← Case index

CASE./003

Governance, risk, compliance

GRC Risk Assessment

A simulated business assessment that connects security gaps to business impact, control ownership, and practical remediation.

Environment
Simulated business
Assessment
Qualitative
Focus
Identity, sensitive data, documentation
Output
Risk register + remediation guidance

Translate gaps into decisions.

Assessment principle

Security gaps matter most when they are connected to business impact. This project practiced turning technical findings into risk language leadership can prioritize.

From environment review to remediation guidance.

  1. 01Identifysecurity gaps, vulnerabilities, compliance risks
  2. 02Connecttechnical condition to business impact
  3. 03Prioritizequalitative likelihood and impact
  4. 04Recommendpractical remediation and ownership
  5. 05Documentgovernance and risk-management artifact
The simulated assessment connects evidence, exposure, priority, and action without treating framework references as a substitute for judgment.

Access review is the priority signal.

FindingInconsistent access review, weak documentation, limited evidence of control ownership
Business exposureRegulated information, audit readiness, incident response speed
Recommended sequenceReduce identity and data-handling risk first

One finding, several organizing lenses.

These relationships are thematic assessment lenses, not claims of legal compliance or mappings to specific clauses.

Structure the conversation. Keep the finding concrete.

Practice connection

The work connects with client-ready deliverables built during Tate’s MSP internship, including scored findings, maturity-assessment language, and remediation guidance.

Four connected forms of judgment.

Risk assessment
Frame the condition and its likely consequence.
Compliance mapping
Use established lenses to organize concerns.
Security documentation
Make the evidence readable to another audience.
Remediation planning
Name a practical next action and owner.

Qualitative priority, shown in context.

Illustrative qualitative placement for the single sample risk. No numerical score is assigned.
Impact ↓ / Likelihood →LowMediumHigh
High—R-01Stale or excessive access—
Medium———
Low———
Risk
Stale or excessive user access
Likelihood
Medium
Impact
High
Priority
High
Recommended action
Run quarterly access reviews, remove stale accounts, document owners, and validate privileged roles.
A good GRC artifact should explain why a problem matters, how likely it is, what it could cost the organization, and what should be done next.

The value is not the list of problems. It is the path from evidence to a decision.