Four hands-on GRC portfolio projects built around NIST frameworks, each simulating a real assessment engagement end-to-end (scoping → assessment → findings → remediation). Built to demonstrate practical GRC analyst work across risk management, cybersecurity maturity, control assessment, and supply chain risk — the core domains covered by the ISC2 CGRC exam and typical GRC/IT Risk analyst roles.
| # | Project | Framework | Focus |
|---|---|---|---|
| 1 | RMF ATO Package | NIST SP 800-37 (RMF) | Full 7-step system authorization package for a new digital lending platform |
| 2 | CSF 2.0 Maturity Assessment | NIST CSF 2.0 | Org-wide cybersecurity maturity profile across all 6 CSF functions |
| 3 | SP 800-53 Control Assessment | NIST SP 800-53 Rev. 5 | Control assessment for a SaaS vendor pursuing FedRAMP Moderate |
| 4 | SP 800-161 Supply Chain Risk Program | NIST SP 800-161 (C-SCRM) | Vendor/ICT supply chain risk management program |
Each project is self-contained with its own README, fictional company scenario, methodology, and deliverables (assessment matrix + executive report), so any one of them can be reviewed or forked independently.
- Meridian Trust Financial Services — Canadian fintech (lending & payments), reused across Projects 1, 2, and 4 for continuity.
- NorthGate SaaS Solutions — fictional B2G SaaS vendor pursuing FedRAMP authorization, used in Project 3 where a federal-agency context fits NIST SP 800-53 better than a Canadian financial services scenario.
All companies, findings, and evidence are illustrative and created for portfolio demonstration purposes only.
Paul Azeez Tunde Hamzat | Cybersecurity GRC Analyst LinkedIn · GitHub