Cybersecurity Risk & Compliance · The Practitioner Series

Understand the security governance system.

A practitioner-led professional library about how cybersecurity governance, risk, controls, assurance and compliance actually work together inside real organizations.

Certifications teach you the framework.
This series teaches you how to actually use it.
Explore the series
Book I digital edition · €19.99 · Protected PDF · Worldwide
Full wrap cover of Book I — The Foundations

The full wrap shows the intended physical edition. The digital edition is available first.

Book I — The Foundations

The foundation before the framework.

Book I begins with the organization itself: what matters, what creates exposure, who owns risk, who has authority to decide, how governance works, what controls are meant to achieve, what evidence proves, and how assurance and feedback keep the system alive.

01

Business & Security Context

Connect objectives, assets, information, services and protection needs.

02

Risk as Decision Logic

Move beyond register administration into ownership, appetite, treatment and accountable decisions.

03

Governance & Accountability

Understand authority, decision rights, escalation, challenge and governance forums.

04

Controls & Operations

See controls as mechanisms that must be designed, implemented, operated, tested and improved.

05

Evidence & Assurance

Distinguish evidence of activity from confidence that the intended outcome is actually achieved.

06

Compliance & Improvement

Place external requirements inside the governance system and close the loop through monitoring and feedback.

Book I — The Foundations front cover
Available now

Book I — The Foundations

First Edition · Version 1.0
For practitioners, aspiring GRC professionals, security leaders, auditors, risk professionals and readers who want to understand the system behind the frameworks.

  • 11 practitioner-focused chapters
  • Original visual governance models
  • Practical toolkits, diagnostics and decision structures
  • Glossary and standards/references
  • Individually protected digital PDF
  • Worldwide direct delivery
Digital Edition · €19.99
View contents
Checkout integration: the site is ready for a payment-provider checkout URL. Until that link is connected, the purchase button opens the direct-purchase information panel instead of accepting payment.
Inside Book I

Eleven chapters. One connected system.

Contents

  1. 01 — What Cybersecurity Risk & Compliance Actually Means
  2. 02 — Security Governance vs. Compliance
  3. 03 — Building a GRC Operating Model
  4. 04 — Security Strategy & Objectives
  5. 05 — Roles, Responsibilities & Accountability
  6. 06 — Policies, Standards, Procedures & Guidelines
  7. 07 — Risk Appetite & Risk Tolerance
  8. 08 — Governance Committees & Decision-Making
  9. 09 — Metrics, KPIs & KRIs
  10. 10 — Security Maturity
  11. 11 — Monitoring, Feedback and Continuous Improvement

What makes it different

The book does not treat governance, risk, compliance, controls and assurance as isolated disciplines. It progressively connects them into one feedback-driven security governance system.

The visual models become more interconnected as the reader progresses, culminating in the complete foundational model in Chapter 11.

The Practitioner Series

One system. A growing professional library.

Book I establishes the foundations. Future volumes will move deeper into the practical disciplines of building, operating, assessing and improving cybersecurity governance, risk and compliance.

AVAILABLE
Book I

The Foundations

Understand the security governance system and the relationships between context, risk, authority, controls, evidence, assurance, compliance and improvement.

IN DEVELOPMENT
Book II

Next Volume

The next book is being architected from the foundation established in Book I. Its final title and contents will be announced when ready.

The platform

The shop is only the first room.

nadyabiserova.com is designed to grow into a practitioner knowledge platform — not remain a one-book landing page.

📚

Library

Articles, models, practitioner notes and selected public resources.

🎓

Learning

Structured lessons, toolkits, scenarios and teaching material derived from the practitioner methodology.

🎬

Entertainment

Original creative and AI-assisted media projects, clearly separated from the professional learning catalogue.

🌍

Languages

English is live first. Russian and German editions are planned as professionally localized releases.

Nadya Biserova
About the author

Nadya Biserova

Independent Security Governance & GRC Leader and author of Cybersecurity Risk & Compliance — The Practitioner Series.

Her professional work spans security governance, enterprise risk, ISO 27001, TISAX, ISAE 3402, incident and crisis management, business continuity, IAM/PIAM governance, control assurance, audit readiness and security operating models.

The Practitioner Series turns real-world security governance experience into structured methods practitioners can understand and apply.

Connect on LinkedIn
Before you buy

Questions

Is this a certification-preparation book?

No. It explains the security governance system that sits before, behind and around individual frameworks and certifications.

What format do I receive?

A protected digital PDF edition for personal use. Purchase and delivery details are presented before payment.

Is a physical edition available?

The physical edition is planned and can be handled separately on demand. The full wrap displayed on this site represents the intended printed-book design.

Can organizations or universities buy copies?

Yes. Institutional, educational and multi-copy licensing can be discussed separately from individual digital purchases.

Are Russian and German editions available?

Not yet. English is the canonical first edition. Russian and German localizations are planned and will be released only after full editorial quality review.

Can I redistribute the PDF?

No. Individual digital copies are licensed to the purchaser for personal use. Separate arrangements can be discussed for organizational or educational use.

Book I is available now

Start with the foundations.

Understand the system before you try to operate the framework. Book I of Cybersecurity Risk & Compliance — The Practitioner Series is available worldwide as a protected digital edition.