NILADRI BISWAS
@Oracleo
About
GRC & InfoSec | M.Tech Information Security | ISC2 CC · SC-900 | Risk Assessment · ISO/IEC 27001:2022 · NIST CSF | Open to GRC Intern
Skills & Technologies
Projects & Repositories
Recent public projects and repositories from this profile.
Oracleo-Fintech-GRC-Reference-Implementation-Portfolio
Enterprise Governance, Risk and Compliance (GRC) Reference Implementation for a FinTech organisation using ISO/IEC 27001:2022, NIST CSF 2.0, ISO 27005, COBIT 2019, NIST SP 800-53 Rev.5 and ServiceNow IRM.
god-watch
TypeScriptGod Watch - Every Day Leaves Evidence. A date-first habit tracker and daily checklist SaaS built with Next.js 15, Supabase, Prisma, Auth.js
GRC-Project-02-Web-Application-Security-Assessment
Web App Risk Assessment | 4 Critical/High findings | SQLi 9.8 · XSS 7.3 · Brute Force 7.5 · CSRF 6.5 | CVSS · OWASP · ISO 27001 | Audit-grade report
GRC-Project-05-Network-Control-Validation-and-Risk-Assessment
Network Threat Detection & Audit Evidence Collection using Suricata IDS and Wireshark — 249 alerts triaged against independent packet evidence, one detection limitation documented honestly rather than concealed, full attack sequence mapped to the cyber kill chain, and a risk register entry assessing control effectiveness and monitoring coverage gap
GRC-Project-04-SIEM-Security-Control-Monitoring-and-Risk-Assessment
Security Control Monitoring & Risk Documentation | Splunk SIEM detecting brute-force authentication activity via Windows Event Logs — real-time alerting, MITRE ATT&CK mapping, and a documented risk register entry assessing control effectiveness, privileged account exposure, and detective-versus-preventive control gaps against ISO 27001 and NIST CSF
GRC-Project-03-Social-Engineering-Risk-Assessment
Social Engineering Risk Assessment | Live phishing email | SPF/DKIM/DMARC analysis · IOC extraction · Threat Intel | ISO 27001 · NIST CSF | Incident report