Self‑directed artifact compares the NIST Cybersecurity Framework, ISO/IEC 27001, and COBIT. Without a rubric or assignment prompt, I had to determine which criteria mattered, what sources to consult, and how to evaluate each framework in a way meaningful to practitioners. This project reinforced a key lesson: “The right answer is always context‑dependent.” This artifact demonstrates independent research, analytical judgment, and the ability to match governance tools to organizational needs a core competency in cybersecurity risk management.