This repository serves as a cybersecurity governance portfolio focused on Governance, Risk, and Compliance (GRC).
The goal of these projects is to explore how a structured security program can be designed for a small business environment, using concepts from frameworks such as the NIST Risk Management Framework (RMF) and the NIST Cybersecurity Framework (CSF).
Projects focus on:
- risk assessment
- governance processes
- identity and access management
- continuous monitoring concepts
- control-to-evidence mapping
As I began my Bachelor of Science in Cybersecurity and Information Assurance in 2024, my initial interest was in offensive security.
As I progressed through A+, Network+, and Security+, I discovered my stronger interest is in governance, security architecture, and the structured protection of systems.
I started by hardening my own environment (separate admin accounts, removing unused services, deny-by-default firewall principles), and then began building workflows that compare system baselines and detect configuration drift through scheduled scans.
This work evolved into building portfolio-style governance projects that connect security controls, monitoring, and documentation.
The repositories in this portfolio represent components of a small-business security program, and the Technical Governance lab was/is an EDR project I was previously working on, now slowly transitioning to its own standalone GRC project (name to be updated).
Cybersecurity Governance Portfolio
│
├── Security Program Projects
│ ├── Coffee Shop Security Program
│ └── IAM Access Review Lab
│
└── Technical Governance Labs
└── Endpoint Monitoring & Configuration Drift Lab
Each project focuses on a different aspect of governance and risk management.
A long-form governance project simulating how a security program could be designed for a small retail coffee shop environment.
The project explores:
- business risk identification
- asset inventory
- control framework alignment
- governance documentation
- security program planning
Repository:
https://github.com/MgnCoding2020/grc-paper-project-coffee-shop
A governance-focused lab simulating an identity access review process.
The goal is to demonstrate how access inventories can be reviewed, findings documented, and remediation tracked.
Repository:
https://github.com/MgnCoding2020/IAM-Access-Review-Lab
This project began as a personal system-hardening and monitoring lab on my workstation.
The lab focuses on:
- baseline snapshots
- configuration drift detection
- reporting workflows
While not directly tied to the coffee shop governance scenario, it helped introduce concepts of continuous monitoring and control validation, which are important in governance programs.
Repository:
https://github.com/MgnCoding2020/HomeEDR-and-Governance-Security
Current areas of study and development include:
- NIST RMF & governance concepts
- continuous monitoring workflows
- configuration drift detection
- governance documentation
- control-to-evidence mapping
Bachelor of Science — Cybersecurity and Information Assurance (WGU)
2024 – In Progress



