deployed by a composite utility enterprise. Applies a four-pillar taxonomy mapped to OWASP LLM Top 10 2025 and MITRE ATLAS. Includes a scored risk register, an adversarial test case plan for the four highest-scoring threats, and a detection and monitoring plan with five detection patterns — each mapped to an ATLAS technique and a named response owner.

Key Deliverables
  • Four-pillar threat taxonomy (Model, Data, Agency, Supply Chain)
  • Risk register: 8 threats scored on 5-point L × I scale
  • Adversarial test case plan for T-01 through T-05
  • Detection plan: 5 patterns mapped to MITRE ATLAS
PDF Document
7 pages
05
Maturity Assessment · NIST CSFReview

NIST CSF Maturity Assessment and Three-Year Remediation Roadmap

Portfolio Project 5 of 8 · 15 pages · July 2026

A full 98-subcategory NIST Cybersecurity Framework maturity assessment for Oscorp, a fictional organization, based on structured stakeholder interviews across IT, cybersecurity, risk, and procurement. Oscorp passed 26 of 98 controls (27% overall). The Respond function scored 0% — the most urgent finding in the assessment. The report closes with a sequenced three-year remediation roadmap: foundational governance and access control in Year 1, detection and response capability plus TPRM in Year 2, and quantified risk management in Year 3.

Key Deliverables
  • Full 98-subcategory assessment across Identify, Protect, Detect, Respond, Recover
  • Per-function compliance: Identify 17%, Protect 46%, Detect 17%, Respond 0%, Recover 50%
  • Supplementary TPRM finding: key SaaS supplier Horizon Labs never assessed
  • Three-year sequenced remediation roadmap with Year 1/2/3 priority actions
PDF Document
15 pages
06
Third-Party Risk · TPRMAlign

TPRM Program Design and Tiered Supplier Risk Assessment

Portfolio Project 6 of 8 · 13 pages · July 2026

A complete third-party risk management (TPRM) program design for Stark Industries Inc., applied to its most critical supplier, Amazon Web Services. The program follows a four-step process: supplier inventory, three-tier risk classification, tiered questionnaire assessment with evidence review, and signed management report. The worked AWS assessment is built from AWS's own publicly published compliance documentation — Shared Responsibility Model, ISO/IEC 27001 certificates, and SOC 2 Type II attestations — and identifies two residual actions that belong to Stark Industries rather than AWS.

Key Deliverables
  • Three-tier supplier classification model (Tier 1/2/3 by criticality and data sensitivity)
  • Questionnaire design methodology: NIST CSF + ISO 27001 Annex A 5.19–5.23 + GDPR/DORA
  • Full Tier 1 worked assessment: AWS as Stark Industries' cloud infrastructure supplier
  • Two residual findings: shared-responsibility boundary documentation and encryption configuration
PDF Document
13 pages
04
Vendor Risk · Third-Party GRCPerform

Third-Party AI Vendor Risk Due Diligence Toolkit

Portfolio Project 4 of 8 · 7 pages · July 2026

A reusable AI-specific vendor due diligence toolkit that extends standard third-party risk management practice. Includes a six-domain questionnaire covering data handling, model provenance, security controls, certifications, incident history, and contractual terms. Features a weighted scoring rubric with a three-tier risk decision (Green / Yellow / Red), a complete worked example against a fictional vendor, and recommended contract clauses for procurement and legal.

Key Deliverables
  • Six-domain due diligence questionnaire (AI-specific supplement)
  • Weighted scoring rubric: Green / Yellow / Red risk tiers
  • Worked example: Cascade AI Concierge (fictional vendor, score 3.7 / Yellow)
  • Recommended contract clauses for data processing, model change, and audit rights
PDF Document
7 pages
07
ISMS Build · Google Workspace SecurityAlign

ISMS Build for a Physical Security Firm: Rockops Protection Agency

Portfolio Project 7 of 7 · Two-Part Series · 18 pages · July 2026

A complete, end-to-end ISMS build for Rockops Protection Agency, a fictional 125-person physical security and executive protection firm. Part A establishes the governance layer — ISMS scope, information security policy, RACI accountability matrix, a ten-entry risk register scored on a 5×5 likelihood-impact scale, and a full 93-control Statement of Applicability — with a documented judgment call on Google Workspace edition selection. Part B translates every Technological control named in Part A's SoA into a specific, sequenced configuration of the Google Admin console: OU structure, BYOD endpoint management for field agents, Gmail hardening (SPF/DKIM/DMARC), Drive sharing controls, audit alerts, Vault retention, and a one-hour offboarding runbook. Together the two documents demonstrate the full governance-to-implementation chain ISO/IEC 27001 requires.

Key Deliverables
  • Part A: ISMS scope, policy, RACI, 10-risk register, full 93-control SoA (ISO/IEC 27001:2022 Clauses 6.1.2–6.1.3)
  • Part B: Google Workspace Admin console runbook — OU structure, BYOD management, Gmail/Drive hardening, Vault retention
  • BYOD risk addressed for 85 field agents: work-profile separation, selective wipe, OS-version enforcement
  • Offboarding runbook: full de-provisioning target within one hour of a for-cause termination notice
IaC GovernanceReview

How Humans Break Terraform Deployments: A Cautionary Tale

Project 08 of 8 · 9 pages · July 2026

A practitioner-focused analysis of the ten most common human failure patterns in Terraform-managed AWS environments, written as a control-gap analysis for GRC professionals and an operational checklist for engineers. Each failure — state file deletion, drift from manual console changes, hardcoded secrets, variable mistakes, accidental destruction, permission failures, backend misconfiguration, circular dependencies, concurrent modification, and version drift — is examined through three lenses: cause, effect, and fix. The document bridges the gap between IaC tooling and governance, mapping each failure to a specific control category: data integrity, change management, access control, segregation of duties, business continuity, least privilege, configuration management, and release management.

Key Deliverables
  • Ten failure patterns mapped to GRC control categories (NIST CSF, CIS Controls)
  • State protection: versioning, locking, and recovery procedures for S3-backed Terraform backends
  • Drift prevention: IAM write-restriction, AWS Config monitoring, and pull-request pipeline enforcement
  • Secret management: pre-commit scanning, short-lived IAM roles, and credential rotation procedures
  • Destruction safeguards: lifecycle prevent_destroy, SCPs, and backup-dependent recovery planning
PDF Document
9 pages
Related Reading
Critical InfrastructureJuly 22, 2026 · 14 min read

TSI/EN 50600: The European Standard Quietly Reshaping How Data Centres Are Built, Secured, and Judged

EN 50600 availability and protection classes, TÜViT TSI certification, and the intersection with NIS2 and the CER Directive. Covers what physical security professionals and GRC practitioners need to verify before the regulatory deadline.

Business ContinuityJuly 22, 2026 · 9 min read

When the Lights Go Out: What ISO 22301 Actually Does for Your Business

ISO 22301 business continuity management explained for leaders: BIA-driven recovery targets, practical strategies, and why certification matters for procurement and regulatory readiness.

GRC Advisory

Need AI governance or GRC implementation support?

These projects demonstrate the methodology. The engagement delivers the outcome. Contact to discuss how this work applies to your organization.