Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 47 páginas
Examen

WGU D485 Cloud Security DGN1 Task 1 Latest Updated Version 100 % correct & verified latest update

Document preview thumbnail
Vista previa 4 fuera de 47 páginas

A. Executive Summary SWBTL LLC’s Microsoft Azure cloud environment displays many security concerns and does not align with the company’s business requirements. The following outlines the gaps between what is evident in the company’s security environment and the company’s business requirements: 1. Compliance with applicable regulations and standards: SWBTL LLC currently has contracts with the U.S. government in addition to processing card transactions on a daily basis. Therefore, the company must comply with the Federal Information Security Modernization Act (FISMA) and the Payment Card Industry Data Security Standard (PCI DSS). Currently, SWBTL LLC does not comply with these regulations in their existing cloud environment. 2. Azure Resource Groups and Azure Role-Based Access Control (RBAC): SWBTL LLC has a business requirement that departmental resources should only be accessed by the respective department’s users. This requirement aligns with the principle of least privilege. However, the cloud environment does not adhere to this concept in its current state. 3. Azure Key Vaults and Encryption of data-at-rest and data-in-transit: There are no services spun up to encrypt data at rest or data in transit. Azure Key Vaults can be used to secure encryption keys when implementing the Azure Disk Encryption and Azure SQL Database TDE services for data at rest. Data in transit: Azure Key Vaults enforces transport-level encryption to protect data between Azure Key Vault and clients. 4. Backups: SWBTL LLC has business requirements pertaining to backups. These requirements include the frequency and retention of those backups as well as the recovery objectives of those backups. There is no policy or other configurations in place that adhere to these business requirements. 5. Vulnerability Scanning: The scope of vulnerability scans are outdated and it’s unknown if the scans include the cloud environment. Overall, SWBTL LLC’s cloud environment is lacking the necessary security controls to fulfill its business requirements and comply with regulations and standards. The company needs to take the appropriate corrective actions in securing the cloud environment. B. Proposed Course of Action The proposed course of action for SWBTL LLC consists of implementing Microsoft’s Azure Government Infrastructure as a Service (IaaS) solution. This solution provides the company with a FedRAMP/FedRAMP+ authorized product that is also DoD Impact Level (IL) 5 authorized. In addition, this service model meets the company’s requirements of allowing deployment and control of multiple operating systems, virtual machines, and custom applications that can be supported by compute, storage, and network resources on demand. Applicable regulatory compliance directives include the following: - Federal Information Security Modernization Act (FISMA): As a U.S. government contractor, SWBTL LLC needs to comply with information security standards and guidelines required by FISMA, including those standards developed by the National Institute of Standards and Technology (NIST) (NIST, 2016). The Federal Risk and Authorization Management Program (FedRAMP) leverages NIST standards to provide standardized security requirements for cloud services (FedRAMP, n.d.). The

Vista previa del contenido

WGU D485 Cloud Security DGN1 Task 1 Latest
Updated Version 100 % correct & verified latest
update




Jordan McCready

Student ID#:

010287766 D485

Cloud Security

DGN1 Task 1


Cloud Security Implementation Plan


A. Executive Summary



SWBTL LLC’s Microsoft Azure cloud environment displays many security

concerns and does not align with the company’s business requirements.

The following outlines the gaps between what is evident in the company’s

security environment and the company’s business requirements:

1. Compliance with applicable regulations and standards: SWBTL LLC

currently has contracts with the U.S. government in addition to

, processing card transactions on a daily basis. Therefore, the

company must comply with the Federal Information Security

Modernization Act (FISMA) and the Payment Card Industry Data

Security Standard (PCI DSS). Currently, SWBTL LLC does not

comply with these regulations in their existing cloud environment.

2. Azure Resource Groups and Azure Role-Based Access Control

(RBAC): SWBTL LLC has a business requirement that departmental

resources should only be accessed by the respective department’s

users. This requirement aligns with the principle of least privilege.

However, the cloud environment does not adhere to this concept in

its current state.

3. Azure Key Vaults and Encryption of data-at-rest and data-in-transit:

There are no services spun up to encrypt data at rest or data in

transit. Azure Key Vaults can be used

, to secure encryption keys when implementing the Azure Disk

Encryption and Azure SQL Database TDE services for data at rest.

Data in transit: Azure Key Vaults enforces transport-level encryption

to protect data between Azure Key Vault and clients.

4. Backups: SWBTL LLC has business requirements pertaining to

backups. These requirements include the frequency and retention of

those backups as well as the recovery objectives of those backups.

There is no policy or other configurations in place that adhere to

these business requirements.

5. Vulnerability Scanning: The scope of vulnerability scans are outdated

and it’s unknown if the scans include the cloud environment.



Overall, SWBTL LLC’s cloud environment is lacking the necessary security

controls to fulfill its business requirements and comply with regulations and

standards. The company needs to take the appropriate corrective actions

in securing the cloud environment.



B. Proposed Course of Action



The proposed course of action for SWBTL LLC consists of implementing

Microsoft’s Azure Government Infrastructure as a Service (IaaS) solution.

This solution provides the company with a FedRAMP/FedRAMP+

, authorized product that is also DoD Impact Level (IL) 5 authorized. In

addition, this service model meets the company’s requirements of allowing

deployment and control of multiple operating systems, virtual machines,

and custom applications that can be supported by compute, storage, and

network resources on demand.



Applicable regulatory compliance directives include the following:

- Federal Information Security Modernization Act (FISMA): As a

U.S. government contractor, SWBTL LLC needs to comply with

information security standards and

Información del documento

Subido en
9 de agosto de 2026
Número de páginas
47
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$11.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Brainarium
3.8
(333)
Vendido
1987
Seguidores
1046
Artículos
23954
Última venta
19 horas hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes