Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 2 fuera de 12 páginas
Otro

WGU C845: Task 1 MANAGING SECURITY OPERATIONS AND ACCESS CONTROLS – 2026 update

Document preview thumbnail
Vista previa 2 fuera de 12 páginas

WGU C845: Task 1 MANAGING SECURITY OPERATIONS AND ACCESS CONTROLS – 2026 update

Vista previa del contenido

MANAGING SECURITY OPERATIONS AND ACCESS CONTROLS – C845

Honey Honey
C845 Task 1
INFORMATION SYSTEMS SECURITY
A. Apply an access control model to the provided user role matrix and access control policies
in the attached "Security Operations Artifact" by doing the following:

A1: ACCESS CONTROL EXPLANATION
The access control model most appropriate for this organization is Role-Based Access Control (RBAC),
as it aligns directly with both the user role matrix structure and the organization’s stated access control
policies. RBAC is based on assigning permissions to roles rather than directly to individual users and
then assigning users to those roles based on their job responsibilities. This model is already implicitly
reflected in the organization’s environment, where access is largely determined by job titles such as
finance manager, HR coordinator, and IT administrator, and where systems and privilege levels are
organized around those roles. By organizing access in this way, RBAC supports scalability, consistency,
and simplified administration across departments.

The principle of least privilege, a core component of RBAC, is partially implemented but inconsistently
enforced across the organization. Some roles, such as the security analyst and customer support
representative, are appropriately restricted to read-only access, indicating an attempt to limit permissions
to what is necessary for job performance. However, several violations undermine this principle,
including the assignment of domain administrator privileges to a junior system administrator and the
presence of payroll system access for a customer support representative. These examples demonstrate
that permissions are not always aligned with job responsibilities, increasing the risk of unauthorized
access or misuse of sensitive data.

RBAC also relies on clearly defined and standardized role-permission mappings, but the organization
shows evidence of poorly defined role boundaries. For instance, a finance analyst has access to the
customer relationship management system, which is not typically required for finance functions, and HR
personnel have access to payroll data beyond what may be necessary for their specific duties.
Additionally, the use of shared accounts, such as the read-only reporting account, reduces accountability
and conflicts with best practices in access control. These inconsistencies indicate that roles have not
been rigorously designed to reflect distinct business functions, weakening the effectiveness of RBAC
implementation.

Another important principle supported by RBAC is the separation of duties, which prevents any single
user from having excessive control over critical systems or processes. In this environment, separation of
duties is insufficiently enforced, as seen with the IT administrator who has unrestricted access to all
internal systems and the ability to modify firewall rules without documented oversight. Furthermore,
privilege escalation events, such as the manual assignment of domain administrator rights, suggest that
no formal approval or validation mechanisms are in place. This lack of control increases the
organization’s exposure to both insider threats and operational errors.

, Effective RBAC implementation also requires proper lifecycle management of user accounts, including
timely provisioning and deprovisioning. While the policy states that access should be revoked within
seven days of termination, the system logs reveal that terminated and expired accounts remain active and
are still being used. This indicates a failure in enforcing offboarding procedures and highlights a critical
gap in identity and access management practices. Without proper lifecycle controls, the organization
cannot ensure that only authorized users retain access to systems.

Finally, RBAC depends on strong governance, including documented exceptions, approval workflows,
and periodic access reviews. Although the policy outlines requirements for documenting exceptions and
conducting access reviews, the operational evidence suggests that these controls are not consistently
followed. Instances such as undocumented firewall changes and untracked privilege escalations
demonstrate a lack of enforcement and oversight. As a result, the organization’s current implementation
of RBAC is incomplete and ineffective, with significant gaps in enforcement, monitoring, and
accountability. To fully realize the benefits of RBAC, the organization must strengthen role definitions,
enforce least privilege and separation of duties, and implement formal processes for access control
governance and review.



A2: MISALIGNMENTS
Four significant misalignments can be identified in the user role matrix when evaluated against the
principles of Role-Based Access Control (RBAC), particularly in relation to least privilege, role
consistency, separation of duties, and lifecycle management.
The first misalignment is the assignment of domain administrator privileges to the junior system
administrator, J. Lopez. Under RBAC, roles should be clearly defined, with permissions aligned strictly
with job responsibilities, and elevated privileges should be limited to senior or highly trusted roles.
Granting domain administrator access to a junior-level employee violates the principle of least privilege
and introduces unnecessary risk, as this level of access provides full control over critical systems. This
also reflects a breakdown in role hierarchy and indicates that privilege escalation is not being properly
governed or restricted.

The second misalignment is the presence of payroll system access for the customer support
representative, J. Hall. In an RBAC model, access should be granted based on business function, and
support roles typically require access only to customer-facing systems such as CRM platforms and email
servers. Providing access to payroll data introduces a clear conflict with the principle of least privilege
and demonstrates poor role definition. This type of access overlap increases the risk of unauthorized
exposure of sensitive financial information and suggests that permissions are being assigned outside of
structured role boundaries.

The third misalignment involves the continued active status of the terminated HR assistant, P. Ellis, who
still retains access to the HR portal and payroll system after their end date. RBAC requires strict
lifecycle management, including timely deprovisioning of accounts when employment ends. Allowing a
terminated user to maintain active access violates the model’s requirement for controlled role
assignment and removal, creating a significant security vulnerability. This failure indicates that

Información del documento

Subido en
4 de junio de 2026
Número de páginas
12
Escrito en
2025/2026
Tipo
Otro
Personaje
Desconocido
$16.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
REIGNDOCS
3.0
(1)
Vendido
4
Seguidores
0
Artículos
305
Última venta
5 días hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes