Cybersecurity Governance, Risk & Policy

Cybersecurity governance and risk management connect technical security requirements to organizational priorities, policies, and decision-making. My coursework increasingly shifted my attention toward this part of the field by requiring me to consider not only whether a security control works, but why it is needed, how it should be implemented, who is responsible for it, and how organizations determine acceptable risk. The artifacts below demonstrate that development through security frameworks and policy enforcement, public cybersecurity policy, and enterprise information assurance.


Structured Policy Enforcement and NIST Frameworks

Course: CYSE 280 – Windows System Management and Security
Artifact Type: Cybersecurity Research Paper

Artifact Description
This research paper examined how structured policy enforcement can strengthen security in Windows-based environments when administrative tools are aligned with the NIST Cybersecurity Framework (CSF) 2.0. I evaluated technologies including Group Policy, Windows Defender, Event Viewer, BitLocker, and Windows Firewall against CSF functions and subcategories and considered how automation, centralized administration, and configuration affect security outcomes. The paper also compared Windows security management with Linux and macOS and used the WannaCry ransomware incident to illustrate the consequences of weak patch and policy enforcement

Skills Demonstrated

  • NIST Cybersecurity Framework application
  • Security policy and control analysis
  • Windows security administration concepts
  • Cross-platform security comparison
  • Risk-based evaluation of technical controls
  • Framework-to-technology mapping
Evaluation of common Windows security tools against NIST Cybersecurity Framework 2.0 functions and subcategories.

National Digital & Media Literacy Policy Analysis

Course: CYSE 425W – Cybersecurity Strategy and Policy
Artifact Type: Four-Part Policy Analysis

Artifact Description:
This four-part policy project examined the potential use of a national digital and media literacy curriculum as part of a broader cybersecurity strategy. I first evaluated digital literacy as a human-layer defense against social engineering, misinformation, and online manipulation, using examples from Finland, Estonia, and U.S. state-level policies. The later stages examined the same proposal through political, ethical, and social perspectives, including federal versus state authority, political bias, privacy, individual autonomy, unequal access to digital-literacy education, and the potential effects on public resilience and institutional trust.

Skills Demonstrated

  • Cybersecurity policy analysis
  • Human-centered security analysis
  • Political and ethical analysis
  • Comparative policy research
  • Social engineering and digital-literacy concepts
  • Evaluation of policy tradeoffs and unintended consequences
  • Research-based professional writing

Enterprise Information Assurance and Ransomware Risk Analysis

Course: CS 465 – Information Assurance for Cybersecurity
Artifact Type: Scenario-Based Enterprise Information Assurance Project

Artifact Description:
This final project required me to assume the role of Chief Information Assurance Officer for a fictional 1,000-employee defense-sector manufacturer following a ransomware incident. I evaluated the organization’s critical assets and vulnerabilities, developed a threat matrix and communications plan, proposed an information assurance reporting structure, and recommended technical, administrative, and organizational controls tied directly to identified risks. The project required me to consider cybersecurity as an enterprise responsibility involving governance, risk assessment, business operations, communication, information technology, operational technology, and organizational accountability.

The submitted report progresses from the incident itself into a vulnerability assessment, threat matrix, communications plan, governance structure, and preventive recommendations.


Skills Demonstrated

  • Enterprise cybersecurity risk assessment
  • Information assurance governance
  • Asset criticality and vulnerability analysis
  • Threat analysis
  • Security policy and control development
  • Incident communications planning
  • Organizational responsibility and accountability
  • IT/OT security considerations