SECURITY IMPLEMENTATION PLAN
COMPLETE SOLUTION | LATEST 2026/2027
UPDATE | A+ GRADED | 100% PASS
MASTER STUDY GUIDE SUMMARY
Course: WGU D485 DGN2 – Cloud Security Implementation Plan
Task: Task 1 – Cloud Security Implementation Plan
Key Topics: Shared Responsibility Model, Identity and Access Management
(IAM), Multi-Factor Authentication (MFA), Encryption at Rest and in Transit, Key
Management (KMS), Network Security (VPC, Security Groups, NACLs), Web
Application Firewall (WAF), DDoS Protection, Security Monitoring (CloudWatch,
CloudTrail, GuardDuty), Incident Response, Compliance (PCI DSS, HIPAA,
GDPR), Cloud-Native Services, Zero Trust Architecture
Key AWS Services: IAM, KMS, S3, VPC, CloudTrail, CloudWatch, GuardDuty,
Inspector, Config, Security Hub, Shield, WAF, Macie, Secrets Manager
Key Azure Services: Azure AD, Azure Security Center, Azure Sentinel, Azure
Policy, Azure Key Vault
,SECTION 1: EXECUTIVE SUMMARY
SWBTL LLC is a nationwide logistics company that began as a local document and delivery
service in 1977. Since then, they have grown to provide nationwide services and employ over
2,000 professionals. The current IT model spans across four leased data centers in the United
States. Because of increased costs, service interruptions, and cybersecurity concerns, the
Microsoft Azure cloud deployment was implemented. However, during implementation, the
consultant responsible for the migration suddenly left, leaving the company in an insecure
position.
SWBTL LLC's IT infrastructure has several security challenges, including inadequate data
protection, unstable access controls, and noncompliance with FISMA and PCI DSS. These
gaps create major risks since the company handles sensitive government and payment card
data.
Critical Improvements Needed:
Implementing RBAC (Role-Based Access Control)
Enabling encryption and backup configurations
Achieving alignment with FISMA, PCI DSS, and NIST 800-53 standards
The company has an upcoming NIST SP 800-53 assessment and must maintain compliance
with FISMA as well as PCI DSS standards because they hold government contracts and conduct
card payment transactions daily.
SECTION 2: PROPOSED SECURE AZURE CLOUD SOLUTION
Cloud Model: Infrastructure-as-a-Service (IaaS)
Aspect Details
Full Control Full control over VMs, OS, and configurations
Security Tools Integrated security and compliance tools
Justification Better suited than PaaS/SaaS for custom security management
Regulatory Compliance Frameworks
,Framework Description Key Requirements
Federal Information Security Continuous monitoring, RBAC,
FISMA
Modernization Act encryption
Payment Card Industry Data Cardholder data encryption, secure
PCI DSS
Security Standard access
NIST 800- Identity management, data protection,
Security & Privacy Controls
53 system availability
Benefits & Challenges
Benefits Challenges
Built-in encryption, patching, centralized monitoring Misconfiguration risks
Scalable resources Ongoing management
Simplified compliance alignment Migration complexity
SECTION 3: ROLE-BASED ACCESS CONTROL (RBAC)
Current Issue
Excessive access permissions across departments violate the principle of least privilege. Users
from multiple departments have been able to access data and assets that belong to other groups,
which they should not have access to.
Recommendations
Recommendation Implementation
Limit Access by Department Assign permissions by resource group
Just-In-Time Access (JIT) Temporary access for specific tasks
, Recommendation Implementation
Role-Specific Permissions Align roles to job responsibilities
Implementation Details
Each department must have its own Azure Resource Group
Each department must have its own Azure Key Vault with the principle of least privilege
enabled
Strict rules must maintain the access capabilities of each department
SECTION 4: AZURE KEY VAULT & ENCRYPTION
Best Practices Implemented
Feature Purpose
Soft Delete & Purge Protection Prevents accidental deletions
Managed Identities Secure app authentication without stored secrets
Encryption Approach
Type Implementation
Data at Rest Use Key Vault with Disk Encryption + SQL Database
Data in Transit Enforce TLS for secure connections
Business Requirement
Data should be encrypted in use and at rest. Only users within that department should be
capable of accessing the encrypted data via their respective Key Vault.
SECTION 5: BACKUP POLICY CONFIGURATION