k k k k k k
Implementation Plan Latest Update With
k k k k k
kComplete Solution k
This document contains:
kgv kgv
WGU D485 kgv
WGU D485 DGN2 TASK 1
kgv kgv kgv kgv
Cloud Security Implementation Plan
kgv kgv kgv
Latest Update with complete solution
kgv kgv kgv kgv
, WGU D485 DGN2 TASK 1: Cloud Security ky ky ky ky ky ky
Implementation Plan Latest Update With
ky ky ky ky ky
Complete Solution
ky ky
DGN2 TASK 1: Cloud Security Implementation Plan College of Information
k k k k k k k k k
Technology, Western Governors University
k k k k
Cloud Security implementation Plan k k k
A. Executive Summary k
With their rapid growth, and mounting cybersecurity concerns, SWBTL LLC has begun a
k k k k k k k k k k k k
migration to the Microsoft Azure cloud environment. The consultant who was heading up the
k k k k k k k k k k k k k k
migration has unexpectedly left the project to work for another company, and in doing so has left
k k k k k k k k k k k k k k k k k
the Microsoft Azure environment in need of serious repair. After viewing the company overview
k k k k k k k k k k k k k k
and business requirements, I have identified several areas in which the business requirements are
k k k k k k k k k k k k k k
not in sync with the current security infrastructure.
k k k k k k k k
1. Role Based Access Control (RBAC): SWBTL LLC’s business requirements document
k k k k k k k k k
k mentions that each department should have its own resource group, and these resource
k k k k k k k k k k k k
k groups should apply the principal of least privilege. That is where role- based access
k k k k k k k k k k k k k
k controls come in. The current cloud environment does not utilize role- based access
k k k k k k k k k k k k
k controls, so it is difficult to apply the principal of least privilege within the
k k k k k k k k k k k k k
k environment. This causes serious security concerns. k k k k k
, 2. Compliance: Due to the frequent payment card transactions that the company processes
k k k k k k k k k k k
daily, and the contracts that they have with the United States Government, SWBTL
k k k k k k k k k k k k k
k LLC must remain in compliance with multiple regulations. The Payment Card Industry
k k k k k k k k k k k
Data Security Standard DSS, or PCI DSS, and the Federal Information Security
k k k k k k k k k k k k
Modernization Act, better known as FISMA. The current Cloud environment does not
k k k k k k k k k k k k
appear to be in compliance with these regulations.
k k k k k k k k
3. Azure Key Vaults and Encryption: The business requirements document states that
k k k k k k k k k k
the cloud should incorporate data at rest and data in transit encryption. This not only
k k k k k k k k k k k k k k k
helps keep the data secure, but it helps keep SWBTL LLC compliant with the
k k k k k k k k k k k k k
relevant standards and regulations. Currently, the Company’s Cloud infrastructure
k k k k k k k k k
does not appear to be taking advantage of the Azure Key Vaults tool.
k k k k k k k k k k k k k
4. Vulnerability Scans: The scope of vulnerability scans and vulnerability management
k k k k k k k k k
in general should be better defined in the Microsoft Azure environment.
k k k k k k k k k k k
5. Backups: The business requirements document has specific requirements regarding
k k k k k k k k
backup frequency, location, times and for how long the backups should be kept.
k k k k k k k k k k k k k
There are no configurations present in the current environment that support these
k k k k k k k k k k k k
requirements.
k
SWBTL LLC’s Azure environment in its current form is seriously lacking the necessary
k k k k k k k k k k k k
configurations and policies to not only be compliant with regulations, but also to keep data
k k k k k k k k k k k k k k k
secure. There are several critical actions that need to be taken in order to strengthen the
k k k k k k k k k k k k k k k k
company’s cloud environment and bring it up to industry security standards.
k k k k k k k k k k k
, B. Proposed Course Of Action k k k
Service Model – k k
SWBTL LLC should take immediate action to bring its Microsoft Azure environment into line with
k k k k k k k k k k k k k k
the business overview and requirements document. The service model should have the capability
k k k k k k k k k k k k k
to be incompliance with all applicable regulations and standards set out in the
k k k k k k k k k k k k k
document. I am recommending that SWBTL LLC transitions into the Azure Government
k k k k k k k k k k k
k Infrastructure as a Service (IaaS) model. This model would fulfil compliance requirements and
k k k k k k k k k k k k
SWBTL LLC should qualify as a government contractor.
k k k k k k k k
Applicable Regulatory Directives - k k k
Payment Card Industry Data Security Standard (PCI DSS): The Payment Card Industry Data
k k k k k k k k k k k k
Security Standard (PCI DSS) is a set of requirements intended to ensure that all companies that
k k k k k k k k k k k k k k k k
process, store, or transmit credit card information maintain a secure environment (de Groot,
k k k k k k k k k k k k k
2024). Because SWBTL LLC processes a large amount of payment card transactions daily, it is
k k k k k k k k k k k k k k k
imperative that they adhere to the standards set out in PCI DSS. These standards include 12 points
k k k k k k k k k k k k k k k k k
that involve a variety of protections including requirements on: firewalls, passwords, encryption,
k k k k k k k k k k k k
antivirus protection, physical access and vulnerability scanning.
k k k k k k k
Federal Information Security Modernization Act (FISMA): Because SWBTL LLC maintains a
k k k k k k k k k k
number of contracts with the United States government, the company overview and business
k k k k k k k k k k k k k
requirements document states that SWBTL LLC must maintain compliance with the Federal
k k k k k k k k k k k k
k Information SecurityModernization Act, which essentially outlines how to secure federal data.
k k k k k k k k k k k
FISMA has requirements regarding monitoring, conducting risk assessments, security controls,
k k k k k k k k k k
maintain a security plan, data categorization and maintaining an IT inventory (Solarwinds,
k k k k k k k k k k k k
2023). Again, a transition to Azure Government Infrastructure as a service (IaaS) should be a
k k k k k k k k k k k k k k k
perfect fit given the business requirements.
k k k k k k