Rédigé par des étudiants ayant réussi Disponible immédiatement après paiement Lire en ligne ou en PDF Mauvais document ? Échangez-le gratuitement 4,6 TrustPilot
logo-home
Autre

WGU D485 DGN2 TASK 1 Cloud Security Implementation Plan Latest Update with Complete Assignment! ALREADY RATED A+

Vendu
5
Pages
26
Publié le
13-01-2025
Écrit en
2024/2025

WGU D485 DGN2 TASK 1 Cloud Security Implementation Plan Latest Update with Complete Assignment Answers

Établissement
Cours

Aperçu du contenu

WGU D485 DGN2 TASK 1 Cloud Security Implementation Plan Latest Update with Complete
Assignment Answers




WGU D485 DGN2 TASK 1 Cloud Security
Implementation Plan Latest Update with
Complete Assignment Answers

,WGU D485 DGN2 TASK 1 Cloud Security Implementation Plan Latest Update with Complete
Assignment Answers




D485 Cloud Security
DGN2 Task1: Cloud Security Implementation Plan
September 9, 2024

A. Executive Summary

SWBTL LLC, a nationwide logistics company, is transitioning to Microsoft’s Azure cloud
environment due to costs, poor server availability, and cybersecurity concerns with its leased
data centers. The consultant hired to start and finish the migration abruptly quit, leading to
serious concern about the migration process. SWBTL's main concerns are:
• Compliance.
• Encryption of data at rest and in transit.
• Proper role-based access controls.
• The integrity of the backup and recovery systems.

SWBTL is also concerned that the cloud instance may not comply with regulatory compliance,
leaving the company vulnerable to exploitation by nation-state actors or cybercriminals. The
company must comply with the Federal Information Security Modernization Act (FISMA) and
the Payment Card Industry Data Security Standard (PCI DSS) to continue servicing its contracts.
This includes contracts with the United States Government (USG). An immediate action plan is
needed to mitigate risks and ensure the company's security posture aligns with industry
regulations and laws.

B. Proposed Azure Cloud Solution

The recommended service model for SWBTL LLC consists of implementing Microsoft's Azure
Government Infrastructure as a Service (IaaS) solution. This solution provides the company with
a Federal Risk and Authorization Management Program (FedRAMP) authorized product that is
also Department of Defense (DoD) Impact Level (IL) 5 authorized, which was approved by the
Defense Information Systems Agency (DISA). This model allows for the deployment and
control of multiple operating systems, virtual machines, and custom applications supported by
computer storage and network resources on demand. IaaS also supports on-demand scalability
and integration with existing Active Directory infrastructure.

Regulatory Compliance:

SWBTL must comply with FISMA and PCI DSS. FISMA requires federal agencies and
contractors to maintain strong cybersecurity practices, including continuous monitoring and
secure information handling. PCI DSS focuses on securing payment card information, mandating
encryption, access control, and regular vulnerability assessments.

, WGU D485 DGN2 TASK 1 Cloud Security Implementation Plan Latest Update with Complete
Assignment Answers




Security Benefits and Challenges:

Benefits:

Transitioning to Azure's Government IaaS offers the following benefits.

• Enhanced scalability.
• Built-in encryption tools.
• Azure’s compliance features
• Azure security tools such as Security Center and Key Vault
• Encryption Management

Challenges:

The primary challenges include the following.

• Managing access control to prevent internal data breaches.
• Ensuring proper encryption policies are applied across departments.
• Ensuring daily backup and recovery policies align with business objectives.
• Misconfigured security controls.

C. Role-Based Access Controls (RBAC)

RBAC Configuration:

1. Separation of Resource Groups: Each department—Marketing, Accounting, and IT—
should have its own Azure Resource Group. Access should be restricted to departmental
resources only, preventing cross-department data visibility.
2. Principle of Least Privilege: RBAC should be aligned so only department users can
access their resources. For example, only accounting users should have "Key Vault
Contributor" access to the Accounting Key Vault.
3. Scoped Administrative Access: Administrative roles should be clearly defined and
scoped to prevent excessive permissions across departments. For instance, marketing
administrators should not have access to IT systems.

The following screenshots show the steps to configure RBAC for the IT, Accounting, and
Marketing departments. I have streamlined the last two departments, showing the completed
configuration to shorten this document.

École, étude et sujet

Établissement
Cours

Infos sur le Document

Publié le
13 janvier 2025
Nombre de pages
26
Écrit en
2024/2025
Type
AUTRE
Personne
Inconnu

Sujets

11,50 €
Accéder à l'intégralité du document:

Mauvais document ? Échangez-le gratuitement Dans les 14 jours suivant votre achat et avant le téléchargement, vous pouvez choisir un autre document. Vous pouvez simplement dépenser le montant à nouveau.
Rédigé par des étudiants ayant réussi
Disponible immédiatement après paiement
Lire en ligne ou en PDF

Avis des acheteurs vérifiés

Affichage de tous les avis
7 mois de cela

Nice input, but the screenshot is not clear at all.

3,0

1 revues

5
0
4
0
3
1
2
0
1
0
Avis fiables sur Stuvia

Tous les avis sont réalisés par de vrais utilisateurs de Stuvia après des achats vérifiés.

Faites connaissance avec le vendeur

Seller avatar
Les scores de réputation sont basés sur le nombre de documents qu'un vendeur a vendus contre paiement ainsi que sur les avis qu'il a reçu pour ces documents. Il y a trois niveaux: Bronze, Argent et Or. Plus la réputation est bonne, plus vous pouvez faire confiance sur la qualité du travail des vendeurs.
AcademicTestBankandExam Teachme2-tutor
S'abonner Vous devez être connecté afin de pouvoir suivre les étudiants ou les formations
Vendu
61
Membre depuis
4 année
Nombre de followers
0
Documents
435
Dernière vente
2 jours de cela

Welcome to AcademicTestBankandExam, your go-to destination for high-quality academic exams and test banks. We specialize in providing carefully curated collections of exam-style questions, chapter-wise test banks, and full-length mock exams across a wide range of subjects. Whether you're a student preparing for finals, a tutor looking for reliable practice materials, or an educator in need of assessment tools, our resources are designed to help you succeed. Each test bank is developed by experienced educators and aligned with current curriculum standards to ensure relevance and accuracy. With clear solutions and detailed explanations, our goal is to make exam preparation more effective, efficient, and stress-free.

Lire la suite Lire moins
4,3

12 revues

5
8
4
1
3
2
2
1
1
0

Récemment consulté par vous

Pourquoi les étudiants choisissent Stuvia

Créé par d'autres étudiants, vérifié par les avis

Une qualité sur laquelle compter : rédigé par des étudiants qui ont réussi et évalué par d'autres qui ont utilisé ce document.

Le document ne convient pas ? Choisis un autre document

Aucun souci ! Tu peux sélectionner directement un autre document qui correspond mieux à ce que tu cherches.

Paye comme tu veux, apprends aussitôt

Aucun abonnement, aucun engagement. Paye selon tes habitudes par carte de crédit et télécharge ton document PDF instantanément.

Student with book image

“Acheté, téléchargé et réussi. C'est aussi simple que ça.”

Alisha Student

Foire aux questions