100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Other

D489 Cybersecurity Management

Rating
-
Sold
1
Pages
21
Uploaded on
09-09-2025
Written in
2025/2026

D489 Cybersecurity Management











Whoops! We can’t load your doc right now. Try again or contact support.

Document information

Uploaded on
September 9, 2025
Number of pages
21
Written in
2025/2026
Type
Other
Person
Unknown

Subjects

Content preview

Cybersecurity Management




Cybersecurity Management

Western Governors University




2025

, Cybersecurity Management




A. Summary of the gaps that currently exist Sage’s in “Independent Security Report.”

Sage’s “Independent Security Report”, or aforementioned “ISR,” revealed considerable

gaps in their cybersecurity framework. The gaps will be discussed below.

1. Business Continuity Plan

Sage’s BCP does not encompass the minute details that are important to continue a business in

the event of a natural disaster and no recovery strategies are in place.

2. Inadequate Security Awareness Plan

Sage’s cybersecurity awareness plan is not compliant with the industry’s best practices and

standards in regard to NIST and PCI Requirement 12.6.

3. Inadequate Incident Response Plan

Sage’s IRP does not define roles and responsibilities of team members. The IRP also has

significant shortcomings regarding efficient incident handling and analysis.

4. Inadequate Information Security Team

Sage’s information security team is poorly staffed and is lacking key team members that are

necessary to provide the company with effective security compliance and regulatory efforts.

5. Noncompliance with PCI-DSS and GDPR

Sage currently does not have policies and procedures that would enable it to become and

maintain compliance with two very important global industry standards: PCI-DSS and GDPR.

, Cybersecurity Management




B. Mitigation strategies that were developed to address the gaps identified in Sage’s

“Independent Security Report,” ensuring compliance with PCI DSS and GDPR.




The gaps that were identified in Sage’s ISR were the lack of an adequate business

continuity plan, security awareness plan, incident response plan, and information security team,

leading to non-compliance with the security principles and standards of GDPR and PCI-DSS.

Compliance with these two important standards is essential for international businesses.

The following sections will include mitigation strategies to be implemented to address the gaps

and achieve compliance with the industry’s standards.

1. Business Continuity Plan

The mitigation strategy that was developed to address Sage’s BCP and ensure compliance with

GDPR and PCI-DSS was done by developing a thorough and finely detailed recovery plan that

addresses natural disasters. The new mitigation strategy will be used to ensure European data and

cardholder data protection and quickly recover the systems that store or use this data. The BCP

mitigation strategy will include a risk assessment, business impact assessment, emergency

response plan, communication plan, and backup recovery plan. Editing the business continuity

plan to include these attuned details can ensure that the business can withstand any disaster and

is properly prepared for any unforeseen event that could possibly disrupt the business’s

operations.
$20.49
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached

Get to know the seller
Seller avatar
danicalee

Get to know the seller

Seller avatar
danicalee Western Governors University
View profile
Follow You need to be logged in order to follow users or courses
Sold
3
Member since
3 months
Number of followers
0
Documents
3
Last sold
1 week ago

0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions