Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 35 pages
Exam (elaborations)

WGU C845 Information Systems Security ACTUAL TASK 3 EXEMPLAR AND SOLUTION GUIDE 2026/2027 | VUN1 Task 3 | High-Pass Model Submission | Pass Guaranteed - A+ Graded

Document preview thumbnail
Preview 4 out of 35 pages

Pass WGU C845 VUN1 Task 3 on your first attempt with this high-pass model submission. This A+ Graded Complete Exemplar & Solution Guide 2026/2027 contains the ACTUAL TASK 3 SUBMISSION aligned with the official rubric. Features comprehensive coverage of evaluating and defending data security and system operations—including identified data protection risks (unencrypted databases, insecure file transfers), recommended cryptographic methods (application-level encryption, SFTP/HTTPS migration), and detailed justifications aligned with NIST and compliance frameworks. Backed by our Pass Guarantee. Download now.

Content preview

1




WGU C845 Information Systems Security
ACTUAL TASK 3 EXEMPLAR AND
SOLUTION GUIDE 2026/2027 | VUN1 Task
3 | High-Pass Model Submission | Pass
Guaranteed - A+ Graded

Scenario Selection

[Guidance: This exemplar uses a mid-sized healthcare organization: "Coastal Medical
Associates (CMA) - A multi-specialty medical practice with 150 providers, 450 staff, 6 clinic
locations, and an ambulatory surgery center." Healthcare organizations face stringent regulatory
requirements (HIPAA, HITECH) and sensitive protected health information (PHI), making this
an ideal scenario for demonstrating comprehensive security risk assessment and program
development. The structure is adaptable to any industry.]



Executive Summary

Coastal Medical Associates (CMA) has experienced significant growth over the past three years,
including the acquisition of two smaller practices, migration to a cloud-based electronic health
record (EHR) system, and expansion of telehealth services. While these changes have improved
patient care and operational efficiency, they have also increased the organization's attack
surface and introduced new security risks.

This security risk assessment and program development document provides a comprehensive
analysis of CMA's current security posture and presents a strategic roadmap for maturing
the information security program. The assessment identified 12 critical and high-risk findings
across people, process, and technology domains, with the most significant risks related to:

Incomplete access controls and lack of multi-factor authentication (MFA) for remote access

Insufficient security awareness training and lack of phishing simulations

No formal incident response plan or testing

Gaps in vendor risk management for cloud service providers

,2


Incomplete security policies and lack of policy enforcement

The proposed security program includes the appointment of a dedicated Information Security
Officer (ISO), implementation of 30 security controls mapped to NIST SP 800-53, and
development of 5 core security policies. This plan is projected to reduce CMA's residual risk
exposure by approximately 55% over 18 months and achieve HIPAA Security Rule compliance
maturity consistent with OCR expectations.



A1: Organizational Profile and Scope

[Guidance: This section requires a detailed description of your chosen organization. Include
size, structure, industry, regulatory environment, and key assets. This context drives all
subsequent risk and control decisions.]

A1a: Organization Overview

Coastal Medical Associates (CMA) is a multi-specialty medical practice headquartered in San
Diego, California. Founded in 1985, CMA has grown to serve approximately 120,000 patients
annually with 150 physicians and advanced practice providers across 12 specialties, including
primary care, cardiology, orthopedics, gastroenterology, and general surgery.

Key Statistics:

Employees: 450 (including clinical and administrative staff)

Locations: 6 outpatient clinics and 1 ambulatory surgery center (ASC)

Annual patient encounters: 450,000

Annual revenue: $85 million

Mission: "To provide compassionate, high-quality, patient-centered healthcare to the San Diego
community."
Vision: "To be the region's most trusted and innovative multi-specialty medical group."

A1b: Regulatory Environment

CMA operates under oversight from:

Department of Health and Human Services (HHS)/OCR: HIPAA Privacy, Security, and
Breach Notification Rules

Centers for Medicare & Medicaid Services (CMS): Medicare and Medicaid compliance

California Department of Public Health: State licensing requirements

California Consumer Privacy Act (CCPA): Patient data privacy requirements

,3


The Joint Commission: ASC accreditation requirements

DEA: Controlled substance prescribing and tracking

A1c: Key Information Assets

Table

Copy

Asset Class Specific Assets Sensitivity Location


Epic (cloud-hosted) - Contains full
patient records including
Electronic demographics, medical history,
Health Record medications, lab results, clinical Cloud (vendor-
(EHR) notes CRITICAL hosted)


Protected Health EHR, practice
Information Individually identifiable patient management,
(PHI) data across all systems CRITICAL billing, archival


Practice
Management Scheduling, registration, insurance On-premise
System verification, billing HIGH servers


Financial Accounts payable/receivable, On-premise and
Systems payroll, general ledger HIGH cloud


Email and Microsoft 365 (Exchange, Teams,
Collaboration SharePoint) MODERATE Cloud


Imaging systems (PACS), lab
Clinical Devices analyzers, vital sign monitors MODERATE On-premise


Telehealth Doxy.me (HIPAA-compliant video
Platform visits) HIGH Cloud

, 4



Asset Class Specific Assets Sensitivity Location


De-identified clinical data for Cloud and on-
Research Data research studies MODERATE premise



A2: Risk Assessment Methodology

[Guidance: Describe your risk assessment approach. This exemplar uses a hybrid
qualitative/quantitative approach based on NIST SP 800-30.]

A2a: Risk Assessment Framework
This risk assessment follows the methodology outlined in NIST Special Publication 800-30,
Revision 1, "Guide for Conducting Risk Assessments." The process includes:

Asset Identification: Critical assets were identified through interviews with department heads
and review of CMA's technology inventory.

Threat Identification: Potential threat sources and events were identified using threat
intelligence sources (CISA, HHS OCR breach reports, industry threat feeds).

Vulnerability Identification: Vulnerabilities were identified through security control
assessments, policy reviews, interviews, and review of past security incidents.

Likelihood Determination: Likelihood was assessed based on threat capability, intent, and
vulnerability prevalence.

Impact Determination: Impact was assessed based on potential harm to patient safety, financial
loss, regulatory penalties, and reputational damage.

Risk Calculation: Risk was calculated as a function of likelihood and impact using a 5x5 risk
matrix.

A2b: Risk Scoring Methodology
Table

Copy

Likelihood Level Description Score


Very High Almost certain to occur (multiple times per year) 5

Document information

Uploaded on
February 13, 2026
Number of pages
35
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAACTUALEXAMS
3.5
(157)
Sold
1221
Followers
208
Items
8733
Last sold
11 hours ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions