100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Essay

Governance, Risk, and Compliance Essay D486

Rating
-
Sold
1
Pages
12
Grade
A+
Uploaded on
21-06-2025
Written in
2024/2025

Complete Security Evaluation for D486










Whoops! We can’t load your doc right now. Try again or contact support.

Document information

Uploaded on
June 21, 2025
Number of pages
12
Written in
2024/2025
Type
Essay
Professor(s)
Unknown
Grade
A+

Subjects

Content preview

Performance Assessment: Governance, Risk, and Compliance

D486

Dorian Stanfield




2/3/2025

, Gaps Overview

In a security audit and assessment conducted by Pruhart Security, an evaluation on the
effectiveness of the implemented enterprises’ controls and the extent to which they were
sufficient to ensure compliance with regulatory requirements has been sanctioned. This
includes the collection and storage of sensitive information.

The initial assessment report implied that the enterprise must augment and expand its
internal control implementation and existing network. As well as improving its current
governance practices. This requires the revision of several existing security controls and
procedures and by the implementation of the following recommendations:

Policies: A requirement for the creation and authorization of privacy and plans that are
parallel with the enterprise’s standards.

Asset management: A necessitation for the modifications to asset management
procedures as well as updates to inventory/asset records

Risk management: Requires the establishment of risk management frameworks to
consistently review and assess security controls of the information systems and network.

Access Controls: A key constraint to the implemented access controls and authentication
procedures to improve the enterprise System Security posture.

Labeled Risks

The Phoenix system was also assessed as part of the evaluation to authenticate the
tolerability of security controls. As well as the configuration of its controls against the
governing requirements outlined in the Federal Information Security Management Act
(FISMA) and payment security standards standard. The assessment detected the five
substantial control areas that demand immediate attention for remediation.

Control Identifier & Assessment Report

AC-6: Least Privilege

Least privilege principles must be employed for discretionary access measures based on
need of access per role.

Rating: High

A vacuum of clearly defined role-based access controls increases the risk of illicit access
and data breaches. FMC is devoted to addressing this control gap to align with NIST 800-
53 guidelines. These guidelines mandate granting users only the permissions required to
$17.39
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached

Get to know the seller
Seller avatar
dorianstanfield

Get to know the seller

Seller avatar
dorianstanfield Western Governers University
View profile
Follow You need to be logged in order to follow users or courses
Sold
3
Member since
1 year
Number of followers
0
Documents
4
Last sold
3 months ago

0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions