Domain

GRC & Risk

Turning frameworks into control decisions somebody can actually defend in an audit.

Governance gets written off as paperwork until an auditor asks a question nobody can answer. The work here is about making controls concrete: what the framework asks for, what's actually in place, and what closing the gap costs.

I've written up CMMC 2.0 and the NIST AI RMF so far.

At work and school: a gap analysis of 58 controls against NIST 800-53 at the McKeever MIS Lab, and a 3-tier access exception framework at Sunflower Bank handling 40+ tickets a week. Frameworks: NIST 800-53, CSF 2.0, AI RMF, CMMC 2.0, SOC 2, MITRE ATT&CK. Certified OCEG IAIP.
Roadmap

What's next

Listed before it exists so you can tell the difference.

Cloud control mapping

The Azure series mapped against NIST CSF 2.0, showing which controls each build actually satisfies.

GRC & Risk Planned
Risk register in practice

A working register with likelihood and impact that leads to a decision instead of a colour-coded grid.

GRC & Risk Planned
Gap analysis walkthrough

A generalized version of how I scored 58 controls, what counted as evidence, and how remediation got prioritized.

GRC & Risk Planned