JoAnn N. Gerena, CISM, M.A.
Cybersecurity Governance • GRC • Process Transformation
I help organizations transform complex cybersecurity and compliance requirements into scalable governance programs that improve security, streamline operations, and strengthen audit readiness.
Applying Responsible AI
I used AI to improve efficiency while preserving human accountability, data protection, and regulatory compliance.
Human Judgement
Define the problem, requirements, context, and intended outcome.








AI Assisstance
Human Validation
Authorized Decision
Analyze, organize, compare, and develop draft content from approved information.
Verify accuracy, sources, completeness, risk, and regulatory alignment.
Approve and implement through established governance and change-control processes.
AI accelerates the work. Human expertise remains accountable for the outcome.
01 Requirements & Control Analysis
I use AI to structure and compare regulatory requirements, identify changes, organize control obligations, and highlight areas requiring further review.
Example: Framework transition → requirement comparison → potential gaps → human validation
02 Documentation & Knowledge Development
I use AI to accelerate first drafts of procedures, implementation guidance, checklists, job aids, training materials, and other compliance documentation.
Example: Process requirements → structured draft → SME review → approved resource.
03 Process & Compliance
I use AI to analyze existing workflows, identify repetitive activities, organize information, and develop standardized approaches that improve consistency and efficiency.
Example: Existing process → analyze friction → proposed improvement → governance review.
04 Structured Prompt Engineering
I use clear context, constraints, source boundaries, output requirements, and validation criteria to produce more reliable and useful AI-assisted work.
Example:
Task: Analyze the provided control requirement.
Source boundary: Use only the information provided.
Output: Identify the requirement, responsible function, implementation considerations, potential evidence, and validation method.
Constraint: Do not assume missing information. Flag gaps for human review.
Effective prompting isn’t just asking a better question—it’s defining the boundaries for a more reliable result.
From intimidated to empowered—your technology journey starts here.
© 2025-2026. All rights reserved.


