Cybersecurity governance and risk management connect technical security requirements to organizational priorities, policies, and decision-making. My coursework increasingly shifted my attention toward this part of the field by requiring me to consider not only whether a security control works, but why it is needed, how it should be implemented, who is responsible for it, and how organizations determine acceptable risk. The artifacts below demonstrate that development through security frameworks and policy enforcement, public cybersecurity policy, and enterprise information assurance.
Structured Policy Enforcement and NIST Frameworks
Course: CYSE 280 – Windows System Management and Security
Artifact Type: Cybersecurity Research Paper
Artifact Description
This research paper examined how structured policy enforcement can strengthen security in Windows-based environments when administrative tools are aligned with the NIST Cybersecurity Framework (CSF) 2.0. I evaluated technologies including Group Policy, Windows Defender, Event Viewer, BitLocker, and Windows Firewall against CSF functions and subcategories and considered how automation, centralized administration, and configuration affect security outcomes. The paper also compared Windows security management with Linux and macOS and used the WannaCry ransomware incident to illustrate the consequences of weak patch and policy enforcement
Skills Demonstrated
- NIST Cybersecurity Framework application
- Security policy and control analysis
- Windows security administration concepts
- Cross-platform security comparison
- Risk-based evaluation of technical controls
- Framework-to-technology mapping

National Digital & Media Literacy Policy Analysis
Course: CYSE 425W – Cybersecurity Strategy and Policy
Artifact Type: Four-Part Policy Analysis
Artifact Description:
This four-part policy project examined the potential use of a national digital and media literacy curriculum as part of a broader cybersecurity strategy. I first evaluated digital literacy as a human-layer defense against social engineering, misinformation, and online manipulation, using examples from Finland, Estonia, and U.S. state-level policies. The later stages examined the same proposal through political, ethical, and social perspectives, including federal versus state authority, political bias, privacy, individual autonomy, unequal access to digital-literacy education, and the potential effects on public resilience and institutional trust.
Skills Demonstrated
- Cybersecurity policy analysis
- Human-centered security analysis
- Political and ethical analysis
- Comparative policy research
- Social engineering and digital-literacy concepts
- Evaluation of policy tradeoffs and unintended consequences
- Research-based professional writing
Enterprise Information Assurance and Ransomware Risk Analysis
Course: CS 465 – Information Assurance for Cybersecurity
Artifact Type: Scenario-Based Enterprise Information Assurance Project
Artifact Description:
This final project required me to assume the role of Chief Information Assurance Officer for a fictional 1,000-employee defense-sector manufacturer following a ransomware incident. I evaluated the organization’s critical assets and vulnerabilities, developed a threat matrix and communications plan, proposed an information assurance reporting structure, and recommended technical, administrative, and organizational controls tied directly to identified risks. The project required me to consider cybersecurity as an enterprise responsibility involving governance, risk assessment, business operations, communication, information technology, operational technology, and organizational accountability.

Skills Demonstrated
- Enterprise cybersecurity risk assessment
- Information assurance governance
- Asset criticality and vulnerability analysis
- Threat analysis
- Security policy and control development
- Incident communications planning
- Organizational responsibility and accountability
- IT/OT security considerations