← Back to GRC Projects

PROJECT 06 / CYBERSECURITY POSTURE

Race for 15

A cybersecurity posture initiative organized around 15 defensive capability areas to help evaluate security coverage, identify control gaps, prioritize improvements, and communicate cybersecurity risk in a structured and understandable way.

FOCUS Security Posture
CAPABILITIES 15
APPROACH Control-Based
OBJECTIVE Risk Reduction

01 / PROJECT CONTEXT

From security tools to security outcomes.

Cybersecurity programs often contain many individual tools, technologies, policies, and processes. The challenge is understanding whether those capabilities collectively provide meaningful protection against organizational risk.

Race for 15 organizes cybersecurity posture into 15 practical defensive capability areas. Each area represents an important component of a layered cybersecurity program.

Instead of asking only whether a security product exists, the approach considers whether the capability is implemented, governed, monitored, maintained, and capable of producing the intended security outcome.

This portfolio version presents the project through a GRC lens by connecting technical security capabilities with control maturity, evidence, risk, ownership, remediation, and measurable improvement.

The portfolio presentation does not contain confidential organizational configurations, internal findings, customer information, or employer data.

02 / THE 15 CAPABILITIES

Fifteen areas of cyber defense.

The capability model provides a practical way to organize technical controls into security outcomes that can be assessed, discussed, prioritized, and improved.

01

Endpoint Detection & Response

Detect, investigate, contain, and respond to suspicious endpoint activity.

02

Multifactor Authentication

Reduce account compromise risk by requiring additional authentication factors.

03

Vulnerability Management

Identify, prioritize, track, and remediate security weaknesses.

04

Least Privilege

Limit access and permissions to legitimate business need.

05

Email Security

Reduce phishing, malicious attachment, spoofing, and email-based attack risk.

06

Security Awareness

Build user awareness of phishing, social engineering, reporting, and safe behavior.

07

DNS Security

Reduce access to known malicious and unwanted internet destinations.

08

Web Filtering

Restrict access to malicious or inappropriate web content based on organizational policy.

09

Patch Management

Deploy security updates within defined timelines based on risk and criticality.

10

Cloud Security

Protect cloud identities, configurations, services, workloads, and information.

11

Backup & Recovery

Maintain recoverable copies of critical information and validate restoration capability.

12

Network Segmentation

Limit unnecessary connectivity and reduce lateral movement opportunities.

13

Incident Response

Prepare for, detect, contain, eradicate, recover from, and learn from security incidents.

14

Identity & Access Management

Govern identity lifecycle, authentication, authorization, and access review.

15

Centralized Logging & Monitoring

Collect and analyze security events to support detection, investigation, and response.

03 / ASSESSMENT APPROACH

Evaluate more than implementation.

A security capability can exist without being consistently governed or effective. The assessment therefore considers multiple dimensions of control maturity.

01

Implementation

Is the security capability deployed where it is required?

02

Coverage

Does the capability protect the intended users, assets, systems, and environments?

03

Governance

Are ownership, requirements, policies, and responsibilities clearly established?

04

Evidence

Can the organization demonstrate that the control is operating through reliable evidence?

05

Monitoring

Is performance, coverage, failure, or compliance continuously observed?

06

Improvement

Are identified gaps assigned, prioritized, remediated, and reassessed?

04 / MATURITY MODEL

Measuring progress.

A simple maturity scale can communicate whether a capability is absent, inconsistently implemented, defined, managed, or continuously improved.

LEVEL 1 Initial

Capability is absent, informal, or highly dependent on individual effort.

LEVEL 2 Developing

Capability exists in portions of the environment but is inconsistent or incomplete.

LEVEL 3 Defined

Requirements, processes, responsibilities, and controls are documented and established.

LEVEL 4 Managed

Capability is measured, monitored, maintained, and consistently executed.

LEVEL 5 Optimized

Metrics, automation, lessons learned, and continuous improvement drive maturity.

05 / SAMPLE ASSESSMENT

Example posture evaluation.

The following scores are simulated portfolio data used to demonstrate how the Race for 15 methodology can communicate current-state maturity and target-state objectives.

# Capability Current Target Gap Priority
01 Endpoint Detection & Response 4 4 0 Maintain
02 Multifactor Authentication 4 5 1 Medium
03 Vulnerability Management 3 4 1 Medium
04 Least Privilege 2 4 2 High
05 Email Security 4 4 0 Maintain
06 Security Awareness 3 4 1 Medium
07 DNS Security 3 4 1 Medium
08 Web Filtering 3 4 1 Medium
09 Patch Management 2 4 2 High
10 Cloud Security 2 4 2 High
11 Backup & Recovery 3 4 1 Medium
12 Network Segmentation 2 4 2 High
13 Incident Response 3 4 1 Medium
14 Identity & Access Management 3 4 1 Medium
15 Centralized Logging & Monitoring 2 4 2 High

06 / SAMPLE DASHBOARD

Turning assessment data into visibility.

These figures are derived from the simulated maturity scores above and demonstrate how leadership-level posture information could be summarized.

Capabilities 15
Current Points 43 / 75
Current Maturity 2.87
Target Points 61 / 75
Target Maturity 4.07
High Priorities 5

07 / PRIORITY GAPS

Focus remediation where it matters most.

Capability Current Target Risk Recommended Action
Least Privilege 2 4 High Establish recurring access reviews, role baselines, privileged-access governance, and removal of unnecessary permissions.
Patch Management 2 4 High Establish risk-based patch timelines, exception tracking, compliance reporting, and escalation for overdue assets.
Cloud Security 2 4 High Establish cloud configuration baselines, identity controls, logging requirements, and recurring posture reviews.
Network Segmentation 2 4 High Review network trust boundaries, restrict unnecessary traffic, and document approved segmentation requirements.
Centralized Logging & Monitoring 2 4 High Define required log sources, retention expectations, alert coverage, monitoring ownership, and ingestion health checks.

08 / SAMPLE FINDING

From maturity gap to GRC finding.

RF15-015

Incomplete Centralized Security Logging

HIGH
CONDITION

The simulated assessment indicates that centralized monitoring exists, but not all required security-relevant systems consistently forward logs to the monitoring platform.

RISK

Missing security telemetry can create detection blind spots and reduce the ability to investigate suspicious activity or reconstruct security events.

CURRENT MATURITY

Level 2 — Developing

TARGET MATURITY

Level 4 — Managed

OWNER

Security Operations / IT

TREATMENT

Mitigate

RECOMMENDED REMEDIATION
  • Define required security log sources based on system criticality and risk.
  • Establish minimum logging and retention requirements.
  • Identify systems not forwarding required logs.
  • Implement monitoring for log-source ingestion failures.
  • Assign ownership for investigating telemetry gaps.
  • Periodically measure logging coverage and report unresolved exceptions.
TARGET OUTCOME MEASURABLE LOGGING COVERAGE

Security leadership should be able to determine which critical systems are producing required telemetry, identify coverage gaps, assign remediation, and monitor improvement over time.

09 / GOVERNANCE

Every capability needs ownership.

01

Control Owner

Assign accountability for maintaining each security capability.

02

Requirements

Define what successful implementation and coverage should look like.

03

Evidence

Identify evidence that can demonstrate whether the capability is operating.

04

Metrics

Establish measurable indicators for coverage, performance, exceptions, and remediation.

05

Exceptions

Document deviations, risk decisions, compensating controls, and expiration dates.

06

Reporting

Communicate material gaps and progress to security and business leadership.

10 / FRAMEWORK ALIGNMENT

Connecting capabilities to recognized frameworks.

Race for 15 is a practical capability model rather than a replacement for a cybersecurity framework. Its control areas can be cross-referenced to recognized security frameworks to support governance and assessment activities.

FRAMEWORK NIST CSF 2.0

Organizes cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond, and Recover.

FRAMEWORK NIST RMF

Supports structured cybersecurity risk management throughout the system lifecycle.

CONTROL CATALOG NIST SP 800-53

Provides detailed security and privacy controls that can support individual capability areas.

SAFEGUARDS CIS Controls

Provides prioritized cybersecurity safeguards that align with many Race for 15 capability areas.

11 / IMPROVEMENT ROADMAP

Move from findings to measurable improvement.

Phase Objective Example Actions Expected Outcome
Phase 1 Address high-risk gaps Least privilege, patching, cloud security, segmentation, and logging remediation. Reduce immediate exposure.
Phase 2 Standardize controls Define ownership, policies, baselines, evidence, and exception processes. Improve consistency.
Phase 3 Establish metrics Measure coverage, compliance, exceptions, overdue actions, and control performance. Improve visibility.
Phase 4 Automate monitoring Automate evidence collection, alerting, reporting, and control-health monitoring. Improve sustainability.
Phase 5 Reassess maturity Repeat capability reviews and compare results against prior assessment periods. Demonstrate improvement.

12 / GRC VALUE

Why Race for 15 belongs in a GRC portfolio.

01

Control Assessment

Evaluate whether important cybersecurity safeguards are implemented and effective.

02

Risk Identification

Translate technical security weaknesses into meaningful organizational risk.

03

Gap Analysis

Compare current capability maturity with a defined target state.

04

Governance

Establish ownership, requirements, evidence, metrics, and accountability.

05

Prioritization

Direct remediation effort toward the capability gaps creating the greatest exposure.

06

Executive Communication

Convert technical security posture into concise information leadership can understand.

13 / INTERVIEW CONNECTION

Technical experience meets governance.

PROJECT STORY

Race for 15

THE PROBLEM

Cybersecurity posture can become difficult to communicate when security is viewed as a collection of disconnected technologies and activities.

THE APPROACH

Organize defensive security into 15 capability areas that can be evaluated using common criteria for implementation, coverage, governance, evidence, monitoring, and improvement.

THE GRC CONNECTION

The model connects technical safeguards to control maturity, risk identification, ownership, remediation, and reporting.

THE OUTCOME

Security gaps become easier to prioritize and communicate as measurable risk-reduction initiatives.

CORE MESSAGE SECURITY CONTROLS SHOULD PRODUCE MEASURABLE OUTCOMES

Race for 15 demonstrates how technical cybersecurity knowledge can support governance and risk management by connecting security capabilities to evidence, accountability, maturity, and measurable improvement.

PROJECT CONCLUSION

Fifteen capabilities. One security posture.

Race for 15 demonstrates a practical way to connect technical cybersecurity controls with governance, risk management, control maturity, evidence, remediation priorities, and leadership reporting. The objective is not simply to deploy more security tools, but to understand whether critical security capabilities are producing measurable risk reduction.