WGU D485 CLOUD SECURITY DNG TASK 1 LATEST UPDATED WESTERN
GOVERNORS UNIVERSITY
D485 Cloud Security
DGN1 Task 1
Cloud Security Implementation Plan
A. Executive Summary
SWBTL LLC’s Microsoft Azure cloud environment displays many security concerns and does
not align with the company’s business requirements. The following outlines the gaps between
what is evident in the company’s security environment and the company’s business
requirements:
1. Compliance with applicable regulations and standards: SWBTL LLC currently has
contracts with the U.S. government in addition to processing card transactions on a daily
basis. Therefore, the company must comply with the Federal Information Security
Modernization Act (FISMA) and the Payment Card Industry Data Security Standard (PCI
DSS). Currently, SWBTL LLC does not comply with these regulations in their existing
cloud environment.
2. Azure Resource Groups and Azure Role-Based Access Control (RBAC): SWBTL LLC
has a business requirement that departmental resources should only be accessed by the
respective department’s users. This requirement aligns with the principle of least
privilege. However, the cloud environment does not adhere to this concept in its current
state.
3. Azure Key Vaults and Encryption of data-at-rest and data-in-transit: There are no
services spun up to encrypt data at rest or data in transit. Azure Key Vaults can be used
Category | WGU EXAM |
Comments | 0 |
Rating | |
Sales | 0 |