01 / Brief
Translate gaps into decisions.
Security gaps matter most when they are connected to business impact. This project practiced turning technical findings into risk language leadership can prioritize.
02 / Assessment path
From environment review to remediation guidance.
- 01Identifysecurity gaps, vulnerabilities, compliance risks
- 02Connecttechnical condition to business impact
- 03Prioritizequalitative likelihood and impact
- 04Recommendpractical remediation and ownership
- 05Documentgovernance and risk-management artifact
03 / Executive finding
Access review is the priority signal.
04 / Control relationships
One finding, several organizing lenses.
These relationships are thematic assessment lenses, not claims of legal compliance or mappings to specific clauses.
CIS Controls
Account management
Access control management
Audit log management
NIST CSF
Identify assets and risk
Protect access
Detect anomalous activity
Improve response planning
Compliance lens
HIPAA, FERPA, and PCI DSS concepts around sensitive data, access, and documentation
05 / Framework use
Structure the conversation. Keep the finding concrete.
The work connects with client-ready deliverables built during Tate’s MSP internship, including scored findings, maturity-assessment language, and remediation guidance.
06 / Capabilities
Four connected forms of judgment.
- Risk assessment
- Frame the condition and its likely consequence.
- Compliance mapping
- Use established lenses to organize concerns.
- Security documentation
- Make the evidence readable to another audience.
- Remediation planning
- Name a practical next action and owner.
07 / Sample risk register
Qualitative priority, shown in context.
| Impact ↓ / Likelihood → | Low | Medium | High |
|---|---|---|---|
| High | — | R-01Stale or excessive access | — |
| Medium | — | — | — |
| Low | — | — | — |
- Risk
- Stale or excessive user access
- Likelihood
- Medium
- Impact
- High
- Priority
- High
- Recommended action
- Run quarterly access reviews, remove stale accounts, document owners, and validate privileged roles.
08 / Reflection
A good GRC artifact should explain why a problem matters, how likely it is, what it could cost the organization, and what should be done next.
The value is not the list of problems. It is the path from evidence to a decision.