100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Other

D489 DEN1 Task 1: Cybersecurity Management Plan

Rating
-
Sold
1
Pages
8
Uploaded on
25-06-2025
Written in
2024/2025

This comprehensive cybersecurity management plan addresses the major gaps and vulnerabilities identified in the fictional organization "SAGE Books." The document includes detailed mitigation strategies aligned with PCI DSS and GDPR compliance, security awareness training, role-based responsibilities, and policy development. It outlines improvements needed in incident response, business continuity planning (BCP), and security governance. Students will find detailed examples of policy frameworks, security threat analysis, recovery time objectives (RTOs), and NIST-aligned procedures. This is an ideal reference for WGU D489 students preparing DEN1 Task 1 or anyone looking to understand practical applications of compliance, risk mitigation, and cybersecurity planning.

Show more Read less









Whoops! We can’t load your doc right now. Try again or contact support.

Document information

Uploaded on
June 25, 2025
Number of pages
8
Written in
2024/2025
Type
Other
Person
Unknown

Subjects

Content preview

DEN1 TASK 1:
CYBERSECURITY
MANAGEMENT PLAN
Dorian Stanfield




6/25/2025
Cybersecurity Management - D489

, A. Summary of Gaps
Per the Independent Security Report, SAGE Books has numerous critical security gaps
within its plaguing its security framework. The organization's present security infrastructure does
not align with industry standards or best practices. The infrastructure also lacks crucial policies
covering AUP, MDM, secrets management, and protection of personally identifiable information
(PII). Additionally, SAGE Books is also noncompliant with PCI DSS, lacking formalized
policies and procedures necessary for managing payment card data securely.
Additional deficiencies exist regarding GDPR compliance. Presently there are no
proactive measures in place to safeguard the personal data of EU citizens, thus failing to meet
GDPR requirements. The organization's security proficiency is also lacking in sufficiency. The
existing team lacks key expert subject matter personnel who are essential for effectively
managing, implementing, and enforcing regulatory compliance.
Security awareness training at SAGE Books is insufficient and is not aligned with
recommended PCI DSS and NIST best practices. Additionally, the Incident Response Plan is
inadequate, lacks clearly defined roles and responsibilities, incident detection handling and
analysis. Lastly, the standing Business Continuity Plan is ineffective, as it fails to thoroughly
address prospective natural disaster scenarios and it also lacks comprehensive recovery
strategies.



B. Mitigation Strategies
To address the security gaps identified in the security report, SAGE Books should employ
several vital mitigation strategies. For starters, the organization must create a comprehensive
security policy aligned with PCI DSS and GDPR best practices. This involves a clear
understanding of the regulatory obligations related to customer data handling. It also involves the
conduction of thorough risk assessments focused on the fortification of cardholders and EU
citizen data, establishing detailed AUP policies, MDM, secure passwords, and personal
identifiable information protection.
Guaranteeing PCI DSS compliance requires numerous actions. SAGE Books must secure
its network through firewalls, ACL’s, security devices, and endpoint protection software. The
organization should also implement system hardening practices, implement robust encryption
methods, maintain asset inventories, and safeguard cardholder data during data in transit.
Moreover, deploying, auditing, and updating antivirus software regularly, alongside instituting a
vulnerability management process, will aid in the identification and remediation of potential
threats swiftly. Access to sensitive information must be strictly regulated based on the principle
of least privilege, employing MFA, and strong cryptographic measures. Systematic scans and
$17.99
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached

Get to know the seller
Seller avatar
dorianstanfield

Get to know the seller

Seller avatar
dorianstanfield Western Governers University
View profile
Follow You need to be logged in order to follow users or courses
Sold
3
Member since
1 year
Number of followers
0
Documents
4
Last sold
3 months ago

0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions