05 · Selected Work

Enterprise Risk Assessment & Risk Register

Risk Management ISO 27005 GRC

Developed a comprehensive information security risk assessment by identifying assets, threats, vulnerabilities, existing controls, and treatment options using an ISO 27005-based methodology.

Role
Risk Analyst
Environment
Simulated Organization
Framework Mapping
ISO 27005
Overview

Effective security begins with understanding organizational risk. This project focused on building a structured risk management process that converts technical concerns into measurable business risks.

Objectives
Tools & Stack
Process

Catalogued assets, identified threats, evaluated vulnerabilities, calculated risk ratings, proposed mitigation plans, and tracked residual risk after treatment.

Findings & Deliverables
Outcome & Reflection

This project strengthened my ability to translate technical weaknesses into business risks while improving my understanding of risk prioritization and governance reporting.

Selected Work