Project page

Cybersecurity Policy Development

Building an organizational security policy framework aligned to regulatory and operational requirements

Project snapshot

This project develops a comprehensive cybersecurity policy framework for an organization. It addresses the gap between technical security controls and the governance structures that make those controls enforceable, consistent, and auditable. The policy covers acceptable use, access control, incident response, data handling, and compliance obligations.

Project illustration

This project develops a comprehensive cybersecurity policy framework for an organization. It addresses the gap between technical security controls and the governance structures that make those controls enforceable, consistent, and auditable. The policy covers acceptable use, access control, incident response, data handling, and compliance obligations.

What the policy covers

Policy development approach

Governance structure

Policy AreaOwnerReview Cycle
Acceptable useHR / IT jointlyAnnual
Access controlIT SecurityAnnual or after incidents
Data classificationData Governance / LegalAnnual
Incident responseIT Security / LeadershipAfter each major incident

Why this project matters

Security policies are the connective tissue between technical controls and organizational behavior. I designed this project to show that I understand security as a governance problem, not just a technical one. Effective policy reduces risk through clarity, accountability, and enforceable expectations — not just firewalls and monitoring tools.