Governance, Risk & Compliance
You need policies people actually follow. You also need evidence you can hand an auditor.
- Policy and standards authoring
- Risk register design and upkeep
- Control mapping to NIST CSF, ISO 27001, SOC 2 and HIPAA
- Audit preparation and evidence collection
- Security awareness program design