Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Overig

WGU D489: Cybersecurity Management Task 1|New 2026 Latest Update Already Passed

Beoordeling
-
Verkocht
-
Pagina's
21
Geüpload op
25-01-2026
Geschreven in
2025/2026

WGU D489: Cybersecurity Management Task 1|New 2026 Latest Update Already Passed

Instelling
Vak

Voorbeeld van de inhoud

Wgu D489: Cybersecurity Management
Task 1|New 2026 Latest Update Already
Passed


Cybersecurity Management - D489


Western Governors University

Flex Vaughn

11/11/2024

A. Summarize the gaps that exist currently in the company’s security framework as
described in the attached “Independent Security Report.”


The gaps that currently exist in the company’s security framework are as follows

Lack of alignment with security best practices and industry standards:

The company’s security program lacks an approach that covers securing and protecting

organizational assets, Security of Payment Card data and privacy protection for customers

located in the European Union. SAGE books lack policy elements that outline acceptable use,

mobile device poly, secure passwords etc. The company also processes card payments and

should be abiding by the PCI DSS Standard requirements but SAGE books does not have any

documentation stating that they are following these standards or accept these payments in

accordance with PCI DSS. Finally, SAGE does not currently have any specific measures to

,protect the collection, storage and use of data of their customers in the European Union as

outlined in the GDPR.

Understaffed security team:

SAGE books currently has a security team that meets operational security goals but they

do not have a sufficient Governance Risk and Compliance team. This could lead to a lapse in

compliance in regulations such as GDPR, FISMA or PCI DSS, which could then lead to lawsuits

and sanctions.

Inadequate cybersecurity awareness program:

The current cybersecurity awareness training is Ad Hoc meaning, on an as needed

basis. Furthermore, only a quarter of new hires and only 10% of current employees took the

training. The training content also does not meet requirements outlined in best practices or

standards.

Incomplete incident response plan (IRP):

SAGE’s IRP deviates from best practices by lacking clear roles and responsibilities for

incident response team members and inadequate procedures for incident handling and

analysis. With this deviation, SAGE puts its information assets at risk and leaves the company

at risk for prolonged security threats and attacks.

Absence of a Business Continuity Plan (BCP):

The report highlights the critical need for a BCP that outlines recovery procedures for

restoring operational capability in the event of disruption. Given SAGE Book’s location of

distribution centers, they are at a higher risk of natural disaster interruptions.



B. Develop mitigation strategies to address the gaps identified in the “Independent

Security Report,” ensuring compliance with PCI DSS and GDPR.

To address the security gaps identified in the "Independent Security Report" and ensure

compliance with PCI DSS and GDPR, SAGE Books should implement the following mitigation

strategies:

Enhance Security Policies and Procedures

, 1.) Create policies to fill gaps in securing and protecting organizational assets:

Create formal policies for acceptable use, mobile device security, secure password

creation and management, and protecting personally identifiable information (PII)

contained on organizational assets. SAGE Book’s should base these policies on

regulatory guidelines from NIST and security best practices outlined in the PCI DSS.

2.) Align existing policies with industry standards and best practices: Update the

cybersecurity awareness training program to meet NIST standards and PCI DSS

Requirement 12.6. SAGE should also align the incident response plan (IRP) with NIST

Special Publication (SP) 800-61 Revision 2 to enhance incident response capabilities.

Strengthen the Information Security Team

1.) Hire additional GRC staff: It was stated that SAGE needed three new employees to

specialize in governance, risk, and compliance (GRC). Their roles should be well defined

and each member should be well versed when it comes to compliance and regulations

surrounding tech standards such as PCI DSS and GDPR.



Implement a Robust Cybersecurity Awareness Training Program

1.) Develop a comprehensive program: Create a cybersecurity awareness training

program that covers topics such as acceptable use, password security, mobile device

security, phishing attacks, and social engineering, The program should be aligned with

NIST standards and PCI DSS Requirement 12.6

2.) Mandatory training for all employees: Make cybersecurity awareness training

mandatory for all new hires and existing employees, with periodic refreshers to ensure

an improved security posture.



Enhance the Incident Response Plan (IRP)

1.) Define clear roles and responsibilities: Establish a dedicated incident response team

with well-defined roles and responsibilities for each member. Document these roles

Geschreven voor

Instelling
Vak

Documentinformatie

Geüpload op
25 januari 2026
Aantal pagina's
21
Geschreven in
2025/2026
Type
OVERIG
Persoon
Onbekend

Onderwerpen

$16.49
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
Prose1 Strayer University
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
778
Lid sinds
2 jaar
Aantal volgers
72
Documenten
6746
Laatst verkocht
7 uur geleden
REALITIEXAM

I know how frustrating it can get with all those assignments mate. Nursing Being my main profession line, i have essential guides that are A graded, I am a very friendly person so don

4.4

319 beoordelingen

5
238
4
27
3
24
2
8
1
22

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen