PCI DSS Security Maturity Model·AWS v1.0.0
Foundational Threat Detection 🤝 Shared

r11.3 Network intrusion detection

Use intrusion detection techniques to detect and alert on intrusions at the perimeter and at critical points of the CDE, keeping the mechanisms up to date.

Quick Wins
Foundational
Efficient
Optimized
Effort: Medium Impact: High Applies to CDE: Yes

AWS services

Amazon GuardDuty AWS Network Firewall AWS Security Hub

Requirement 11

Test Security of Systems and Networks Regularly

PCI sub-requirements covered

  • 11.5 Network intrusions and unexpected file changes are detected and responded to

How to implement on AWS

Enable GuardDuty (including VPC Flow Logs and DNS analysis) for agentless intrusion detection. Complement with AWS Network Firewall IPS rules (Suricata) at the CDE perimeter. Alert on and respond to findings through Security Hub/EventBridge.

Practical implementation

How this control is implemented in each reference architecture:

Enable GuardDuty (VPC Flow Logs + DNS analysis) and add AWS Network Firewall IPS rules at the CDE boundary in the account; respond to findings via Security Hub/EventBridge.

Single-account, 3-tier →

GuardDuty runs org-wide and IPS is applied centrally in the inspection VPC (network account), so intrusion detection covers every CDE account with one consistently managed rule set and central alerting.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineobserve

Testing procedures

  • Examine system configurations and network diagrams to verify intrusion-detection/prevention techniques monitor traffic at the perimeter and at critical points of the CDE (11.5.1.a).
  • Examine configurations and interview personnel to verify the techniques alert personnel of suspected compromises and are kept up to date (engines, baselines, signatures) (11.5.1.b, 11.5.1.c).

Evidence in AWS

  • GuardDuty enabled with VPC Flow Logs and DNS analysis.
  • AWS Network Firewall IPS rules active at the CDE perimeter.
  • Alerting and handling of findings in Security Hub.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 11.5 — Mechanisms to detect real-time suspicious or anomalous network traffic that may indicate threat actor activity are implemented, and alerts are responded to.

Learning resources

References

  • PCI DSS v4.0.1 Requirement 11.5