<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Projects | Guiselle Armstrong</title><link>https://guisellearmstrong.com/projects/</link><atom:link href="https://guisellearmstrong.com/projects/index.xml" rel="self" type="application/rss+xml"/><description>Projects</description><generator>HugoBlox Kit (https://hugoblox.com)</generator><language>en</language><lastBuildDate>Sun, 19 May 2024 00:00:00 +0000</lastBuildDate><image><url>https://guisellearmstrong.com/media/icon.svg</url><title>Projects</title><link>https://guisellearmstrong.com/projects/</link></image><item><title>Audit Readiness &amp; GRC Program Enablement</title><link>https://guisellearmstrong.com/projects/audit-readiness-grc-program-enablement/</link><pubDate>Tue, 01 Aug 2023 00:00:00 +0000</pubDate><guid>https://guisellearmstrong.com/projects/audit-readiness-grc-program-enablement/</guid><description>&lt;p&gt;&lt;strong&gt;Focus Areas:&lt;/strong&gt; SOC 2 · PCI DSS · CCPA · ISO/IEC 27001&lt;/p&gt;
&lt;p&gt;Focused on transforming audit readiness from a reactive, audit-season effort into a continuous, well-governed program aligned with SOC 2, PCI DSS, CCPA, and ISO/IEC 27001 principles. I led cross-functional efforts to improve visibility into risk, standardize evidence management, automate governance workflows, and strengthen collaboration between business teams, technical teams, and auditors.&lt;/p&gt;
&lt;h2 id="experience"&gt;Experience&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Established Executive-Level GRC Visibility&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Designed and automated a Power BI GRC Executive Dashboard providing leadership with monthly visibility into key compliance and risk metrics&lt;/li&gt;
&lt;li&gt;Tracked user access reviews, policy exceptions, audit artifacts, remediation activity, and vulnerability trends&lt;/li&gt;
&lt;li&gt;Enabled continuous monitoring, management review, and risk-based decision-making&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Strengthened Access Controls &amp;amp; Resiliency&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Partnered with departments to complete and document User Access Reviews (UARs)&lt;/li&gt;
&lt;li&gt;Developed and maintained Disaster Recovery documentation aligned with audit and availability requirements&lt;/li&gt;
&lt;li&gt;Ensured access controls and recovery practices were clearly defined, owned, and consistently audit-ready&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Operationalized Privacy &amp;amp; Regulatory Compliance (CCPA)&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Supported privacy access removals and data rights requests using OneTrust&lt;/li&gt;
&lt;li&gt;Ensured requests were processed within regulatory timelines and documented with appropriate approvals&lt;/li&gt;
&lt;li&gt;Maintained defensible evidence aligned with SOC 2 Privacy and ISO data protection controls&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Centralized Evidence Management &amp;amp; Audit Support&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Gathered, validated, and archived audit artifacts from multiple business and technical teams&lt;/li&gt;
&lt;li&gt;Maintained organized evidence repositories to support internal audits, SOC 2, PCI DSS, and regulatory assessments&lt;/li&gt;
&lt;li&gt;Actively participated in QSA and auditor meetings, helping translate control intent, clarify scope, and resolve gaps efficiently&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Supported Audit Findings &amp;amp; Timely Remediation (MAPS)&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Assisted teams in reviewing and addressing audit (MAPS) findings&lt;/li&gt;
&lt;li&gt;Partnered with control owners to identify root causes, define corrective actions, and track remediation efforts&lt;/li&gt;
&lt;li&gt;Ensured findings were remediated within required timelines and supported with appropriate evidence to meet audit expectations&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Implemented Policy Exception Governance&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Created and facilitated a weekly policy exception review meeting with cross-functional stakeholders&lt;/li&gt;
&lt;li&gt;Built a Power Automate workflow and dashboard to track exception approvals and notify owners of upcoming expirations&lt;/li&gt;
&lt;li&gt;Documented risk acceptance decisions and communicated outcomes to leadership to maintain a clear audit trail&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Enabled PCI DSS Compliance Through Training&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Designed and delivered PCI DSS training for employees involved in payment processing and credit card handling&lt;/li&gt;
&lt;li&gt;Reinforced secure handling practices, role-based responsibilities, and compliance expectations&lt;/li&gt;
&lt;li&gt;Supported ongoing audit readiness and reduced compliance risk&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Developed People &amp;amp; GRC Capability&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Trained, mentored, and empowered early-career cybersecurity engineers&lt;/li&gt;
&lt;li&gt;Helped teams understand how technical controls support SOC 2, PCI DSS, and ISO requirements&lt;/li&gt;
&lt;li&gt;Strengthened long-term ownership and accountability for controls across the organization&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="impact--results"&gt;Impact &amp;amp; Results&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Improved continuous audit readiness across SOC 2, PCI DSS, privacy, and internal audit programs&lt;/li&gt;
&lt;li&gt;Reduced audit friction by proactively addressing MAPS findings and control gaps&lt;/li&gt;
&lt;li&gt;Increased leadership visibility into compliance health and remediation status&lt;/li&gt;
&lt;li&gt;Strengthened collaboration between security, IT, legal, and business teams&lt;/li&gt;
&lt;li&gt;Built scalable, repeatable governance processes that supported consistent audit outcomes&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Vulnerability Management &amp; Risk Reduction Program</title><link>https://guisellearmstrong.com/projects/vulnerability-management-risk-reduction-program/</link><pubDate>Wed, 01 Mar 2023 00:00:00 +0000</pubDate><guid>https://guisellearmstrong.com/projects/vulnerability-management-risk-reduction-program/</guid><description>&lt;p&gt;&lt;strong&gt;Framework Alignment:&lt;/strong&gt; SOC 2 &amp;amp; ISO/IEC 27001&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Objective:&lt;/strong&gt; Reduce organizational risk by preventing vulnerable assets from entering production and ensuring timely, well‑governed remediation across infrastructure, databases, and endpoints&lt;/p&gt;
&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Established vulnerability management as a preventive, risk‑based control integrated into both production readiness and ongoing operations. The program aligned technical vulnerability scanning, remediation scheduling, and patch validation to SOC 2 and ISO/IEC 27001 expectations, ensuring vulnerabilities were identified early, prioritized appropriately, and remediated in a controlled, auditable manner.&lt;/p&gt;
&lt;h2 id="how-i-approached-vulnerability-risk-management"&gt;How I Approached Vulnerability Risk Management&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Preventive Vulnerability Controls &amp;amp; Production Readiness&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Executed enterprise vulnerability scans using Qualys and Nessus&lt;/li&gt;
&lt;li&gt;Performed mandatory vulnerability scans on all new server builds prior to production deployment&lt;/li&gt;
&lt;li&gt;Ensured systems met baseline security requirements before promotion to production, supporting preventive controls under SOC 2 CC7 and ISO operational security principles&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Continuous Risk Monitoring &amp;amp; Leadership Visibility (SOC 2 CC4 | ISO Clause 9)&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Designed and delivered a Power BI Vulnerability Management Dashboard&lt;/li&gt;
&lt;li&gt;Provided visibility into open vulnerabilities, remediation progress, and vulnerability burndown trends&lt;/li&gt;
&lt;li&gt;Enabled management review and continuous monitoring of security risk posture&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Clear Ownership &amp;amp; Accurate Data Mapping (SOC 2 CC3 | ISO Clause 6)&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Parsed vulnerability scan outputs using Python to accurately map vulnerabilities to specific devices and responsible owners&lt;/li&gt;
&lt;li&gt;Delivered owner‑specific remediation views to reduce noise and increase accountability&lt;/li&gt;
&lt;li&gt;Improved data integrity for both remediation tracking and audit evidence&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Risk‑Based Prioritization &amp;amp; Zero‑Day Response (SOC 2 CC5 | ISO Risk Treatment)&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Prioritized vulnerabilities based on severity, exploitability, and active threat intelligence, including zero‑day exploitation&lt;/li&gt;
&lt;li&gt;Focused remediation efforts on vulnerabilities posing the highest risk to confidentiality, integrity, and availability&lt;/li&gt;
&lt;li&gt;Ensured remediation decisions aligned with documented risk tolerance and audit expectations&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Cross‑Team Remediation Scheduling &amp;amp; Governance (SOC 2 CC7 | ISO Clause 8)&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Collaborated closely with server, database, and endpoint teams to establish structured vulnerability remediation schedules&lt;/li&gt;
&lt;li&gt;Coordinated remediation timelines based on system criticality, exposure, and operational impact&lt;/li&gt;
&lt;li&gt;Facilitated recurring remediation discussions to track progress and remove blockers&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Patch Testing &amp;amp; Controlled Deployment&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Worked directly in SCCM and Patch My PC to validate and test patches prior to production rollout&lt;/li&gt;
&lt;li&gt;Ensured patches were tested for stability and compatibility before deployment&lt;/li&gt;
&lt;li&gt;Supported controlled, auditable patch management processes aligned with ISO patch management and SOC 2 system operations controls&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Audit &amp;amp; GRC Integration&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Ensured vulnerability remediation activities, approvals, and outcomes were documented and retained as audit evidence&lt;/li&gt;
&lt;li&gt;Demonstrated continuous monitoring, risk treatment, and control effectiveness during audits&lt;/li&gt;
&lt;li&gt;Integrated vulnerability management metrics into broader GRC and audit readiness reporting&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="impact--results"&gt;Impact &amp;amp; Results&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Prevented insecure servers from entering production environments&lt;/li&gt;
&lt;li&gt;Reduced time‑to‑remediate for high‑risk and zero‑day vulnerabilities&lt;/li&gt;
&lt;li&gt;Improved coordination and accountability across infrastructure, database, and endpoint teams&lt;/li&gt;
&lt;li&gt;Strengthened patch governance through testing and controlled deployment&lt;/li&gt;
&lt;li&gt;Provided clear, defensible evidence of vulnerability management controls during SOC 2 and ISO‑aligned audits&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Change Management &amp; Controlled Release Governance</title><link>https://guisellearmstrong.com/projects/change-management-controlled-release-governance/</link><pubDate>Wed, 01 Jun 2022 00:00:00 +0000</pubDate><guid>https://guisellearmstrong.com/projects/change-management-controlled-release-governance/</guid><description>&lt;p&gt;&lt;strong&gt;Framework Alignment:&lt;/strong&gt; SOC 2 (CC7) &amp;amp; ISO/IEC 27001&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Objective:&lt;/strong&gt; Ensure all system and application changes were authorized, risk‑assessed, tested, documented, and deployed in a controlled manner to protect system availability, security, and compliance posture&lt;/p&gt;
&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Focused on strengthening organizational change management practices to meet SOC 2 CC7 and ISO change control expectations. The goal was to ensure that changes were not only implemented successfully, but also governed in a way that reduced operational risk, protected sensitive data, and produced defensible audit evidence. My work emphasized education, structured governance, and cross‑functional collaboration to embed change management into daily operations.&lt;/p&gt;
&lt;h2 id="how-i-applied-soc-2--iso-change-control-principles"&gt;How I Applied SOC 2 &amp;amp; ISO Change Control Principles&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Established Controlled Change Processes (SOC 2 CC7 | ISO Change Controls)&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Trained department managers and stakeholders on how to properly submit change documentation in alignment with formal change control requirements&lt;/li&gt;
&lt;li&gt;Ensured all changes included required elements such as testing evidence, risk assessments, business justification, and approvals&lt;/li&gt;
&lt;li&gt;Reinforced that changes must be authorized, reviewed, and traceable prior to implementation&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Led Change Advisory Board (CAB) Governance (SOC 2 CC7.2 | ISO Authorization &amp;amp; Review)&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Led daily CAB meetings, facilitating structured reviews of proposed changes&lt;/li&gt;
&lt;li&gt;Evaluated changes for risk, timing conflicts, dependencies, and potential impact to availability and security&lt;/li&gt;
&lt;li&gt;Ensured approval decisions, conditions, and outcomes were clearly documented for audit purposes&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Ensured Change Documentation Integrity &amp;amp; Data Protection&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Reviewed and revised submitted change records to ensure completeness, accuracy, and audit readiness&lt;/li&gt;
&lt;li&gt;Verified inclusion of testing results, risk assessments, and formal business approvals&lt;/li&gt;
&lt;li&gt;Ensured no PII or PCI data was included in change documentation, reducing data exposure risk and supporting regulatory compliance&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Coordinated Secure &amp;amp; Successful Releases (SOC 2 CC7 | ISO Operational Change)&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Worked closely with release and deployment teams to verify that approved changes were deployed as planned&lt;/li&gt;
&lt;li&gt;Supported coordination, communication, and scheduling to minimize disruption&lt;/li&gt;
&lt;li&gt;Assisted with post‑implementation validation to confirm change success and stability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Advised on Risk, Impact, and Organizational Readiness&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Acted as a trusted advisor to teams on how uncontrolled or poorly documented changes can impact availability, security, audit results, and customer trust&lt;/li&gt;
&lt;li&gt;Educated stakeholders on the importance of structured change management as a core operational and compliance control&lt;/li&gt;
&lt;li&gt;Strengthened awareness that change management is a shared responsibility supporting the organization as a whole&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="impact--results"&gt;Impact &amp;amp; Results&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Improved consistency and quality of change documentation across departments&lt;/li&gt;
&lt;li&gt;Reduced operational risk from unauthorized or insufficiently tested changes&lt;/li&gt;
&lt;li&gt;Supported system stability and availability during deployments&lt;/li&gt;
&lt;li&gt;Strengthened evidence for SOC 2 and ISO‑aligned audits&lt;/li&gt;
&lt;li&gt;Increased organizational understanding of change as a critical governance control&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>