WGU D486 DFN1 TASK 1:
GOVERNANCE, RISK, AND
COMPLIANCE | 2026 UPDATE | WITH
COMPLETE SOLUTIONS.
messages.downloaded_by
, A. Identify Security Gaps mn mn
After careful review of the Security Assessment Report (SAR) for Fielder Medical Center (FMC), mu
mn mn mn mn mn mn mn mn mn mn mn mn mn mn
ltiple gaps have been identified in the security framework of the organization. FMC has declared that
mn mn mn mn mn mn mn mn mn mn mn m n mn mn mn
it intends to meet compliance standards for both NIST SP 800-
mn mn mn mn mn mn mn mn mn mn mn
53r5, FISMA, and PCI DSS, and as such intends to hold themselves to the documented requirements
mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn
of each. Despite this, gaps have been located in their network to include endpoints notably lacking pr
mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn
otections and improper antivirus configuration, hardware and software being at End-Of-
mn mn mn mn mn mn mn mn mn mn
Life (EOL), and a lack of Multifactor Authentication (MFA) configured on their sensitive systems. All
mn mn mn mn mn mn mn mn mn mn mn mn mn mn
of this combined with lacking access controls, security policies, and other attributes leads to their net
mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn
work being insufficiently secure. The lack of these security controls on the FMC network is dangerou
mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn
s as it exposes PII to unauthorized access.
mn mn mn mn mn mn mn
B. Risk Identification, Ranking, and Justification mn mn mn mn
As requested, each of the controls identified in Section 3.3 of the SAR have been identified, ranked, an
mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn
d justification has been provided on why this should be remediated rather than accepted in their new
mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn
environment.
Control mn Control/Control mn Notes Rating and E mn mn Justification
Identifi mn Enhancement xplanation
er
AC-6 Least Privilege mn Least privilege mn High. With the principle of least
mn mn mn mn
needs to be mn mn Least privilege is mn mn privilege not being actively mn mn mn
employed a principle in
mn mn utilized, not only is this a mn mn mn mn mn
based on mn cybersecurity blatant violation of NIST mn mn mn
duties and mn that users have mn mn specifications (Goulding, mn
systems. the minimum mn 2024) but it is also an mn mn mn mn mn
required access mn avenue for drastic increases mn mn mn
and privileges to
mn mn to malicious activity and
mn mn mn
properly perform mn data breach potential. Due
mn mn mn
duties. to this, the potential risk is
mn mn mn mn mn
critically high and should mn mn mn
be resolved immediately.
mn mn
CA-5 Plan of Action and mn mn mn Develop and mn Moderate. While the use of a mn mn mn mn
Milestones track planned mn A POA&M for
mn mn POA&M is considered best mn mn mn
(POA&M) remediation FMC will be mn mn practice for security, there mn mn mn
actions. necessary to mn is no direct threat or risk to
mn mn mn mn mn mn
identify, rank, mn the environment by not
mn mn mn
and act on mn mn using one. The risks mn mn mn
remediation affiliated with a lack of the mn mn mn mn mn
efforts. POA&M are primarily mn mn
related to inconsistency. mn mn
Lacking such measures for mn mn mn
messages.downloaded_by
GOVERNANCE, RISK, AND
COMPLIANCE | 2026 UPDATE | WITH
COMPLETE SOLUTIONS.
messages.downloaded_by
, A. Identify Security Gaps mn mn
After careful review of the Security Assessment Report (SAR) for Fielder Medical Center (FMC), mu
mn mn mn mn mn mn mn mn mn mn mn mn mn mn
ltiple gaps have been identified in the security framework of the organization. FMC has declared that
mn mn mn mn mn mn mn mn mn mn mn m n mn mn mn
it intends to meet compliance standards for both NIST SP 800-
mn mn mn mn mn mn mn mn mn mn mn
53r5, FISMA, and PCI DSS, and as such intends to hold themselves to the documented requirements
mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn
of each. Despite this, gaps have been located in their network to include endpoints notably lacking pr
mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn
otections and improper antivirus configuration, hardware and software being at End-Of-
mn mn mn mn mn mn mn mn mn mn
Life (EOL), and a lack of Multifactor Authentication (MFA) configured on their sensitive systems. All
mn mn mn mn mn mn mn mn mn mn mn mn mn mn
of this combined with lacking access controls, security policies, and other attributes leads to their net
mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn
work being insufficiently secure. The lack of these security controls on the FMC network is dangerou
mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn
s as it exposes PII to unauthorized access.
mn mn mn mn mn mn mn
B. Risk Identification, Ranking, and Justification mn mn mn mn
As requested, each of the controls identified in Section 3.3 of the SAR have been identified, ranked, an
mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn
d justification has been provided on why this should be remediated rather than accepted in their new
mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn mn
environment.
Control mn Control/Control mn Notes Rating and E mn mn Justification
Identifi mn Enhancement xplanation
er
AC-6 Least Privilege mn Least privilege mn High. With the principle of least
mn mn mn mn
needs to be mn mn Least privilege is mn mn privilege not being actively mn mn mn
employed a principle in
mn mn utilized, not only is this a mn mn mn mn mn
based on mn cybersecurity blatant violation of NIST mn mn mn
duties and mn that users have mn mn specifications (Goulding, mn
systems. the minimum mn 2024) but it is also an mn mn mn mn mn
required access mn avenue for drastic increases mn mn mn
and privileges to
mn mn to malicious activity and
mn mn mn
properly perform mn data breach potential. Due
mn mn mn
duties. to this, the potential risk is
mn mn mn mn mn
critically high and should mn mn mn
be resolved immediately.
mn mn
CA-5 Plan of Action and mn mn mn Develop and mn Moderate. While the use of a mn mn mn mn
Milestones track planned mn A POA&M for
mn mn POA&M is considered best mn mn mn
(POA&M) remediation FMC will be mn mn practice for security, there mn mn mn
actions. necessary to mn is no direct threat or risk to
mn mn mn mn mn mn
identify, rank, mn the environment by not
mn mn mn
and act on mn mn using one. The risks mn mn mn
remediation affiliated with a lack of the mn mn mn mn mn
efforts. POA&M are primarily mn mn
related to inconsistency. mn mn
Lacking such measures for mn mn mn
messages.downloaded_by