Updated Version 100 % correct & verified latest
update
Jordan McCready
Student ID#:
010287766 D485
Cloud Security
DGN1 Task 1
Cloud Security Implementation Plan
A. Executive Summary
SWBTL LLC’s Microsoft Azure cloud environment displays many security
concerns and does not align with the company’s business requirements.
The following outlines the gaps between what is evident in the company’s
security environment and the company’s business requirements:
1. Compliance with applicable regulations and standards: SWBTL LLC
currently has contracts with the U.S. government in addition to
, processing card transactions on a daily basis. Therefore, the
company must comply with the Federal Information Security
Modernization Act (FISMA) and the Payment Card Industry Data
Security Standard (PCI DSS). Currently, SWBTL LLC does not
comply with these regulations in their existing cloud environment.
2. Azure Resource Groups and Azure Role-Based Access Control
(RBAC): SWBTL LLC has a business requirement that departmental
resources should only be accessed by the respective department’s
users. This requirement aligns with the principle of least privilege.
However, the cloud environment does not adhere to this concept in
its current state.
3. Azure Key Vaults and Encryption of data-at-rest and data-in-transit:
There are no services spun up to encrypt data at rest or data in
transit. Azure Key Vaults can be used
, to secure encryption keys when implementing the Azure Disk
Encryption and Azure SQL Database TDE services for data at rest.
Data in transit: Azure Key Vaults enforces transport-level encryption
to protect data between Azure Key Vault and clients.
4. Backups: SWBTL LLC has business requirements pertaining to
backups. These requirements include the frequency and retention of
those backups as well as the recovery objectives of those backups.
There is no policy or other configurations in place that adhere to
these business requirements.
5. Vulnerability Scanning: The scope of vulnerability scans are outdated
and it’s unknown if the scans include the cloud environment.
Overall, SWBTL LLC’s cloud environment is lacking the necessary security
controls to fulfill its business requirements and comply with regulations and
standards. The company needs to take the appropriate corrective actions
in securing the cloud environment.
B. Proposed Course of Action
The proposed course of action for SWBTL LLC consists of implementing
Microsoft’s Azure Government Infrastructure as a Service (IaaS) solution.
This solution provides the company with a FedRAMP/FedRAMP+
, authorized product that is also DoD Impact Level (IL) 5 authorized. In
addition, this service model meets the company’s requirements of allowing
deployment and control of multiple operating systems, virtual machines,
and custom applications that can be supported by compute, storage, and
network resources on demand.
Applicable regulatory compliance directives include the following:
- Federal Information Security Modernization Act (FISMA): As a
U.S. government contractor, SWBTL LLC needs to comply with
information security standards and