Skip to content

Latest commit

 

History

14 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

Governance, Risk, and Compliance Portfolio

Published: 2025-02-21 | Updated: 2025-10-06

Objective

This repository serves as a resource for exploring Governance, Risk, and Compliance (GRC) through practical tools, educational materials, and real-world applications. It includes risk assessment templates, policy frameworks, and tutorials aimed at enhancing understanding and implementation of GRC concepts. The goal is to provide a hands-on learning experience for professionals and students while showcasing practical solutions to navigate complex regulatory environments and strengthen organizational governance.

Skills Learned

  • Governance:

    • Development and implementation of corporate policies and procedures
    • Establishing governance frameworks and structures
    • Board and executive reporting on governance metrics
    • Ethical decision-making and corporate responsibility
  • Risk Management:

    • Risk identification, assessment, and mitigation techniques
    • Creation and maintenance of risk registers
    • Quantitative and qualitative risk analysis
    • Business Continuity Planning (BCP) and Disaster Recovery (DR)
    • Vendor and third-party risk management
  • Compliance:

    • Understanding and applying regulatory requirements (e.g., PCI-DSS, GDPR, HIPAA, SOX)
    • Conducting compliance audits and assessments
    • Developing compliance training programs
    • Regulatory reporting and documentation
    • Continuous compliance monitoring and enforcement
  • Information Security and Privacy:

    • Data privacy risk assessments
    • Security policy development and enforcement
    • Incident response planning and execution
    • Cybersecurity governance and risk frameworks (e.g., NIST, ISO 27001)
  • Tools and Technologies:

    • GRC platforms (e.g., RSA Archer, BitSight, etc.)
    • Compliance management software
    • Risk assessment and visualization tools
    • Automation tools for compliance reporting
  • Communication and Collaboration:

    • Stakeholder engagement and reporting
    • Cross-functional team collaboration
    • Preparing and presenting audit findings and risk reports
    • Training and awareness programs for GRC practices

Tools Used

  • Microsoft Word
  • Microsoft Excel
  • Microsoft PowerPoint
  • Microsoft Visio
  • Power BI
  • BitSight

Blog

Blog Post Description
Quantitative and Qualitative Risk Assessment: Cheatsheet A guide for professionals and students who would like to understand the use and implementation of Quantitative and Qualitative risk assessment approaches. Includes use cases, formulas, and resources.
Understanding Risk Management, Risk Assessment, and Risk Treatment in Cybersecurity Why Risk Management, Risk Assessment, and Risk Treatment in Cybersecurity are important concepts to understand and how to approach risk management - includes a sample risk matrix.
Cybersecurity Fundamentals: A Short Guide A short introduction to the importance of cybersecurity, risks in the enviroment, and countermeasures to close the gap.
Understanding Business Impact Analysis (BIA), Business Continuity Planning (BCP), and Disaster Recovery (DR) A blog post detailing the importance and implementation of BIA, BCP, and DR for information technology systems.

Projects

Project Name Description
Conducting a basic audit of an AWS environment An audit using multiple AWS services: EC2, VPC, IAM, CloudTrail, and CloudWatch.

© 2025-2026 Brock Frary. All rights reserved.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors