Academic / Governance · Academic

Enterprise Security Risk Assessment & Policy

Connecting organizational risk with practical security governance.

Completed academic work · 2022–2024

Academic work · educational scenarios are not commercial engagements.

Ganesh Uprety — Enterprise Security Risk Assessment & Policy, editorial portrait

Editorial illustration. Dashboard figures are illustrative and are not project results.

Context and problem

A self-reported assessment for a hypothetical mid-sized organization, developed during Lambton College studies.

Methodology and risk assessment

Asset identification, threat analysis and security control assessment informed a structured risk register, with reference to ISO 27001 and NIST.

Policy development

The reported policy set covered incident response, disaster recovery and business continuity.

Reported deliverables

Approximately 4,000–5,000 words of risk assessment and policy documentation. Original reports, risk scores and audit outcomes are not presented as verified evidence.

From risk identification to decisions

A risk register is useful when it helps an organization decide what to protect and why. The case study connects assets and threats with control choices, ownership and continuity considerations.

Making policy usable

Incident response and disaster recovery guidance need to describe responsibilities and decisions clearly. The project’s governance focus connects technical controls to how an organization prepares, responds and recovers.