PCI DSS Security Maturity Model·AWS v1.0.0
Quick Wins Security Governance 👤 Customer

r12.1 Define the CDE scope and maintain the inventory with AWS Config

Document and validate the PCI DSS scope by maintaining an accurate inventory of the system components in the CDE, updated as changes occur.

Quick Wins
Foundational
Efficient
Optimized
Effort: Low Impact: High Applies to CDE: Yes

AWS services

AWS Config AWS Organizations AWS Resource Groups

Requirement 12

Support Information Security with Organizational Policies and Programs

PCI sub-requirements covered

  • 12.5 PCI DSS scope is documented and validated

How to implement on AWS

Enable AWS Config to inventory resources continuously. Tag CDE resources with a consistent tagging strategy and enforce it with Organizations tag policies. Generate the in-scope component inventory from Config. Review scope at least annually and after significant changes.

Practical implementation

How this control is implemented in each reference architecture:

Enable AWS Config in the account to inventory resources continuously, tag CDE resources consistently, and generate the in-scope component inventory from Config; review scope at least annually.

Single-account, 3-tier →

Aggregate the resource inventory across the PCI OU with a Config aggregator in the security tooling account, enforce a tagging strategy via Organizations tag policies, and derive the in-scope inventory org-wide.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineinterview

Testing procedures

  • Examine the inventory to verify it includes all in-scope system components with a description of function/use, and interview personnel to confirm it is kept current (12.5.1.a, 12.5.1.b).
  • Examine documented scope-review results and interview personnel to verify scope is confirmed at least every 12 months and after significant changes (12.5.2.a, 12.5.2.b).

Evidence in AWS

  • AWS Config resource inventory filtered by CDE tags.
  • Organizations tag policies applied to the CDE.
  • PCI scope document with last-review date (<= 12 months).

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 12.5 — All system components in scope for PCI DSS are identified and known.

Learning resources

References

  • AWS Security Maturity Model: Define scope, Inventory
  • PCI DSS v4.0.1 Requirement 12.5