PCI DSS Security Maturity Model·AWS v1.0.0

PCI DSS Security Maturity Model for AWS

The 12 PCI DSS v4.0.1 requirements mapped to AWS security control recommendations across 4 maturity phases.

Requirement
Quick Wins
High-impact, low-effort, low-cost controls that reduce immediate risk in the cardholder data environment (CDE).
Foundational
Foundational controls that establish a solid, sustainable baseline for PCI compliance on AWS.
Efficient
Controls that increase operational efficiency, automation, and compliance coverage at scale.
Optimized
Advanced controls that optimize and refine compliance posture with proactive and continuous-improvement capabilities.
Requirement 1
Install and Maintain Network Security Controls
Build and Maintain a Secure Network and Systems
r1.1 Shared
Close risky open ports in security groups
Effort: Low Impact: High
r1.2 Shared
Limit network access to and from the CDE
Effort: Medium Impact: High
r1.3 Shared
Network segmentation with VPCs and multi-account architecture
Effort: High Impact: High
r1.4 Shared
Traffic inspection with AWS Network Firewall at the CDE perimeter
Effort: High Impact: Medium
r1.5 Shared
Outbound traffic control and automated remediation of network deviations
Effort: High Impact: Medium
Requirement 2
Apply Secure Configurations to All System Components
Build and Maintain a Secure Network and Systems
r2.1 Shared
Remove default credentials and configurations
Effort: Low Impact: High
r2.2 Shared
Define and enforce secure configuration standards (hardening)
Effort: Medium Impact: High
r2.3 Shared
Encrypt and harden non-console administrative access
Effort: Medium Impact: Medium
r2.4 Customer
Detect wireless access points and validate wireless configurations
Effort: Medium Impact: Low
·
Requirement 3
Protect Stored Account Data
Protect Account Data
r3.1 Customer
Enable encryption at rest by default (EBS, S3, RDS)
Effort: Low Impact: High
r3.2 Customer
Minimize account data storage and do not retain SAD
Effort: Medium Impact: High
r3.3 Customer
Mask PAN when displayed
Effort: Medium Impact: Medium
r3.4 Shared
Protect cryptographic keys with AWS KMS
Effort: High Impact: High
r3.5 Customer
Continuous account data discovery and leak prevention
Effort: High Impact: Medium
Requirement 4
Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks
Protect Account Data
r4.1 Customer
Enforce strong TLS on public endpoints (ALB, CloudFront, API Gateway)
Effort: Low Impact: High
r4.2 Customer
Inventory and validate certificates and connection trust
Effort: Medium Impact: Medium
r4.3 Customer
Continuous monitoring of in-transit encryption posture
Effort: Medium Impact: Medium
·
Requirement 5
Protect All Systems and Networks from Malicious Software
Maintain a Vulnerability Management Program
r5.1 Shared
Enable malware detection with Amazon GuardDuty
Effort: Low Impact: High
r5.2 Shared
Deploy maintained and monitored anti-malware/EDR on instances
Effort: Medium Impact: High
r5.3 Shared
Anti-phishing protection with email and browsing controls
Effort: Medium Impact: Medium
r5.4 Shared
Automated response to malware detection
Effort: High Impact: Medium
Requirement 6
Develop and Maintain Secure Systems and Software
Maintain a Vulnerability Management Program
r6.1 Shared
Automated vulnerability scanning with Amazon Inspector
Effort: Low Impact: High
r6.2 Shared
Patch management and controlled changes
Effort: Medium Impact: High
r6.3 Shared
Protect public-facing web applications with AWS WAF
Effort: Medium Impact: High
r6.4 Shared
Security built into the pipeline (DevSecOps)
Effort: High Impact: Medium
r6.5 Shared
Automated vulnerability detection and remediation at scale
Effort: High Impact: Medium
Requirement 7
Restrict Access to System Components and Cardholder Data by Business Need to Know
Implement Strong Access Control Measures
r7.1 Shared
Enforce least privilege with IAM policies
Effort: Low Impact: High
r7.2 Shared
Centralize access with IAM Identity Center and role-based permissions
Effort: Medium Impact: High
r7.3 Shared
Automated access review and refinement
Effort: Medium Impact: Medium
·
Requirement 8
Identify Users and Authenticate Access to System Components
Implement Strong Access Control Measures
r8.1 Shared
Require MFA for all console and CDE access
Effort: Low Impact: High
r8.2 Shared
Unique identity and federated user lifecycle
Effort: Medium Impact: High
r8.3 Shared
Eliminate long-lived credentials with temporary access
Effort: Medium Impact: High
r8.4 Shared
Advanced protection of privileged identities and anomaly detection
Effort: High Impact: Medium
·
Requirement 9
Restrict Physical Access to Cardholder Data
Implement Strong Access Control Measures
r9.1 AWS
Inherit AWS physical controls through the compliance reports
Effort: Low Impact: High
r9.2 Shared
Manage the physical scope of your own components (hybrid/POI)
Effort: Medium Impact: Medium
· ·
Requirement 10
Log and Monitor All Access to System Components and Cardholder Data
Regularly Monitor and Test Networks
r10.1 Shared
Enable CloudTrail across the organization
Effort: Low Impact: High
r10.3 Shared
Reliable time synchronization (10.6)
Effort: Low Impact: Medium
r10.2 Shared
Centralize and protect logs against tampering
Effort: Medium Impact: High
r10.4 Shared
Automated log review and anomaly detection
Effort: Medium Impact: Medium
r10.5 Shared
Timely detection and alerting of critical control failures
Effort: High Impact: Medium
Requirement 11
Test Security of Systems and Networks Regularly
Regularly Monitor and Test Networks
r11.1 Shared
Internal and external vulnerability scans
Effort: Low Impact: High
r11.2 AWS
Detection of unauthorized wireless access points
Effort: Low Impact: Low
r11.3 Shared
Network intrusion detection
Effort: Medium Impact: High
r11.4 Shared
Detection of unauthorized changes on payment pages
Effort: High Impact: Medium
r11.5 Shared
Internal and external penetration testing
Effort: High Impact: Medium
·
Requirement 12
Support Information Security with Organizational Policies and Programs
Maintain an Information Security Policy
r12.1 Customer
Define the CDE scope and maintain the inventory with AWS Config
Effort: Low Impact: High
r12.2 Customer
Establish security and acceptable use policies
Effort: Low Impact: Medium
r12.3 Customer
Formalize risk management (targeted risk analysis)
Effort: Medium Impact: Medium
r12.4 Customer
Security awareness program
Effort: Low Impact: Medium
r12.5 Customer
Third-party service provider (TPSP) risk management and shared responsibility
Effort: Medium Impact: High
r12.6 Customer
Automated incident response plan
Effort: High Impact: High
·