Project Name
MedData Solutions — Eramba GRC Implementation
Category
Cybersecurity Governance / GRC
Project Overview
A complete governance, risk, and compliance model developed in Eramba for MedData Solutions, a fictional healthcare SaaS company. The project brings together organizational assets, security controls, risks, policies, third parties, compliance requirements, audits, and continuity planning within a single structured GRC environment.
Challenge
Healthcare technology companies manage sensitive patient information, cloud infrastructure, external service providers, and strict regulatory requirements. The challenge was to create a clear governance structure that connects business objectives, information assets, cybersecurity risks, responsibilities, and compliance obligations.
Solution
An integrated Eramba model was created to document the organization’s goals, business units, assets, liabilities, third parties, internal controls, policies, audits, and continuity plans. Asset, business, and third-party risks were assessed and linked to relevant security controls, compliance requirements, improvement projects, and monitored tasks.
My Role
I designed and implemented the GRC model in Eramba, covering organizational assets, risk assessments, security controls, compliance requirements, policies, audits, third-party dependencies, and business continuity planning.
Key Areas
Asset Risk Management
Third-Party Risk
Business Risk
Internal Controls
Compliance Analysis
Security Policies
Control Audits
Business Continuity
