Security Implementation Plan –
Complete Solution Latest 2026/2027
Update |Guaranteed Pass !!
📋 TASK OVERVIEW
Component Details
Course D485 – Cloud Security
Task DGN2 Task 1 – Cloud Security Implementation Plan
INSTITUTION Western Governors University
Identity and Access Management (IAM), data protection (encryption, DLP), network security, incident response,
Focus Areas compliance (GDPR, HIPAA, SOC, PCI DSS), cloud architecture (AWS, Azure, GCP), security monitoring (SIEM
CASB)
Format Written task with complete solutions and rationales
🔍 SECTION A: CURRENT STATE ASSESSMENT & GAP ANALYSIS
A1: Identified Security Gaps and Vulnerabilities
Gap Severity Description
Overly permissive IAM Many IAM roles have "*" (wildcard) permissions or "AdministratorAccess" rather tha
🔴 High
roles least privilege. Users have more access than needed.
No MFA enforcement 🔴 High MFA is not required for IAM users, including those with administrative privileges.
1|Page SUCCESS!!!
,Gap Severity Description
Publicly accessible S3 Several S3 buckets are configured with public read or write access, potentially exposi
🔴 High
buckets sensitive data.
🟡 Some RDS databases and EBS volumes are not encrypted. S3 buckets lack default
Unencrypted data at rest
Medium encryption.
🟡
No DLP controls No Data Loss Prevention controls to prevent unauthorized data exfiltration.
Medium
No centralized 🟡 Logs are stored locally on VMs; no centralized log aggregation or analysis. Security e
logging/SIEM Medium are not monitored in real time.
Missing WAF or DDoS 🟡 Web applications are not protected by a Web Application Firewall. No DDoS mitigati
protection Medium service is enabled.
No vulnerability
🔴 High No automated vulnerability scanning of VMs or container images.
scanning
No incident response
🔴 High No documented incident response plan for cloud environment.
plan
Lack of compliance 🟡
No automated monitoring for compliance with GDPR, HIPAA, or PCI DSS.
monitoring Medium
A2: Compliance Requirements
Framework Applicability Key Requirements
Data subject access rights, data breach notification within 72 hours, data
Customer data from EU
GDPR protection by design and by default, data processing agreements, strong acces
residents
control measures
Security controls (firewalls, IDS/IPS, access controls), availability (redundan
SOC 2 (Type Customer trust (security,
backup), confidentiality (encryption, data classification), processing integrity
II) availability, confidentiality)
privacy
2|Page SUCCESS!!!
, Framework Applicability Key Requirements
Business Associate Agreements (BAA), encryption of PHI, access controls, a
HIPAA Healthcare data
logs, breach notification
Strong access controls, network segmentation, encryption, regular vulnerabili
PCI DSS Payment card data
scanning
Security controls mapped to NIST 800-53, continuous monitoring, authorizat
FedRAMP Government cloud workloads
to operate
A2: Mapping Compliance Requirements to Security Controls
Compliance Requirement Security Control Cloud Service
Encryption of data at rest Enable default encryption AWS S3, RDS, EBS
AWS Certificate Manager, Load
Encryption of data in transit TLS 1.2+ for all data; enforce HTTPS
Balancer
IAM roles with least privilege; conditional
Access controls (least privilege) AWS IAM
policies
MFA for privileged users Enable MFA for all IAM users AWS IAM
Incident response Develop and test IR plan; automated alerts AWS Security Hub, GuardDuty, S
Business Associate Agreements
Execute BAA with AWS AWS BAA
(HIPAA)
Data subject access requests (GDPR) Identify, retrieve, and delete personal data Data tagging, search capabilities
Configure alerts; establish notification
Breach notification AWS GuardDuty, Security Hub, S
procedures
🔐 SECTION B: IDENTITY AND ACCESS MANAGEMENT (IAM)
B1: IAM Implementation Plan
Step 1: Inventory Current IAM Roles and Permissions
3|Page SUCCESS!!!