D485 Cloud Security
DGN2 Task1: Cloud Security Implementation Plan
September 9, 2024
A. Executive Summary
SWBTL LLC, a nationwide logistics company, is transitioning to Microsoft’s Azure cloud
environment due to costs, poor server availability, and cybersecurity concerns with its leased
data centers. The consultant hired to start and finish the migration abruptly quit, leading to
serious concern about the migration process. SWBTL's main concerns are:
• Compliance.
• Encryption of data at rest and in transit.
• Proper role-based access controls.
, • The integrity of the backup and recovery systems.
SWBTL is also concerned that the cloud instance may not comply with regulatory
compliance, leaving the company vulnerable to exploitation by nation-state actors or
cybercriminals. The company must comply with the Federal Information Security
Modernization Act (FISMA) and the Payment Card Industry Data Security Standard (PCI DSS)
to continue servicing its contracts. This includes contracts with the United States
Government (USG). An immediate action plan is needed to mitigate risks and ensure the
company's security posture aligns with industry regulations and laws.
B. Proposed Azure Cloud Solution
The recommended service model for SWBTL LLC consists of implementing Microsoft's Azure
Government Infrastructure as a Service (IaaS) solution. This solution provides the company
with a Federal Risk and Authorization Management Program (FedRAMP) authorized product
that is also Department of Defense (DoD) Impact Level (IL) 5 authorized, which was
approved by the Defense Information Systems Agency (DISA). This model allows for the
deployment and control of multiple operating systems, virtual machines, and custom
applications supported by computer storage and network resources on demand. IaaS also
supports on-demand scalability and integration with existing Active Directory infrastructure.
Regulatory Compliance:
SWBTL must comply with FISMA and PCI DSS. FISMA requires federal agencies and
contractors to maintain strong cybersecurity practices, including continuous monitoring and
secure information handling. PCI DSS focuses on securing payment card information,
mandating encryption, access control, and regular vulnerability assessments.
DGN2 Task1: Cloud Security Implementation Plan
September 9, 2024
A. Executive Summary
SWBTL LLC, a nationwide logistics company, is transitioning to Microsoft’s Azure cloud
environment due to costs, poor server availability, and cybersecurity concerns with its leased
data centers. The consultant hired to start and finish the migration abruptly quit, leading to
serious concern about the migration process. SWBTL's main concerns are:
• Compliance.
• Encryption of data at rest and in transit.
• Proper role-based access controls.
, • The integrity of the backup and recovery systems.
SWBTL is also concerned that the cloud instance may not comply with regulatory
compliance, leaving the company vulnerable to exploitation by nation-state actors or
cybercriminals. The company must comply with the Federal Information Security
Modernization Act (FISMA) and the Payment Card Industry Data Security Standard (PCI DSS)
to continue servicing its contracts. This includes contracts with the United States
Government (USG). An immediate action plan is needed to mitigate risks and ensure the
company's security posture aligns with industry regulations and laws.
B. Proposed Azure Cloud Solution
The recommended service model for SWBTL LLC consists of implementing Microsoft's Azure
Government Infrastructure as a Service (IaaS) solution. This solution provides the company
with a Federal Risk and Authorization Management Program (FedRAMP) authorized product
that is also Department of Defense (DoD) Impact Level (IL) 5 authorized, which was
approved by the Defense Information Systems Agency (DISA). This model allows for the
deployment and control of multiple operating systems, virtual machines, and custom
applications supported by computer storage and network resources on demand. IaaS also
supports on-demand scalability and integration with existing Active Directory infrastructure.
Regulatory Compliance:
SWBTL must comply with FISMA and PCI DSS. FISMA requires federal agencies and
contractors to maintain strong cybersecurity practices, including continuous monitoring and
secure information handling. PCI DSS focuses on securing payment card information,
mandating encryption, access control, and regular vulnerability assessments.