Instant DownloadGet your files immediately
Secure PaymentsYour information is safe
30-Day RefundHassle-free returns
HomeDiscussionsBuilding a security plan for a compromised tax portal
Question

Building a security plan for a compromised tax portal

Question

Unit 6 Assignment Directions: Case Scenario 3: The Security Plan California Tax Agency Information Security Privacy Compliance Officers must draft a security plan after…

Details

TypeQuestion

Question Requirements

Unit 6 Assignment Directions: Case Scenario 3: The Security Plan

California Tax Agency Information Security Privacy Compliance Officers must draft a security plan after a malicious outsider compromised the online web-application portal and obtained 2,500 taxpayers’ encrypted records from an Oracle database; the plan must address seven core security issues, outline a Business Continuity Plan for payment processing, and establish a new Incident Response team with defined roles and responsibilities.

Read the scenario, and then write a paper that responds to the questions posed. The California Tax Agency processes individual and business tax returns, so the stakes here involve real people whose financial lives depend on how well the agency responds. Follow the instructions and submission requirements carefully.

Scenario

You are one of three Information Security Privacy Compliance Officers for the California Tax Agency, which processes individual and business tax returns. You are informed by the Information Security Officer (ISO) that a malicious outsider (a “bad actor”) has compromised the agency’s online web-application portal. This portal is responsible for assisting taxpayers with setting up payment plans for their state taxes.

The online web application portal collects:

  • taxpayer name
  • address
  • social security number
  • date of birth
  • bank account or credit-card payment information

During the investigation by the California Highway Patrol and the Computer Investigations Team, it was determined that 2,500 individual taxpayers’ data were obtained from an encrypted Oracle database. The obtained data was encrypted using Transparent Data Encryption (TDE). Recent analysis of TDE implementations shows that encryption keys often reside in the same environment as the protected data, which creates a pathway for attackers who gain access to database memory or server resources (Fortanix, 2025). California law requires all state agencies to notify California residents whose unencrypted personal information was found to be acquired by bad actors or was believed to have been acquired. You are asked to take the lead in creating a draft of a security plan that addresses organizational needs to prevent future breaches.

Instructions

To begin the security plan, the ISO has asked you to respond to the following prompts:

  1. Following the seven issues that every security plan includes (per Chapter 10 of your textbook), the ISO would like you to address all seven issues, briefly, as a starting point in the building of a security plan. These seven issues are policy, current state, requirements, recommended controls, accountability, timetable, and continuing attention (Brainkart, 2017).
  2. The ISO would also like you to begin the discussion of a Business Continuity Plan (BCP), to ensure the agency can still function in accepting payments during or after an attack. Discuss at least two points that should be considered in this plan and why they should be considered. A well-designed BCP for a tax administration must account for both technological backups and the human element of crisis response, since protocols and drills prepare teams for decisive action when systems fail (CIAT, 2025).
  3. The agency does not have a clearly defined Incident Response (IR) team to address cyber issues. The ISO is now required to develop this team. To begin the security plan, the ISO has asked you to provide them with the following information:
    1. Explain the importance of three aspects that need to be a part of this newly developed response team.
    2. Provide a recommendation of what positions should make up this team. Research on high-performance IR teams consistently identifies the incident commander, technical lead, forensics analyst, communications lead, and legal counsel as core positions that balance technical containment with legal compliance and public trust (Sygnia, 2025).

Requirements

  • Address all the above prompts in a 4- to 6-page paper that follows APA 7 style.
  • Include credible sources. Refrain from relying on blogs as sources. To find credible sources, you might begin with the UMGC Library using OneSearch. You can also utilize Google Scholar, a general web search (Google), government websites, and professional organizations.
  • Include a references page for the sources you used.

Submission

Review the Grading Rubric to understand how you will be assessed on this assignment.


Sample Answer Excerpts

Seven Issues in Security Planning

A security plan for the California Tax Agency must begin with a policy that states the agency’s commitment to protecting taxpayer data and defines who holds responsibility for security decisions. The current state section should honestly describe the agency’s present vulnerabilities, including the compromised portal and the limitations of the existing encryption approach. Requirements then translate those vulnerabilities into functional demands, such as stronger access controls, external key management, and continuous monitoring for anomalous database activity. Recommended controls map specific countermeasures to each identified weakness; for instance, the agency might adopt multifactor authentication for portal access, network segmentation for the database environment, and real-time alerting on bulk data exports (Fortanix, 2025). Accountability assigns a named individual to every security activity, so no task falls through the cracks during a crisis. A timetable with concrete milestones keeps the plan actionable rather than aspirational. Finally, continuing attention ensures the plan remains a living document through scheduled reviews and updates as threats evolve.

Each of these seven issues matters because the agency handles sensitive financial and personal information that, if exposed, can lead to identity theft and financial fraud for thousands of Californians. The stakes extend beyond regulatory compliance, since public trust in tax administration depends on the agency’s ability to safeguard the data citizens are legally required to provide.

Business Continuity for Payment Processing

The Business Continuity Plan should address at least two critical considerations: maintaining a fallback payment channel and establishing clear communication protocols during an outage. A fallback channel, such as a verified telephone payment system or a temporarily secured alternative portal, allows taxpayers to continue meeting their obligations even when the primary web application is offline. Clear communication protocols, including pre-drafted notifications and a designated spokesperson, prevent confusion among taxpayers and reduce the volume of support calls that can overwhelm staff during an incident. The CIAT guide to business continuity planning for tax administrations emphasizes that organizational attitude and defined protocols make the difference in critical situations, since theory alone cannot substitute for practiced response (CIAT, 2025). Without a tested BCP, the agency risks losing revenue, eroding public confidence, and violating its service obligations to California residents.

Incident Response Team Composition

An effective Incident Response team requires three foundational aspects: clear leadership with authority to make containment decisions, dedicated forensic capability to determine the scope and source of a breach, and a legal and communications function that handles notification obligations and public messaging. These three aspects matter because technical containment without legal guidance can jeopardize evidence or violate notification timelines, while legal compliance without technical understanding cannot effectively stop an ongoing attack. A recommended team composition includes an incident commander, a technical lead, a forensics analyst, a communications lead, and legal counsel. The incident commander owns the overall response and makes escalation decisions. The technical lead directs hands-on investigation and remediation. The forensics analyst collects and preserves evidence. The communications lead manages internal and external messaging. Legal counsel advises on notification requirements under California Civil Code section 1798.29 and coordinates with law enforcement (Sygnia, 2025). This cross-functional structure ensures that technical, legal, and reputational dimensions receive simultaneous attention during the critical hours after detection.

Why This Matters in Practice

These security planning elements translate directly into workplace practice for information security professionals in government agencies. A compliance officer who understands the seven issues can build a plan that auditors will accept and that leadership will fund. A BCP that addresses payment continuity protects the agency’s core revenue function and demonstrates operational maturity to oversight bodies. An IR team with defined roles reduces the chaos that accompanies real breaches, when every minute of downtime carries financial and reputational cost. For students entering the information security field, mastering these frameworks prepares them to contribute meaningfully from their first day on the job.

Frequently Asked Question

How does California law treat encrypted data in breach notification requirements?

California Civil Code section 1798.29 requires state agencies to notify residents whose unencrypted personal information was acquired by an unauthorized person, and the law provides a safe harbor when the data was encrypted at the time of the breach so long as the encryption key was not also compromised (California Office of the Attorney General, n.d.).


Research, Writing, Citation & Referencing Guide

This assignment expects APA 7 style with in-text citations and a references page. The following peer-reviewed sources align with the topic and can support the paper’s key arguments. Two or three citations per page is a reasonable target, with priority given to sources that directly strengthen the analysis rather than padding the reference list.

References

Brainkart. (2017). Contents of a security plan. Security in Computing: Administering Security.

California Office of the Attorney General. (n.d.). Search data security breaches. State of California Department of Justice.

CIAT. (2025). Guide to designing your business continuity plan. Inter-American Center of Tax Administrations.

Fortanix. (2025, May 8). Oracle’s data breach is a wake-up call to rethink key management.

Sygnia. (2025, September 23). Building a high-performance incident response team: Key roles, responsibilities, and structure.

California Legislative Information. (2025). California Civil Code section 1798.29.


Next Assignment

Week 7 Assignment: Case Scenario 4: Post-Breach Communication and Regulatory Compliance

Building on the security plan you drafted in Week 6, this assignment asks you to prepare the external communication package that the California Tax Agency would deploy after the confirmed breach. You will draft a notification letter to affected taxpayers that meets the plain-language requirement of California Civil Code section 1798.29, prepare a press release that balances transparency with the agency’s legal obligations, and outline the steps the agency will take to restore public confidence in its payment portal. The assignment also requires a brief analysis of how the agency should coordinate with the California Attorney General’s office and the California Highway Patrol during the notification process. Submit a 3- to 4-page APA 7 paper with credible sources and a references page.

The post Building a security plan for a compromised tax portal appeared first on EssayBishops.

Make sure to support your response with credible sources and examples from your textbook or recent research articles.

Request Answer of this Assignment

Get the complete, well-researched answer to this discussion question and improve your academic performance.

Request Answer