All Projects
GRC / Security Assessment · 01

GRC & Information Security Assessment

Client
Confidential Client
Role
GRC Analyst
Year
2025
Category
GRC / Security Assessment

Overview

A structured assessment of governance, risk and information-security posture, mapping existing controls against organizational risk appetite and identifying gaps ahead of formal certification work.

Key Activities

  • Reviewed governance structures, policies and control ownership
  • Conducted risk identification and impact/likelihood scoring
  • Interviewed control owners across IT, HR and operations
  • Documented findings in a structured gap-assessment report

Outcome

Delivered a prioritized remediation roadmap that gave leadership a clear, evidence-based view of security maturity.

Frameworks & Standards

ISO/IEC 27001NIST CSFInternal risk register