Enterprise Security Risk Assessment & Policy
Connecting organizational risk with practical security governance.
Completed academic work · 2022–2024Academic work · educational scenarios are not commercial engagements.

Editorial illustration. Dashboard figures are illustrative and are not project results.
Context and problem
A self-reported assessment for a hypothetical mid-sized organization, developed during Lambton College studies.
Methodology and risk assessment
Asset identification, threat analysis and security control assessment informed a structured risk register, with reference to ISO 27001 and NIST.
Policy development
The reported policy set covered incident response, disaster recovery and business continuity.
Reported deliverables
Approximately 4,000–5,000 words of risk assessment and policy documentation. Original reports, risk scores and audit outcomes are not presented as verified evidence.
From risk identification to decisions
A risk register is useful when it helps an organization decide what to protect and why. The case study connects assets and threats with control choices, ownership and continuity considerations.
Making policy usable
Incident response and disaster recovery guidance need to describe responsibilities and decisions clearly. The project’s governance focus connects technical controls to how an organization prepares, responds and recovers.