r12.1 Define the CDE scope and maintain the inventory with AWS Config
Document and validate the PCI DSS scope by maintaining an accurate inventory of the system components in the CDE, updated as changes occur.
AWS services
Requirement 12
Support Information Security with Organizational Policies and Programs
PCI sub-requirements covered
- 12.5 PCI DSS scope is documented and validated
How to implement on AWS
Enable AWS Config to inventory resources continuously. Tag CDE resources with a consistent tagging strategy and enforce it with Organizations tag policies. Generate the in-scope component inventory from Config. Review scope at least annually and after significant changes.
Practical implementation
How this control is implemented in each reference architecture:
Enable AWS Config in the account to inventory resources continuously, tag CDE resources consistently, and generate the in-scope component inventory from Config; review scope at least annually.
Single-account, 3-tier →Aggregate the resource inventory across the PCI OU with a Config aggregator in the security tooling account, enforce a tagging strategy via Organizations tag policies, and derive the in-scope inventory org-wide.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine the inventory to verify it includes all in-scope system components with a description of function/use, and interview personnel to confirm it is kept current (12.5.1.a, 12.5.1.b).
- Examine documented scope-review results and interview personnel to verify scope is confirmed at least every 12 months and after significant changes (12.5.2.a, 12.5.2.b).
Evidence in AWS
- AWS Config resource inventory filtered by CDE tags.
- Organizations tag policies applied to the CDE.
- PCI scope document with last-review date (<= 12 months).
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 12.5 — All system components in scope for PCI DSS are identified and known.
Learning resources
References
- AWS Security Maturity Model: Define scope, Inventory
- PCI DSS v4.0.1 Requirement 12.5
PCI DSS Security Maturity Model