Skip to content
View Nkee07's full-sized avatar

Block or report Nkee07

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Nkee07/README.md

Nkeiru Sarah Adesida

Cybersecurity GRC Analyst | NIST RMF, FISMA, FedRAMP | Security Control Assessment, Risk Assessment, POA&M Management

Washington DC and Baltimore area  |  nkiru_sarah@yahoo.com  |  LinkedIn  |  CISA, CompTIA Security+  |  MS Cybersecurity Management and Policy

PORTFOLIO EXERCISE, SIMULATED SYSTEM

Every project below is built on a fictional organisation. The Keystone Grants Management System does not exist and the Federal Workforce Development Agency is a fictional agency invented for this portfolio. Every organisation, person, identifier, finding, date and signature is fabricated for training purposes, with one exception: the author, Nkeiru Sarah Adesida, is a real person. Where her name appears in a scenario role, that role is fictional, and she has never worked for this agency, which does not exist. Nothing here comes from any real employer, client or government system, no real document or data has been reproduced, and none of it is a government record. Each repository and each individual document repeats this on its own first screen.


Credentials

CISA Security+ UMGC NIST RMF FedRAMP ISO 27001


About

Cybersecurity Governance, Risk and Compliance analyst with approximately five years of hands on experience in NIST Risk Management Framework implementation, security control assessment, risk assessment and continuous monitoring across federal and regulated environments.

My work sits where security meets evidence. I review implementation statements, examine artifacts, test controls against NIST SP 800-53 requirements, and document what I find in language both engineers and auditors can act on. I build and maintain Plan of Action and Milestones records so that every open weakness has an owner, a target date, and closure evidence that holds up under review.

Open to: Cybersecurity GRC Analyst, Information System Security Officer (ISSO), Security Control Assessor, Security Compliance Analyst and IT Audit roles across the Washington DC, Maryland and Virginia region. On site, hybrid or remote.


Frameworks and standards

SP 800-53 SP 800-53A SP 800-37 SP 800-30 SP 800-137 FISMA FIPS 199 ISO 27005

Tools and platforms

Nessus ServiceNow RSA Archer Wazuh

GRC practice areas

SSP SCA POAM ConMon Audit


Portfolio

Every project below is built on a fictional organisation and a simulated system. The Federal Workforce Development Agency and the Keystone Grants Management System do not exist. Every organisation, person, identifier, finding, date and signature is fabricated for training purposes, with one exception: the author, Nkeiru Sarah Adesida, is a real person. Where her name appears in a scenario role, that role is fictional, and she has never worked for this agency, which does not exist. Nothing in this portfolio comes from any real employer, client or government system, and no real document or data has been reproduced. Each repository and each individual document states this on its own first screen.

One simulated system, three framework lenses

Rather than three unrelated projects, these repositories document the same simulated federal system three times, from three professional angles. An employer is not buying knowledge of one framework, they are buying the ability to pick up a framework and apply it, and doing one system three ways is how that gets demonstrated.

Repository What it covers Focus
keystone-kgms-fedramp-rmf A complete FedRAMP Moderate authorisation: NIST RMF Steps 0 to 6, from readiness through a FIPS 199 categorisation with a documented impact adjustment, a System Security Plan with control implementation narratives, 16 assessment findings each with a disposition, a 10 item POA&M, the Authorization to Operate memorandum, and a live monthly continuous monitoring report FedRAMP
keystone-kgms-iso27001 The same system under ISO/IEC 27001:2022: ISMS scope and context, a Statement of Applicability covering all 93 Annex A controls individually, a 12 risk register scored inherent and residual, a risk treatment plan, an internal audit, a management review, and a crosswalk showing where the federal and international frameworks genuinely diverge ISO 27001
keystone-kgms-security-plus All five CompTIA Security+ SY0-701 domains applied to the same simulated system: general security concepts and cryptography, threats and mitigations traced to the real assessment findings, security architecture, security operations, and program management. The technical breadth underneath the GRC work Security+
keystone-kgms-conmon-vulnmgmt The work of keeping a system authorised: continuous monitoring strategy, a vulnerability management programme with real CVEs and correct CVSS handling, the POA&M lifecycle in ServiceNow, control monitoring and evidence management in RSA Archer, security control assessment procedures with worked test cases, and the metrics and reporting that go to the Authorizing Official ConMon

What I tried to do differently

  • Every summary number is generated from its own detail rows. No summary table in this portfolio disagrees with the rows beneath it, because the summaries are computed rather than typed. A summary that does not reconcile takes a reviewer under a minute to find.
  • Every assessment finding has exactly one disposition, and they sum to the total. 16 findings: 5 closed during fieldwork, 1 formally risk accepted, 10 carried into the POA&M. Nothing is unexplained.
  • Machine readable artifacts, not only documents. The POA&M, the Statement of Applicability, the risk register, the finding sets and the test cases are published as CSV as well, because that is the format they are actually worked in.
  • The failures are written up as fully as the successes, including root cause. A portfolio where nothing went wrong is a portfolio that was not tested.
  • Every document discloses that it is simulated, on its own first screen, not only in a repository landing page a reader may never open.

Contact

Email LinkedIn


All portfolio work on this profile is built on a fictional organisation and a simulated system. It is coursework and it is not a government record. nkiru_sarah@yahoo.com | LinkedIn

Pinned Loading

  1. keystone-kgms-conmon-vulnmgmt keystone-kgms-conmon-vulnmgmt Public

    PORTFOLIO EXERCISE on a fictional system. Continuous monitoring and vulnerability management with Tenable Nessus, ServiceNow and RSA Archer: scan programme, CVSS handling, POA&M lifecycle, control …

  2. keystone-kgms-fedramp-rmf keystone-kgms-fedramp-rmf Public

    PORTFOLIO EXERCISE on a fictional system. A complete FedRAMP Moderate authorization package: NIST RMF Steps 0 to 6, 16 assessment findings, a 10 item POA&M, and a live continuous monitoring report.

  3. keystone-kgms-iso27001 keystone-kgms-iso27001 Public

    PORTFOLIO EXERCISE on a fictional system. ISO/IEC 27001:2022 and ISO/IEC 27005: ISMS scope, a Statement of Applicability covering all 93 Annex A controls, a 12 risk register, internal audit, manage…

  4. keystone-kgms-security-plus keystone-kgms-security-plus Public

    PORTFOLIO EXERCISE on a fictional system. All five CompTIA Security+ SY0-701 domains applied to the same simulated federal system: general security concepts, threats and mitigations, architecture, …