Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 35 páginas
Examen

WGU C845 Information Systems Security ACTUAL TASK 3 EXEMPLAR AND SOLUTION GUIDE 2026/2027 | VUN1 Task 3 | High-Pass Model Submission | Pass Guaranteed - A+ Graded

Document preview thumbnail
Vista previa 4 fuera de 35 páginas

Pass WGU C845 VUN1 Task 3 on your first attempt with this high-pass model submission. This A+ Graded Complete Exemplar & Solution Guide 2026/2027 contains the ACTUAL TASK 3 SUBMISSION aligned with the official rubric. Features comprehensive coverage of evaluating and defending data security and system operations—including identified data protection risks (unencrypted databases, insecure file transfers), recommended cryptographic methods (application-level encryption, SFTP/HTTPS migration), and detailed justifications aligned with NIST and compliance frameworks. Backed by our Pass Guarantee. Download now.

Vista previa del contenido

1




WGU C845 Information Systems Security
ACTUAL TASK 3 EXEMPLAR AND
SOLUTION GUIDE 2026/2027 | VUN1 Task
3 | High-Pass Model Submission | Pass
Guaranteed - A+ Graded

Scenario Selection

[Guidance: This exemplar uses a mid-sized healthcare organization: "Coastal Medical
Associates (CMA) - A multi-specialty medical practice with 150 providers, 450 staff, 6 clinic
locations, and an ambulatory surgery center." Healthcare organizations face stringent regulatory
requirements (HIPAA, HITECH) and sensitive protected health information (PHI), making this
an ideal scenario for demonstrating comprehensive security risk assessment and program
development. The structure is adaptable to any industry.]



Executive Summary

Coastal Medical Associates (CMA) has experienced significant growth over the past three years,
including the acquisition of two smaller practices, migration to a cloud-based electronic health
record (EHR) system, and expansion of telehealth services. While these changes have improved
patient care and operational efficiency, they have also increased the organization's attack
surface and introduced new security risks.

This security risk assessment and program development document provides a comprehensive
analysis of CMA's current security posture and presents a strategic roadmap for maturing
the information security program. The assessment identified 12 critical and high-risk findings
across people, process, and technology domains, with the most significant risks related to:

Incomplete access controls and lack of multi-factor authentication (MFA) for remote access

Insufficient security awareness training and lack of phishing simulations

No formal incident response plan or testing

Gaps in vendor risk management for cloud service providers

,2


Incomplete security policies and lack of policy enforcement

The proposed security program includes the appointment of a dedicated Information Security
Officer (ISO), implementation of 30 security controls mapped to NIST SP 800-53, and
development of 5 core security policies. This plan is projected to reduce CMA's residual risk
exposure by approximately 55% over 18 months and achieve HIPAA Security Rule compliance
maturity consistent with OCR expectations.



A1: Organizational Profile and Scope

[Guidance: This section requires a detailed description of your chosen organization. Include
size, structure, industry, regulatory environment, and key assets. This context drives all
subsequent risk and control decisions.]

A1a: Organization Overview

Coastal Medical Associates (CMA) is a multi-specialty medical practice headquartered in San
Diego, California. Founded in 1985, CMA has grown to serve approximately 120,000 patients
annually with 150 physicians and advanced practice providers across 12 specialties, including
primary care, cardiology, orthopedics, gastroenterology, and general surgery.

Key Statistics:

Employees: 450 (including clinical and administrative staff)

Locations: 6 outpatient clinics and 1 ambulatory surgery center (ASC)

Annual patient encounters: 450,000

Annual revenue: $85 million

Mission: "To provide compassionate, high-quality, patient-centered healthcare to the San Diego
community."
Vision: "To be the region's most trusted and innovative multi-specialty medical group."

A1b: Regulatory Environment

CMA operates under oversight from:

Department of Health and Human Services (HHS)/OCR: HIPAA Privacy, Security, and
Breach Notification Rules

Centers for Medicare & Medicaid Services (CMS): Medicare and Medicaid compliance

California Department of Public Health: State licensing requirements

California Consumer Privacy Act (CCPA): Patient data privacy requirements

,3


The Joint Commission: ASC accreditation requirements

DEA: Controlled substance prescribing and tracking

A1c: Key Information Assets

Table

Copy

Asset Class Specific Assets Sensitivity Location


Epic (cloud-hosted) - Contains full
patient records including
Electronic demographics, medical history,
Health Record medications, lab results, clinical Cloud (vendor-
(EHR) notes CRITICAL hosted)


Protected Health EHR, practice
Information Individually identifiable patient management,
(PHI) data across all systems CRITICAL billing, archival


Practice
Management Scheduling, registration, insurance On-premise
System verification, billing HIGH servers


Financial Accounts payable/receivable, On-premise and
Systems payroll, general ledger HIGH cloud


Email and Microsoft 365 (Exchange, Teams,
Collaboration SharePoint) MODERATE Cloud


Imaging systems (PACS), lab
Clinical Devices analyzers, vital sign monitors MODERATE On-premise


Telehealth Doxy.me (HIPAA-compliant video
Platform visits) HIGH Cloud

, 4



Asset Class Specific Assets Sensitivity Location


De-identified clinical data for Cloud and on-
Research Data research studies MODERATE premise



A2: Risk Assessment Methodology

[Guidance: Describe your risk assessment approach. This exemplar uses a hybrid
qualitative/quantitative approach based on NIST SP 800-30.]

A2a: Risk Assessment Framework
This risk assessment follows the methodology outlined in NIST Special Publication 800-30,
Revision 1, "Guide for Conducting Risk Assessments." The process includes:

Asset Identification: Critical assets were identified through interviews with department heads
and review of CMA's technology inventory.

Threat Identification: Potential threat sources and events were identified using threat
intelligence sources (CISA, HHS OCR breach reports, industry threat feeds).

Vulnerability Identification: Vulnerabilities were identified through security control
assessments, policy reviews, interviews, and review of past security incidents.

Likelihood Determination: Likelihood was assessed based on threat capability, intent, and
vulnerability prevalence.

Impact Determination: Impact was assessed based on potential harm to patient safety, financial
loss, regulatory penalties, and reputational damage.

Risk Calculation: Risk was calculated as a function of likelihood and impact using a 5x5 risk
matrix.

A2b: Risk Scoring Methodology
Table

Copy

Likelihood Level Description Score


Very High Almost certain to occur (multiple times per year) 5

Información del documento

Subido en
13 de febrero de 2026
Número de páginas
35
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$15.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
STUVIAACTUALEXAMS
3.5
(158)
Vendido
1236
Seguidores
208
Artículos
8904
Última venta
15 horas hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes