IBRAHIM OJOYE Project Delivery · Cyber Security & GRC
COMSEC Compliance Auditor · HMG IS4 v8.1

Cyber Security & GRC

Cyber Security and GRC specialist. Most recently audited COMSEC compliance against HMG IS4 v8.1 with HMG. I help organisations identify control gaps, assess risk and turn audit findings into practical remediation.

Previously DV clearedBased in London, UK

About

Background

I'm a Cyber Security and Governance, Risk and Compliance (GRC) specialist with over ten years across government, public sector and regulated environments. I most recently audited COMSEC compliance against HMG IS4 v8.1 with HMG: reviewing evidence, assessing control effectiveness and supporting risk-rated findings, and investigating cryptographic incidents from initial escalation through to corrective action. That sits alongside broader work in IT compliance, information assurance, incident management, audit readiness and secure service governance. I managed and improved key parts of the Service Request Catalogue (SRC) for HMG, and before that supported IT infrastructure at Lewisham Homes. Across both, the constant has been turning technical control gaps into remediation actions that service owners, managers and senior stakeholders can act on.

COMSEC Audit

Built the HMG IS4 audit readiness pack used across every account I audit, the same pack behind the AuditFlow OS case study.

Service Governance

Ran ServiceNow and Service Manager governance for HMG's SRC, cutting new starter onboarding from up to three months down to under one.

Clearance

Previously held Developed Vetting (DV) clearance, the level required for the most sensitive COMSEC and cryptographic incident work.

Frameworks

HMG IS4 v8.1NCSC CAFNIST CSFISO 27001

Tools & Methods

Risk & Control AssessmentAudit Evidence ReviewITIL v4Access Governance / JMLServiceNowPowerShellPower BI

BSc Computer Networks, First Class Honours, University of East London

Foundation

The Cyber and GRC Readiness Pack Series

I built a four-part cyber and Governance, Risk and Compliance (GRC) readiness pack series covering IS4, ISO 27001, NCSC CAF and NIST CSF 2.0. It started with the IS4 COMSEC audit question pack from my COMSEC audit work, then I used the same audit method to create the other three packs: evidence-led questions, deep-dive challenge points, good-practice and red-flag checks, findings capture and readiness scoring, each remapped to that framework's own domains. The ISO 27001, CAF and NIST CSF packs also close with an interview-preparation appendix. This series is also where AuditFlow OS started, see the full build story →

IS4 Compliance Audit question pack overview
IS4 Compliance Audit
Download IS4 pack →
ISO 27001 Readiness Audit question pack overview
ISO 27001 Readiness Audit
Download ISO 27001 pack →
NCSC CAF Readiness Audit question pack overview
NCSC CAF Readiness Audit
Download NCSC CAF pack →
NIST CSF 2.0 Readiness Audit question pack overview
NIST CSF 2.0 Readiness Audit
Download NIST CSF pack →
Method

How I work an audit

The same sequence runs through the COMSEC audits, the Readiness Pack Series and AuditFlow OS itself.

01 Scope & Evidence
02 Assess Controls
03 Identify Gaps
04 Prioritise Findings
05 Recommend Remediation
06 Assure & Report
Across the work

Capabilities

What each part of this site demonstrates, and where to find the evidence.

Applied Professionally

  • HMG IS4 v8.1 COMSEC compliance
  • Cryptographic incident management
  • Service Request Catalogue (SRC) governance
  • Audit planning & evidence review
  • IT infrastructure & access provisioning

Built

  • AuditFlow OS (Notion workspace & SaaS beta)
  • Cyber and GRC Readiness Pack Series (IS4, ISO 27001, NCSC CAF, NIST CSF)
  • 8-week public audit and assurance content series
CapabilityEvidenceShown
Audit & compliance readinessHMG IS4 v8.1 COMSEC audits, Cyber and GRC Readiness Pack Series
Risk identification & control assessmentCOMSEC audits, cryptographic incident investigation
Governance & service ownershipService Request Catalogue (SRC) governance for HMG
Stakeholder engagementSRC approval routes and ownership records, audit findings briefings
Process mapping & documentationReadiness Pack Series, SRC conformance checks and audit-ready documentation
Incident managementCryptographic incidents, escalation through to corrective action
Information assurance & infrastructureIT infrastructure, device deployment and access provisioning at Lewisham Homes
Product & systems thinkingAuditFlow OS, from Notion workspace to SaaS beta
Featured project

AuditFlow OS

Built off the back of the COMSEC audit work and the SRC governance work above: a readiness pack series, a Notion audit operating system, a public build-in-progress series, and now a live SaaS beta. The full build story, screenshots and downloads are on its own page.

View the AuditFlow OS case study →