top of page
Search

Where I've Been: Building, Learning, and Applying

  • Writer: Shola Hassan
    Shola Hassan
  • Jun 23
  • 2 min read

It's been a little over three months since my last post.

The silence wasn't intentional. I've simply been focused on doing the work.

Over the past few months, I've been investing heavily in strengthening my cybersecurity governance, risk, and compliance capabilities—not just through study, but through practical application.

On the certification front, I successfully earned the CompTIA CySA+ and ISACA CISM, while also completing training in PCI DSS v4.0. Each of these has deepened my understanding of how organizations manage risk, govern security programs, and demonstrate compliance in increasingly complex environments.

But what has been even more valuable has been the opportunity to apply those concepts in practice.

I've spent time working through SOC 2 Type II audit readiness activities, helping translate security controls into audit-ready evidence, policies, governance structures, and testing approaches.

I've also had the opportunity to support ISO 27001-related initiatives, gaining greater appreciation for the amount of coordination required between business, security, legal, operations, and leadership teams to build a functioning information security management system.

One lesson that continues to stand out is that compliance is rarely about compliance.

At its best, compliance is about creating repeatable processes, clear accountability, effective controls, and evidence that an organization can be trusted to do what it says it does.

The frameworks may differ—SOC 2, ISO 27001, PCI DSS—but the underlying principles are remarkably similar:

  • Understand the risks.

  • Implement appropriate controls.

  • Monitor effectiveness.

  • Demonstrate accountability.

  • Continuously improve.

As I continue this journey, my focus remains on governance, risk management, compliance, third-party risk, and the growing intersection between cybersecurity, privacy, and emerging technologies.

Thank you to everyone who has shared advice, opportunities, encouragement, and constructive feedback along the way.

More to come.

— Shola Hassan, CISM, CySA+, CPSP

 
 
 

Comments


bottom of page