📅 Day 106 — From Risk Management to Portfolio Evidence
🔄 Topic
Consolidating Course 2 into practical portfolio artifacts: audit notes, SIEM triage, playbooks, and risk language.
🎯 Goal
Turn risk-management course material into credible public documentation without sounding like copied course notes.
🛠 What I Did
Today I consolidated the main work from Course 2 — Play It Safe: Manage Security Risks.
The strongest portfolio opportunities from this course are not the definitions. They are the activities and workflows:
- threat/risk/vulnerability classification
- security audit findings
- control reviews
- SIEM alert triage
- playbook-based response
- clear documentation of evidence and impact
This is where broad course theory starts becoming useful public proof of work.
🔗 Key Cybersecurity Connections
A certificate says I studied something. A portfolio artifact shows how I think.
A weak blog post says:
I learned about SIEM and playbooks.
A stronger artifact shows:
alert evidence, triage questions, false-positive checks, escalation logic, impact, and recommended next action.
This difference is important for employability because hiring managers need evidence that I can reason through a security problem.
🔍 Investigation Questions
- Can this topic become a realistic mini-case?
- What evidence would I include?
- What logs or screenshots would make it credible?
- What decision did the analyst make?
- What false positives were considered?
- What control failed or worked?
- What should be improved after the incident?
🚨 Detection Opportunities
Portfolio-worthy detection/reporting ideas:
- password spray triage report
- phishing playbook
- security audit finding
- SIEM dashboard explanation
- control failure mapped to risk
- incident response timeline
Example artifact structure:
scenario
evidence
triage questions
detection logic
false positives
severity
response steps
lessons learned
🧭 MITRE ATT&CK Techniques
Possible ATT&CK mappings depend on the scenario selected:
- T1566 — Phishing
- T1110.003 — Password Spraying
- T1078 — Valid Accounts
- T1562 — Impair Defenses
- T1490 — Inhibit System Recovery
🗺 Visual Investigation Diagram
Course concept
↓
Realistic scenario
↓
Logs / evidence
↓
Triage workflow
↓
Detection or playbook
↓
Portfolio artifact
⚠ Challenges
The challenge is avoiding generic certificate summaries. Public blog posts should not read like course recaps only.
They need to show practical judgement: what I would check, what evidence matters, what mistakes I would avoid, and how I would respond.
📚 What I Learned
I learned that Course 2 gives useful SOC structure if I convert it properly. Risk management, SIEM, and playbooks are directly connected to analyst work.
➡ Next Steps
- Turn one Course 2 topic into a polished GitHub artifact
- Create a reusable incident triage template
- Write one playbook in a practical format
- Use risk/control/evidence language consistently
🧠 Reflection
This was a good checkpoint. I can now explain risk more professionally and connect it to SOC operations.
🧩 Lessons Learned
What worked
Focusing on artifacts instead of course completion.
What broke
Generic summaries do not prove skill.
Why it broke
Anyone can say they learned a concept; fewer people show how they would use it.
Fix / takeaway
Every blog post should include scenario, evidence, decision points, and defender value.
📈 Skill Progression Context
This supports my SOC analyst and detection engineering progression because it turns course material into investigation habits: identifying assets, reading evidence, asking better questions, and explaining security risk clearly.
Instead of treating the certificate as passive study, I am using each topic to build practical analyst thinking that can later become lab notes, detections, diagrams, or portfolio writeups.
😄 TL;DR
The certificate is learning. The portfolio is proof.
