Gideon Sarfo-Nyantakyi | GRC Analyst | ISSO | RMF Analyst
π Waco, TX | π Active DoD Secret Security Clearance
π MS Cybersecurity Management β University of Illinois Springfield (Dec 2026) | GPA: 3.95
π CompTIA Security+ CE | DoD FM Certification β Level 1
π LinkedIn
This repository documents hands-on cybersecurity lab work conducted in a personal homelab environment running Kali Linux on VirtualBox. All labs are aligned to NIST SP 800-53 Rev. 5 controls and DoD RMF frameworks, targeting GRC, vulnerability management, and security operations competencies.
| Component | Details |
|---|---|
| Host Machine | Lenovo IdeaPad, Intel i5-9300HF, 8GB RAM |
| Virtualization | Oracle VirtualBox |
| Primary OS | Kali Linux |
| Scanner | OpenVAS (Greenbone) GVM 26.17.0 |
| Frameworks | NIST SP 800-53 Rev. 5, NIST RMF, CMMC 2.0 |
| Lab | Title | Tools | NIST Controls | Status |
|---|---|---|---|---|
| 01 | Vulnerability Assessment | OpenVAS GVM 26.17.0 | RA-5, SI-2, CA-7 | β Complete |
| 02 | Network Enumeration & Asset Inventory | Nmap | CM-8, CA-7, PL-2 | π In Progress |
| 03 | System Security Plan (SSP) | NIST SP 800-53 Rev. 5 | PL-2, AC-1, IA-1 | π² Planned |
| 04 | Continuous Monitoring & Log Analysis | Kali Linux logs | AU-6, CA-7, IR-4 | π² Planned |
| Project | Description |
|---|---|
| Blue Stripe Tech DoD Ready | RMF package for simulated DoD contractor (FISMA, CMMC 2.0, NIST SP 800-53) |
| Health Network BCP/BIA | Business continuity and impact analysis for healthcare organization |
| Mircom Ransomware Case Study | Incident response analysis and lessons learned |
| Network Footprinting Lab | Passive/active reconnaissance using OSINT tools |
| Asset Risk Analysis | Risk identification, likelihood/impact matrix, mitigation recommendations |
- β CompTIA Security+ CE
- β Active DoD Secret Security Clearance
- β DoD FM Certification β Level 1
- β Army Financial Management Certification
- π MS Cybersecurity Management (Dec 2026) β GPA 3.95
U.S. Army Veteran (MOS 36B β Financial Management Technician) with experience in financial operations, compliance, and audit at Fort Cavazos. Transitioning into cybersecurity GRC with hands-on RMF, FISMA, CMMC 2.0, and NIST SP 800-53 experience through graduate coursework and self-directed homelab practice.