Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Other

WGU D485 DGN2 TASK 1 Cloud Security Implementation Plan Latest Update with Complete Assignment! ALREADY RATED A+

Rating
3.0
(1)
Sold
5
Pages
26
Uploaded on
13-01-2025
Written in
2024/2025

WGU D485 DGN2 TASK 1 Cloud Security Implementation Plan Latest Update with Complete Assignment Answers

Content preview

WGU D485 DGN2 TASK 1 Cloud Security Implementation Plan Latest Update with Complete
Assignment Answers




WGU D485 DGN2 TASK 1 Cloud Security
Implementation Plan Latest Update with
Complete Assignment Answers

,WGU D485 DGN2 TASK 1 Cloud Security Implementation Plan Latest Update with Complete
Assignment Answers




D485 Cloud Security
DGN2 Task1: Cloud Security Implementation Plan
September 9, 2024

A. Executive Summary

SWBTL LLC, a nationwide logistics company, is transitioning to Microsoft’s Azure cloud
environment due to costs, poor server availability, and cybersecurity concerns with its leased
data centers. The consultant hired to start and finish the migration abruptly quit, leading to
serious concern about the migration process. SWBTL's main concerns are:
• Compliance.
• Encryption of data at rest and in transit.
• Proper role-based access controls.
• The integrity of the backup and recovery systems.

SWBTL is also concerned that the cloud instance may not comply with regulatory compliance,
leaving the company vulnerable to exploitation by nation-state actors or cybercriminals. The
company must comply with the Federal Information Security Modernization Act (FISMA) and
the Payment Card Industry Data Security Standard (PCI DSS) to continue servicing its contracts.
This includes contracts with the United States Government (USG). An immediate action plan is
needed to mitigate risks and ensure the company's security posture aligns with industry
regulations and laws.

B. Proposed Azure Cloud Solution

The recommended service model for SWBTL LLC consists of implementing Microsoft's Azure
Government Infrastructure as a Service (IaaS) solution. This solution provides the company with
a Federal Risk and Authorization Management Program (FedRAMP) authorized product that is
also Department of Defense (DoD) Impact Level (IL) 5 authorized, which was approved by the
Defense Information Systems Agency (DISA). This model allows for the deployment and
control of multiple operating systems, virtual machines, and custom applications supported by
computer storage and network resources on demand. IaaS also supports on-demand scalability
and integration with existing Active Directory infrastructure.

Regulatory Compliance:

SWBTL must comply with FISMA and PCI DSS. FISMA requires federal agencies and
contractors to maintain strong cybersecurity practices, including continuous monitoring and
secure information handling. PCI DSS focuses on securing payment card information, mandating
encryption, access control, and regular vulnerability assessments.

, WGU D485 DGN2 TASK 1 Cloud Security Implementation Plan Latest Update with Complete
Assignment Answers




Security Benefits and Challenges:

Benefits:

Transitioning to Azure's Government IaaS offers the following benefits.

• Enhanced scalability.
• Built-in encryption tools.
• Azure’s compliance features
• Azure security tools such as Security Center and Key Vault
• Encryption Management

Challenges:

The primary challenges include the following.

• Managing access control to prevent internal data breaches.
• Ensuring proper encryption policies are applied across departments.
• Ensuring daily backup and recovery policies align with business objectives.
• Misconfigured security controls.

C. Role-Based Access Controls (RBAC)

RBAC Configuration:

1. Separation of Resource Groups: Each department—Marketing, Accounting, and IT—
should have its own Azure Resource Group. Access should be restricted to departmental
resources only, preventing cross-department data visibility.
2. Principle of Least Privilege: RBAC should be aligned so only department users can
access their resources. For example, only accounting users should have "Key Vault
Contributor" access to the Accounting Key Vault.
3. Scoped Administrative Access: Administrative roles should be clearly defined and
scoped to prevent excessive permissions across departments. For instance, marketing
administrators should not have access to IT systems.

The following screenshots show the steps to configure RBAC for the IT, Accounting, and
Marketing departments. I have streamlined the last two departments, showing the completed
configuration to shorten this document.

Document information

Uploaded on
January 13, 2025
Number of pages
26
Written in
2024/2025
Type
OTHER
Person
Unknown

Subjects

$12.89
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Reviews from verified buyers

Showing all reviews
7 months ago

Nice input, but the screenshot is not clear at all.

3.0

1 reviews

5
0
4
0
3
1
2
0
1
0
Trustworthy reviews on Stuvia

All reviews are made by real Stuvia users after verified purchases.

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
AcademicTestBankandExam Teachme2-tutor
View profile
Follow You need to be logged in order to follow users or courses
Sold
61
Member since
4 year
Number of followers
0
Documents
435
Last sold
1 day ago

Welcome to AcademicTestBankandExam, your go-to destination for high-quality academic exams and test banks. We specialize in providing carefully curated collections of exam-style questions, chapter-wise test banks, and full-length mock exams across a wide range of subjects. Whether you're a student preparing for finals, a tutor looking for reliable practice materials, or an educator in need of assessment tools, our resources are designed to help you succeed. Each test bank is developed by experienced educators and aligned with current curriculum standards to ensure relevance and accuracy. With clear solutions and detailed explanations, our goal is to make exam preparation more effective, efficient, and stress-free.

Read more Read less
4.3

12 reviews

5
8
4
1
3
2
2
1
1
0

Trending documents

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions