{"id":25,"date":"2026-05-04T15:32:34","date_gmt":"2026-05-04T15:32:34","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/tboak002\/?page_id=25"},"modified":"2026-05-04T18:28:11","modified_gmt":"2026-05-04T18:28:11","slug":"risk-management-compliance","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/tboak002\/risk-management-compliance\/","title":{"rendered":"Risk Management &amp; Compliance"},"content":{"rendered":"\n<h4 class=\"wp-block-heading has-white-color has-vivid-green-cyan-background-color has-text-color has-background has-link-color wp-elements-5d4b2a812f4d59040c0a2bbcb6b375ef\">Why This Skill Matters<\/h4>\n\n\n\n<p>Cybersecurity is not just about stopping attacks. It is also about understanding the rules, frameworks, and policies that shape how organizations protect themselves. This is what risk management and compliance is about. It is the skill of looking at the big picture. It is the skill of seeing how laws, strategies, and business goals affect security choices.<\/p>\n\n\n\n<p>Job ads in this space are growing fast. GRC Analyst roles ask for knowledge of NIST, ISO 27001, HIPAA, and PCI-DSS. Risk Analyst roles ask for the ability to read policy documents and turn them into clear action. Even SOC Analyst roles now ask for compliance awareness. Hiring managers want people who can think beyond the firewall. They want people who understand why a control exists, not just how it works.<\/p>\n\n\n\n<p>I built this skill through three writing-heavy courses at Old Dominion University. Each course pushed me into a different layer of risk and compliance. CYSE 425 taught me about national strategy and organizational culture. CYSE 526 taught me how risk plays out at the global level in cyber conflict. PHIL 355E taught me how ethics and law shape policy debates. The three artifacts below show what I learned in each.<\/p>\n\n\n\n<h4 class=\"wp-block-heading has-vivid-cyan-blue-background-color has-background\">1. Artifact Title<\/h4>\n\n\n\n<p><strong>Policy Paper 4: Cybersecurity Culture, Strategy, and the Influence of Generative AI<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Course<\/h4>\n\n\n\n<p>CYSE 425W: Cyber Strategy and Policy (Fall 2025)<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">What It Is<\/h4>\n\n\n\n<p>A policy paper that analyzes the 2023 U.S. National Cybersecurity Strategy. The paper looks at how this strategy shapes organizational culture. It also explores how Generative AI changes the picture. The paper covers the five pillars of the strategy. It examines how training, accountability, and transparency build a strong security culture. It also includes a visual model that links national strategy, culture, and GenAI together.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Why This Artifact Shows the Skill<\/h4>\n\n\n\n<p>This paper is the clearest example of risk management thinking in my coursework. To write it, I had to read government policy documents from the White House and NIST. I had to understand how a national strategy reaches private companies. I had to see how rules shape behavior at every level of an organization.<\/p>\n\n\n\n<p>The biggest lesson from this paper was that compliance is a culture. A company can have every policy on paper and still fail if the people inside do not believe in it. Strong compliance comes from leadership, training, and clear expectations. Weak compliance comes from fear, silence, and copy-paste rules. The paper also showed me how new technology like Generative AI can support compliance or break it. Both sides matter.<\/p>\n\n\n\n<p>This artifact ties directly to GRC roles. Hiring managers in this space want people who can read a strategy document and explain what it means for the business. This paper proves I can do that.<\/p>\n\n\n\n<div data-wp-interactive=\"\" class=\"wp-block-file\"><object data-wp-bind--hidden=\"!selectors.core.file.hasPdfPreview\" hidden class=\"wp-block-file__embed\" data=\"https:\/\/sites.wp.odu.edu\/tboak002\/wp-content\/uploads\/sites\/41203\/2026\/05\/Assignment-3-Author-Insights-Table-IDS.pdf\" type=\"application\/pdf\" style=\"width:100%;height:600px\" aria-label=\"Embed of Assignment-3-Author-Insights-Table-IDS.\"><\/object><a id=\"wp-block-file--media-296cf8fd-1316-4b93-81ac-32cdb6efc238\" href=\"https:\/\/sites.wp.odu.edu\/tboak002\/wp-content\/uploads\/sites\/41203\/2026\/05\/Assignment-3-Author-Insights-Table-IDS.pdf\">Assignment-3-Author-Insights-Table-IDS<\/a><a href=\"https:\/\/sites.wp.odu.edu\/tboak002\/wp-content\/uploads\/sites\/41203\/2026\/05\/Assignment-3-Author-Insights-Table-IDS.pdf\" class=\"wp-block-file__button wp-element-button\" download aria-describedby=\"wp-block-file--media-296cf8fd-1316-4b93-81ac-32cdb6efc238\">Download<\/a><\/div>\n\n\n\n<h4 class=\"wp-block-heading has-vivid-cyan-blue-background-color has-background\">2. Artifact Title<\/h4>\n\n\n\n<p><strong>Is Cyberspace Being Militarized?<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Course<\/h4>\n\n\n\n<p>CYSE 526: Cyber War (Fall 2025)<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">What It Is<\/h4>\n\n\n\n<p>A long-form research paper that examines whether cyberspace is becoming a domain of military conflict. The paper reviews work from major experts in the field. It looks at real-world examples like the 2007 Estonia attack, Stuxnet, and Russian cyber operations in Ukraine. It also covers the legal gaps that make cyber conflict so hard to manage. The paper closes with regional analysis of how Europe, Asia, and the Middle East respond to cyber militarization in different ways.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Why This Artifact Shows the Skill<\/h4>\n\n\n\n<p>This paper showed me that risk does not stop at the company firewall. Risk lives at the national and global level too. A single attack on a power grid can affect millions of people across borders. A single piece of malware can leak from a military target into a civilian hospital. Risk and compliance must be understood at every scale.<\/p>\n\n\n\n<p>Writing this paper forced me to read peer-reviewed sources from cybersecurity, international relations, and law. I learned that international law was built for physical war. It struggles to fit cyber conflict. Concepts like sovereignty and proportionality do not always work when attacks come through code. I also learned how attribution problems create gray zones. If you cannot prove who attacked you, your options become limited.<\/p>\n\n\n\n<p>This artifact connects to risk management roles in a real way. Many large companies now think about geopolitical risk. They want analysts who understand how nation-state actors move. They want people who can read global news through a security lens. This paper proves I can do that kind of analysis.<\/p>\n\n\n\n<div data-wp-interactive=\"\" class=\"wp-block-file\"><object data-wp-bind--hidden=\"!selectors.core.file.hasPdfPreview\" hidden class=\"wp-block-file__embed\" data=\"https:\/\/sites.wp.odu.edu\/tboak002\/wp-content\/uploads\/sites\/41203\/2026\/05\/Is-Cyberspace-Being-Militarized-pdf.pdf\" type=\"application\/pdf\" style=\"width:100%;height:600px\" aria-label=\"Embed of Is-Cyberspace-Being-Militarized-pdf.\"><\/object><a id=\"wp-block-file--media-718f6e7d-ac1a-4eaf-a93e-9b3b7ebc397d\" href=\"https:\/\/sites.wp.odu.edu\/tboak002\/wp-content\/uploads\/sites\/41203\/2026\/05\/Is-Cyberspace-Being-Militarized-pdf.pdf\">Is-Cyberspace-Being-Militarized-pdf<\/a><a href=\"https:\/\/sites.wp.odu.edu\/tboak002\/wp-content\/uploads\/sites\/41203\/2026\/05\/Is-Cyberspace-Being-Militarized-pdf.pdf\" class=\"wp-block-file__button wp-element-button\" download aria-describedby=\"wp-block-file--media-718f6e7d-ac1a-4eaf-a93e-9b3b7ebc397d\">Download<\/a><\/div>\n\n\n\n<h4 class=\"wp-block-heading has-vivid-cyan-blue-background-color has-background\">3. Artifact Title<\/h4>\n\n\n\n<p><strong>Going Dark Discussion: Encryption, Law Enforcement, and Global Compliance<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Course<\/h4>\n\n\n\n<p>PHIL 355E: Cybersecurity Ethics (Fall 2025)<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">What It Is<\/h4>\n\n\n\n<p>A discussion board response that engaged with former FBI Director James Comey&#8217;s argument about encryption and law enforcement. The post examined the tension between digital privacy and national security. It pulled in global examples from the European Union, Australia, and India. The post also took a clear stance on the risks of weakening encryption.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Why This Artifact Shows the Skill<\/h4>\n\n\n\n<p>Compliance is not the same in every country. This post showed me that. The European Union protects strong encryption under privacy law. Australia has tried to force backdoors with mixed results. India has pushed for similar access. Each region balances privacy and security in its own way. A real GRC professional needs to know these differences. A company that operates across borders has to follow many compliance rules at once.<\/p>\n\n\n\n<p>The post also showed my ability to take a stand. I argued that weakening encryption for &#8220;good guys&#8221; creates risks for everyone. Hackers can exploit those same backdoors. Privacy gets eroded. Trust falls. Real risk management means understanding trade-offs. It means making hard calls based on evidence, not fear.<\/p>\n\n\n\n<p>Floridi&#8217;s work on information ethics teaches that good policy balances many values at once. The encryption debate forces us to do exactly that. This artifact proves I can think through ethical and policy trade-offs in a clear way.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote has-pale-pink-background-color has-background\">\n<p><strong>Director Comey&#8217;s argument about encryption creating &#8220;unreachable spaces&#8221; for law enforcement made me think. Even though I understand why police need access for serious crimes, forcing tech companies to add backdoors could probably harm them more. Hackers could exploit those weaknesses, putting everyone&#8217;s privacy at risk. Countries like the EU need strong encryption to protect data, while Australia and India have tried forcing backdoors with questionable results. I believe there is no way to weaken encryption just for &#8220;good guys.&#8221; Instead of risking global security, law enforcement should aim on other tools, like tracking metadata, to solve crimes without sacrificing privacy.<\/strong><\/p>\n<\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\">How These Three Artifacts Work Together<\/h4>\n\n\n\n<p>These three artifacts cover risk and compliance from three different angles. The CYSE 425 paper looks at national strategy and how it shapes organizational culture. The CYSE 526 paper looks at global risk and how cyber conflict crosses borders. The PHIL 355E discussion looks at ethical and policy trade-offs in encryption.<\/p>\n\n\n\n<p>Together they show that I think about risk at every level. From a single company&#8217;s culture, to a nation&#8217;s strategy, to the global stage. This is what GRC and risk analyst roles need. People who can zoom out and zoom in. People who can read a policy and understand what it means in practice.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Why This Skill Matters Cybersecurity is not just about stopping attacks. It is also about understanding the rules, frameworks, and policies that shape how organizations protect themselves. This is what risk management and compliance is about. It is the skill of looking at the big picture. It is the skill of seeing how laws, strategies,&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/tboak002\/risk-management-compliance\/\">Read More<\/a><\/div>\n","protected":false},"author":21984,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/tboak002\/wp-json\/wp\/v2\/pages\/25"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/tboak002\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/tboak002\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/tboak002\/wp-json\/wp\/v2\/users\/21984"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/tboak002\/wp-json\/wp\/v2\/comments?post=25"}],"version-history":[{"count":5,"href":"https:\/\/sites.wp.odu.edu\/tboak002\/wp-json\/wp\/v2\/pages\/25\/revisions"}],"predecessor-version":[{"id":89,"href":"https:\/\/sites.wp.odu.edu\/tboak002\/wp-json\/wp\/v2\/pages\/25\/revisions\/89"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/tboak002\/wp-json\/wp\/v2\/media?parent=25"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}