Assessment and Remediation Plan 2026 Update
with complete solutions.
DFN1 — DFN1 TASK 1: SECURITY SYSTEM EVALUATION AND
REMEDIATION
GOVERNANCE, RISK, AND COMPLIANCE — D486
PRFA — DFN1
Preparation Task Overview Submissions Evaluation Report
COMPETENCIES
4115.1.1 : Evaluates a System Security Plan
The learner evaluates a system security plan in line with business organizational strategy and regulatory
compliance requirements.
4115.1.2 : Develops a Remediation Plan for Compliance
The learner develops a remediation plan for security and privacy compliance issues.
INTRODUCTION
Throughout your career in cybersecurity management, you will be asked to develop and improve an IT
department to support a company’s strategic goals and mission. Assessments of the organization’s
cybersecurity posture will need to be conducted to secure the company’s information and systems. The
organization’s leadership may decide to hire external consultants to do this assessment. The consultants will
review the security policies, standards, procedures, and guidelines that are used to secure the company’s
assets. Additionally, they will look at compliance issues, personnel roles and assignments, continuity plans,
and overall risk management.
In this task, you will serve as a chief information security officer (CISO) to review a security assessment
report provided by an external consulting firm (see the attached "Security Assessment Report for Fielder
Medical Center"). You will confirm or reject the findings by evaluating the focus points of the security
assessment report and will develop a remediation plan for compliance based on the National Institute of
Standards and Technology (NIST) Special Publication (SP) 800-53 Rev. 5 and your company’s business needs.
, SCENARIO
Fielder Medical Center (FMC) is a federally funded healthcare facility that seeks to expand its business into
the local sale of medical equipment. As FMC sought to improve its data management in alignment with
digitization goals, it implemented a system to manage the licensing, certificates, and relevant professional
documents for the doctors working at FMC. Doctors are required to log in and upload sensitive artifacts that
prove they are current in their licensing to practice. These artifacts may contain personally identifiable
information about the doctor, including real name, home address, social security number, and other sensitive
data.