Cloud control mapping
The Azure series mapped against NIST CSF 2.0, showing which controls each build actually satisfies.
GRC & Risk
Planned
Turning frameworks into control decisions somebody can actually defend in an audit.
Governance gets written off as paperwork until an auditor asks a question nobody can answer. The work here is about making controls concrete: what the framework asks for, what's actually in place, and what closing the gap costs.
I've written up CMMC 2.0 and the NIST AI RMF so far.
Listed before it exists so you can tell the difference.
The Azure series mapped against NIST CSF 2.0, showing which controls each build actually satisfies.
A working register with likelihood and impact that leads to a decision instead of a colour-coded grid.
A generalized version of how I scored 58 controls, what counted as evidence, and how remediation got prioritized.