I am an Information Security and GRC professional with experience in security governance, risk management, policies, procedures, controls and compliance.
I help organizations review and improve their information security documentation and processes through practical and structured recommendations.
My areas of expertise include Information Security, GRC, ISO 27001, ISO 27002, NIST, CIS Controls, risk management, third-party risk management, security policies, procedures, controls, KPIs and KRIs.
I focus on clear, practical and actionable deliverables that organizations can actually use.... Read more