Portfolio Disclaimer & Comment
The following samples were created for my academic projects and professional simulations. All company names, technologies, and information were fabricated for educational purposes.
Please note that these are simulated example scenarios to demonstrate my thought process, organization, analysis, and results - from risk assessments and PCI DSS compliance projects to incident response exercises and Zero Trust implementation plans. You can click on each project to access the full case study PDF, which walks through the scenario, my approach, and a quantifiable solution.
No real companies were used in creating this portfolio.
View our Previous work
Discover our collection of creative work and visual projects. Each piece showcases our attention to detail and commitment to delivering results that exceed expectations.
1. SNOWBE ONLINE Policy# NAP-01 NEW ACCOUNT PROCEDURE POLICY
The New Account Procedure Policy outlines the formal, secure process for opening, provisioning, and approving new accounts to be placed on a company's systems and network. The goal of this process is to ensure all new accounts are created in compliance with the least privilege principle, screened, management-approved, and documented from the start. This process prevents unwanted access, privilege creep, and orphaned accounts.
2. SNOWBE ONLINE Policy# SB-01 PATCH AND VULNERABILITY POLICY
The Patch and Vulnerability Management Policy document defines the standardized procedure for patching software and mitigating known vulnerabilities on all systems within the organization. The goal of this policy is to reduce the organization's attack surface by patching/stopping known attacks as quickly as possible, with minimal system downtime, in a controlled and documented manner.
3. SNOWBE ONLINE Policy# SB-02 INCIDENT RESPONSE POLICY
The Incident Response Policy provides guidelines for identifying, responding to, and recovering from security incidents.
The intent is to limit damage, shorten recovery time, and maintain evidence by managing all security incidents in a uniform, coordinated, and documented manner - including identification, containment, eradication, recovery, and lessons learned.
4. SNOWBE ONLINE Policy# CCM-01 CHANGE CONTROL MANAGEMENT POLICY
The Change Control Management Policy defines the standard procedure for requesting, reviewing, approving, and implementing changes to IT systems, infrastructure, and applications. It ensures that all changes undergo risk, security impact, and business continuity review before implementation. Changes will not be made without authorization. The main goals are to reduce service interruption and ensure the integrity and stability of our systems.
5. THE SIMPLE MATURITY SPREADSHEET AND PRIORITIZATION
The Simple Maturity Self Assessment Tool allows an organization to measure where they currently sit in terms of cybersecurity maturity within a given domain, Designed to identify gaps in your current security controls by scoring them against a cybersecurity maturity model, it empowers you to remediate the most important gaps first, based on risk and business impact, so you can be confident in where you need to direct your effort and where to focus first.
6. CATEGORIZE A COMPANY USING A SECURITY MATURITY MODEL
This interprets the previous point. A Security Assessment is designed to analyze an organization and place its overall security maturity into a predetermined Security Maturity Model. The goal is to measure the organization's security capabilities, identify where it sits on a progression scale (from nascent to optimized), and provide an objective, consistent outline of what areas are strong, what areas need improvement, and what the overall strategic plan looks like for ongoing security improvement.
7. GROUP PROJECT: SNOWBE ONLINE SECURITY PLAN
I completed 8 deliverables as part of my *group project*, which tasked us with building an entire security program from the previous security policies. Our group created fundamental cybersecurity policies such as New Account Procedure, Patch and Vulnerability Management, Incident Response, and Change Control. We also created a Security Maturity assessment, a prioritization spreadsheet, company categorization, and the SNOWBE Online Security Plan. Collaboratively worked on creating policies, conducting risk assessments, and creating security plans. The great power of Teamwork!