Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 12 pages
Other

WGU C845: Task 1 MANAGING SECURITY OPERATIONS AND ACCESS CONTROLS – 2026 update

Document preview thumbnail
Preview 2 out of 12 pages

WGU C845: Task 1 MANAGING SECURITY OPERATIONS AND ACCESS CONTROLS – 2026 update

Content preview

MANAGING SECURITY OPERATIONS AND ACCESS CONTROLS – C845

Honey Honey
C845 Task 1
INFORMATION SYSTEMS SECURITY
A. Apply an access control model to the provided user role matrix and access control policies
in the attached "Security Operations Artifact" by doing the following:

A1: ACCESS CONTROL EXPLANATION
The access control model most appropriate for this organization is Role-Based Access Control (RBAC),
as it aligns directly with both the user role matrix structure and the organization’s stated access control
policies. RBAC is based on assigning permissions to roles rather than directly to individual users and
then assigning users to those roles based on their job responsibilities. This model is already implicitly
reflected in the organization’s environment, where access is largely determined by job titles such as
finance manager, HR coordinator, and IT administrator, and where systems and privilege levels are
organized around those roles. By organizing access in this way, RBAC supports scalability, consistency,
and simplified administration across departments.

The principle of least privilege, a core component of RBAC, is partially implemented but inconsistently
enforced across the organization. Some roles, such as the security analyst and customer support
representative, are appropriately restricted to read-only access, indicating an attempt to limit permissions
to what is necessary for job performance. However, several violations undermine this principle,
including the assignment of domain administrator privileges to a junior system administrator and the
presence of payroll system access for a customer support representative. These examples demonstrate
that permissions are not always aligned with job responsibilities, increasing the risk of unauthorized
access or misuse of sensitive data.

RBAC also relies on clearly defined and standardized role-permission mappings, but the organization
shows evidence of poorly defined role boundaries. For instance, a finance analyst has access to the
customer relationship management system, which is not typically required for finance functions, and HR
personnel have access to payroll data beyond what may be necessary for their specific duties.
Additionally, the use of shared accounts, such as the read-only reporting account, reduces accountability
and conflicts with best practices in access control. These inconsistencies indicate that roles have not
been rigorously designed to reflect distinct business functions, weakening the effectiveness of RBAC
implementation.

Another important principle supported by RBAC is the separation of duties, which prevents any single
user from having excessive control over critical systems or processes. In this environment, separation of
duties is insufficiently enforced, as seen with the IT administrator who has unrestricted access to all
internal systems and the ability to modify firewall rules without documented oversight. Furthermore,
privilege escalation events, such as the manual assignment of domain administrator rights, suggest that
no formal approval or validation mechanisms are in place. This lack of control increases the
organization’s exposure to both insider threats and operational errors.

, Effective RBAC implementation also requires proper lifecycle management of user accounts, including
timely provisioning and deprovisioning. While the policy states that access should be revoked within
seven days of termination, the system logs reveal that terminated and expired accounts remain active and
are still being used. This indicates a failure in enforcing offboarding procedures and highlights a critical
gap in identity and access management practices. Without proper lifecycle controls, the organization
cannot ensure that only authorized users retain access to systems.

Finally, RBAC depends on strong governance, including documented exceptions, approval workflows,
and periodic access reviews. Although the policy outlines requirements for documenting exceptions and
conducting access reviews, the operational evidence suggests that these controls are not consistently
followed. Instances such as undocumented firewall changes and untracked privilege escalations
demonstrate a lack of enforcement and oversight. As a result, the organization’s current implementation
of RBAC is incomplete and ineffective, with significant gaps in enforcement, monitoring, and
accountability. To fully realize the benefits of RBAC, the organization must strengthen role definitions,
enforce least privilege and separation of duties, and implement formal processes for access control
governance and review.



A2: MISALIGNMENTS
Four significant misalignments can be identified in the user role matrix when evaluated against the
principles of Role-Based Access Control (RBAC), particularly in relation to least privilege, role
consistency, separation of duties, and lifecycle management.
The first misalignment is the assignment of domain administrator privileges to the junior system
administrator, J. Lopez. Under RBAC, roles should be clearly defined, with permissions aligned strictly
with job responsibilities, and elevated privileges should be limited to senior or highly trusted roles.
Granting domain administrator access to a junior-level employee violates the principle of least privilege
and introduces unnecessary risk, as this level of access provides full control over critical systems. This
also reflects a breakdown in role hierarchy and indicates that privilege escalation is not being properly
governed or restricted.

The second misalignment is the presence of payroll system access for the customer support
representative, J. Hall. In an RBAC model, access should be granted based on business function, and
support roles typically require access only to customer-facing systems such as CRM platforms and email
servers. Providing access to payroll data introduces a clear conflict with the principle of least privilege
and demonstrates poor role definition. This type of access overlap increases the risk of unauthorized
exposure of sensitive financial information and suggests that permissions are being assigned outside of
structured role boundaries.

The third misalignment involves the continued active status of the terminated HR assistant, P. Ellis, who
still retains access to the HR portal and payroll system after their end date. RBAC requires strict
lifecycle management, including timely deprovisioning of accounts when employment ends. Allowing a
terminated user to maintain active access violates the model’s requirement for controlled role
assignment and removal, creating a significant security vulnerability. This failure indicates that

Document information

Uploaded on
June 4, 2026
Number of pages
12
Written in
2025/2026
Type
Other
Person
Unknown
$16.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
REIGNDOCS
3.0
(1)
Sold
4
Followers
0
Items
305
Last sold
5 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions