Implementation Plan
Andre Gary
Student ID#:
000717518 D485
DGN2 — DGN2 TASK 1: CLOUD SECURITY IMPLEMENTATION
PLAN
A: EXECUTIVE SUMMARY:
Executive Summary: Current Security Environment Overview for
SWBTL LLC
SWBTL LLC, a rapidly growing logistics and document delivery
company, has transitioned to the Microsoft Azure cloud environment to
address several operational challenges, including regulatory compliance,
cybersecurity concerns, and logistical inefficiencies. As the company
expands its cloud footprint, it faces several critical security and
operational challenges that need immediate attention to ensure a secure,
compliant, and resilient cloud environment.
Key Security and Compliance Challenges
1. SWBTL LLC must maintain compliance with FISMA, PCI DSS,
and NIST SP 800-53 to protect sensitive data and maintain federal
contracts. All cloud configurations and operations should align
with these stringent requirements.
• SWBTL LLC must comply with strict regulations such
as the Federal Information Security Modernization Act
(FISMA) and the Payment Card Industry Data Security
, Standard (PCI DSS). These regulations mandate
stringent security controls and regular assessments to
protect sensitive data, especially given the company's
contracts with the U.S. government and involvement in
processing card transactions. (FISMA, 2014)
• The organization is preparing for an upcoming NIST SP
800-53 assessment, which underscores the importance of
maintaining robust security controls across all systems,
including those in the cloud environment. (NIST, 2013)
2. Data and Access Control Issues:
• Post-transition issues have emerged, with users reportedly
accessing data and assets belonging to other teams,
indicating a breakdown in access controls and the
principle of least privilege.
• There are concerns about the security and isolation of
departmental resources within Azure. The company's
current setup lacks clear separation between departments,
increasing the risk of unauthorized access and data
leakage.
3. Backup and Recovery Failures:
, • IT administrators have been unable to verify file and
system backups since the cloud transition began,
potentially jeopardizing the integrity and availability of
critical data.
• The company must adhere to a strict Recovery Point
Objective (RPO) of 1 day and a Recovery Time Objective
(RTO) of 36 hours. However, the current backup and
recovery configurations appear inadequate, raising
concerns about the company's ability to meet these
objectives in the event of a disaster.
4. Cloud Security Architecture:
• SWBTL LLC's cloud environment requires a robust
security architecture that includes encryption for data-at-
rest and data-in-transit, adherence to least privilege
principles, and secure backup procedures.
• The company also needs to implement proper tagging
and resource management strategies to enhance visibility
and control over cloud assets, ensuring that each
department's resources are properly isolated and
managed.
B: PROPOSED COURSE OF ACTION:
Business Requirements for a Secure Cloud Environment
To address these challenges, SWBTL LLC must focus on the following
priorities:
1. SWBTL LLC must maintain compliance with FISMA, PCI DSS, and
NIST SP 800-53 to protect sensitive data and maintain federal
contracts. All cloud configurations and operations should align with
these stringent requirements.
2. Each department (Accounting, Marketing, and IT) must have its own