GRC / Security Assessment · 01
GRC & Information Security Assessment
- Client
- Confidential Client
- Role
- GRC Analyst
- Year
- 2025
- Category
- GRC / Security Assessment
Overview
A structured assessment of governance, risk and information-security posture, mapping existing controls against organizational risk appetite and identifying gaps ahead of formal certification work.
Key Activities
- Reviewed governance structures, policies and control ownership
- Conducted risk identification and impact/likelihood scoring
- Interviewed control owners across IT, HR and operations
- Documented findings in a structured gap-assessment report
Outcome
Delivered a prioritized remediation roadmap that gave leadership a clear, evidence-based view of security maturity.
Frameworks & Standards
ISO/IEC 27001NIST CSFInternal risk register