Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 47 pages
Exam (elaborations)

WGU D485 Cloud Security DGN1 Task 1 Latest Updated Version 100 % correct & verified latest update

Document preview thumbnail
Preview 4 out of 47 pages

A. Executive Summary SWBTL LLC’s Microsoft Azure cloud environment displays many security concerns and does not align with the company’s business requirements. The following outlines the gaps between what is evident in the company’s security environment and the company’s business requirements: 1. Compliance with applicable regulations and standards: SWBTL LLC currently has contracts with the U.S. government in addition to processing card transactions on a daily basis. Therefore, the company must comply with the Federal Information Security Modernization Act (FISMA) and the Payment Card Industry Data Security Standard (PCI DSS). Currently, SWBTL LLC does not comply with these regulations in their existing cloud environment. 2. Azure Resource Groups and Azure Role-Based Access Control (RBAC): SWBTL LLC has a business requirement that departmental resources should only be accessed by the respective department’s users. This requirement aligns with the principle of least privilege. However, the cloud environment does not adhere to this concept in its current state. 3. Azure Key Vaults and Encryption of data-at-rest and data-in-transit: There are no services spun up to encrypt data at rest or data in transit. Azure Key Vaults can be used to secure encryption keys when implementing the Azure Disk Encryption and Azure SQL Database TDE services for data at rest. Data in transit: Azure Key Vaults enforces transport-level encryption to protect data between Azure Key Vault and clients. 4. Backups: SWBTL LLC has business requirements pertaining to backups. These requirements include the frequency and retention of those backups as well as the recovery objectives of those backups. There is no policy or other configurations in place that adhere to these business requirements. 5. Vulnerability Scanning: The scope of vulnerability scans are outdated and it’s unknown if the scans include the cloud environment. Overall, SWBTL LLC’s cloud environment is lacking the necessary security controls to fulfill its business requirements and comply with regulations and standards. The company needs to take the appropriate corrective actions in securing the cloud environment. B. Proposed Course of Action The proposed course of action for SWBTL LLC consists of implementing Microsoft’s Azure Government Infrastructure as a Service (IaaS) solution. This solution provides the company with a FedRAMP/FedRAMP+ authorized product that is also DoD Impact Level (IL) 5 authorized. In addition, this service model meets the company’s requirements of allowing deployment and control of multiple operating systems, virtual machines, and custom applications that can be supported by compute, storage, and network resources on demand. Applicable regulatory compliance directives include the following: - Federal Information Security Modernization Act (FISMA): As a U.S. government contractor, SWBTL LLC needs to comply with information security standards and guidelines required by FISMA, including those standards developed by the National Institute of Standards and Technology (NIST) (NIST, 2016). The Federal Risk and Authorization Management Program (FedRAMP) leverages NIST standards to provide standardized security requirements for cloud services (FedRAMP, n.d.). The

Content preview

WGU D485 Cloud Security DGN1 Task 1 Latest
Updated Version 100 % correct & verified latest
update




Jordan McCready

Student ID#:

010287766 D485

Cloud Security

DGN1 Task 1


Cloud Security Implementation Plan


A. Executive Summary



SWBTL LLC’s Microsoft Azure cloud environment displays many security

concerns and does not align with the company’s business requirements.

The following outlines the gaps between what is evident in the company’s

security environment and the company’s business requirements:

1. Compliance with applicable regulations and standards: SWBTL LLC

currently has contracts with the U.S. government in addition to

, processing card transactions on a daily basis. Therefore, the

company must comply with the Federal Information Security

Modernization Act (FISMA) and the Payment Card Industry Data

Security Standard (PCI DSS). Currently, SWBTL LLC does not

comply with these regulations in their existing cloud environment.

2. Azure Resource Groups and Azure Role-Based Access Control

(RBAC): SWBTL LLC has a business requirement that departmental

resources should only be accessed by the respective department’s

users. This requirement aligns with the principle of least privilege.

However, the cloud environment does not adhere to this concept in

its current state.

3. Azure Key Vaults and Encryption of data-at-rest and data-in-transit:

There are no services spun up to encrypt data at rest or data in

transit. Azure Key Vaults can be used

, to secure encryption keys when implementing the Azure Disk

Encryption and Azure SQL Database TDE services for data at rest.

Data in transit: Azure Key Vaults enforces transport-level encryption

to protect data between Azure Key Vault and clients.

4. Backups: SWBTL LLC has business requirements pertaining to

backups. These requirements include the frequency and retention of

those backups as well as the recovery objectives of those backups.

There is no policy or other configurations in place that adhere to

these business requirements.

5. Vulnerability Scanning: The scope of vulnerability scans are outdated

and it’s unknown if the scans include the cloud environment.



Overall, SWBTL LLC’s cloud environment is lacking the necessary security

controls to fulfill its business requirements and comply with regulations and

standards. The company needs to take the appropriate corrective actions

in securing the cloud environment.



B. Proposed Course of Action



The proposed course of action for SWBTL LLC consists of implementing

Microsoft’s Azure Government Infrastructure as a Service (IaaS) solution.

This solution provides the company with a FedRAMP/FedRAMP+

, authorized product that is also DoD Impact Level (IL) 5 authorized. In

addition, this service model meets the company’s requirements of allowing

deployment and control of multiple operating systems, virtual machines,

and custom applications that can be supported by compute, storage, and

network resources on demand.



Applicable regulatory compliance directives include the following:

- Federal Information Security Modernization Act (FISMA): As a

U.S. government contractor, SWBTL LLC needs to comply with

information security standards and

Document information

Uploaded on
August 9, 2026
Number of pages
47
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$11.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Brainarium
3.8
(333)
Sold
1987
Followers
1046
Items
23954
Last sold
15 hours ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions