| Requirement 1 Install and Maintain Network Security Controls Build and Maintain a Secure Network and Systems | r1.1 Shared Close risky open ports in security groups Effort: Low Impact: High | r1.2 Shared Limit network access to and from the CDE Effort: Medium Impact: High r1.3 Shared Network segmentation with VPCs and multi-account architecture Effort: High Impact: High | r1.4 Shared Traffic inspection with AWS Network Firewall at the CDE perimeter Effort: High Impact: Medium | r1.5 Shared Outbound traffic control and automated remediation of network deviations Effort: High Impact: Medium |
| Requirement 2 Apply Secure Configurations to All System Components Build and Maintain a Secure Network and Systems | r2.1 Shared Remove default credentials and configurations Effort: Low Impact: High | r2.2 Shared Define and enforce secure configuration standards (hardening) Effort: Medium Impact: High r2.3 Shared Encrypt and harden non-console administrative access Effort: Medium Impact: Medium | r2.4 Customer Detect wireless access points and validate wireless configurations Effort: Medium Impact: Low | · |
| Requirement 3 Protect Stored Account Data Protect Account Data | r3.1 Customer Enable encryption at rest by default (EBS, S3, RDS) Effort: Low Impact: High | r3.2 Customer Minimize account data storage and do not retain SAD Effort: Medium Impact: High r3.3 Customer Mask PAN when displayed Effort: Medium Impact: Medium | r3.4 Shared Protect cryptographic keys with AWS KMS Effort: High Impact: High | r3.5 Customer Continuous account data discovery and leak prevention Effort: High Impact: Medium |
| Requirement 4 Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks Protect Account Data | r4.1 Customer Enforce strong TLS on public endpoints (ALB, CloudFront, API Gateway) Effort: Low Impact: High | r4.2 Customer Inventory and validate certificates and connection trust Effort: Medium Impact: Medium | r4.3 Customer Continuous monitoring of in-transit encryption posture Effort: Medium Impact: Medium | · |
| Requirement 5 Protect All Systems and Networks from Malicious Software Maintain a Vulnerability Management Program | r5.1 Shared Enable malware detection with Amazon GuardDuty Effort: Low Impact: High | r5.2 Shared Deploy maintained and monitored anti-malware/EDR on instances Effort: Medium Impact: High | r5.3 Shared Anti-phishing protection with email and browsing controls Effort: Medium Impact: Medium | r5.4 Shared Automated response to malware detection Effort: High Impact: Medium |
| Requirement 6 Develop and Maintain Secure Systems and Software Maintain a Vulnerability Management Program | r6.1 Shared Automated vulnerability scanning with Amazon Inspector Effort: Low Impact: High | r6.2 Shared Patch management and controlled changes Effort: Medium Impact: High r6.3 Shared Protect public-facing web applications with AWS WAF Effort: Medium Impact: High | r6.4 Shared Security built into the pipeline (DevSecOps) Effort: High Impact: Medium | r6.5 Shared Automated vulnerability detection and remediation at scale Effort: High Impact: Medium |
| Requirement 7 Restrict Access to System Components and Cardholder Data by Business Need to Know Implement Strong Access Control Measures | r7.1 Shared Enforce least privilege with IAM policies Effort: Low Impact: High | r7.2 Shared Centralize access with IAM Identity Center and role-based permissions Effort: Medium Impact: High | r7.3 Shared Automated access review and refinement Effort: Medium Impact: Medium | · |
| Requirement 8 Identify Users and Authenticate Access to System Components Implement Strong Access Control Measures | r8.1 Shared Require MFA for all console and CDE access Effort: Low Impact: High | r8.2 Shared Unique identity and federated user lifecycle Effort: Medium Impact: High r8.3 Shared Eliminate long-lived credentials with temporary access Effort: Medium Impact: High | r8.4 Shared Advanced protection of privileged identities and anomaly detection Effort: High Impact: Medium | · |
| Requirement 9 Restrict Physical Access to Cardholder Data Implement Strong Access Control Measures | r9.1 AWS Inherit AWS physical controls through the compliance reports Effort: Low Impact: High | r9.2 Shared Manage the physical scope of your own components (hybrid/POI) Effort: Medium Impact: Medium | · | · |
| Requirement 10 Log and Monitor All Access to System Components and Cardholder Data Regularly Monitor and Test Networks | r10.1 Shared Enable CloudTrail across the organization Effort: Low Impact: High r10.3 Shared Reliable time synchronization (10.6) Effort: Low Impact: Medium | r10.2 Shared Centralize and protect logs against tampering Effort: Medium Impact: High | r10.4 Shared Automated log review and anomaly detection Effort: Medium Impact: Medium | r10.5 Shared Timely detection and alerting of critical control failures Effort: High Impact: Medium |
| Requirement 11 Test Security of Systems and Networks Regularly Regularly Monitor and Test Networks | r11.1 Shared Internal and external vulnerability scans Effort: Low Impact: High | r11.2 AWS Detection of unauthorized wireless access points Effort: Low Impact: Low r11.3 Shared Network intrusion detection Effort: Medium Impact: High | r11.4 Shared Detection of unauthorized changes on payment pages Effort: High Impact: Medium r11.5 Shared Internal and external penetration testing Effort: High Impact: Medium | · |
| Requirement 12 Support Information Security with Organizational Policies and Programs Maintain an Information Security Policy | r12.1 Customer Define the CDE scope and maintain the inventory with AWS Config Effort: Low Impact: High r12.2 Customer Establish security and acceptable use policies Effort: Low Impact: Medium | r12.3 Customer Formalize risk management (targeted risk analysis) Effort: Medium Impact: Medium r12.4 Customer Security awareness program Effort: Low Impact: Medium r12.5 Customer Third-party service provider (TPSP) risk management and shared responsibility Effort: Medium Impact: High | r12.6 Customer Automated incident response plan Effort: High Impact: High | · |