PCI DSS Security Maturity Model·AWS v1.0.0
Efficient Security Assurance 👤 Customer

r4.3 Continuous monitoring of in-transit encryption posture

Automatically detect any endpoint or connection that transmits data without strong encryption and remediate consistently to sustain continuous compliance.

Quick Wins
Foundational
Efficient
Optimized
Effort: Medium Impact: Medium Applies to CDE: Yes

AWS services

AWS Config AWS Security Hub AWS Systems Manager Automation Amazon EventBridge

Requirement 4

Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks

PCI sub-requirements covered

  • 4.2 PAN is protected with strong cryptography during transmission

How to implement on AWS

Define AWS Config rules (alb-http-to-https-redirection-check, elb-tls-https-listeners-only, cloudfront-viewer-policy-https) and consolidate in Security Hub. Automate remediation with SSM Automation. Alert on deviations via EventBridge and Security Hub.

Practical implementation

How this control is implemented in each reference architecture:

Enable the AWS Config HTTPS/TLS managed rules in the account and auto-remediate non-compliant listeners with SSM Automation; alert on drift via EventBridge.

Single-account, 3-tier →

Deploy those Config rules organization-wide via a conformance pack and aggregate results in the security tooling account's Security Hub, so in-transit encryption posture is monitored uniformly across every CDE account.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineobserve

Testing procedures

  • Examine system configurations and monitoring evidence to verify strong cryptography and security protocols remain implemented across all PAN transmissions over open, public networks (4.2.1.b, 4.2.1.c).

Evidence in AWS

  • AWS Config HTTPS/TLS rules in COMPLIANT state.
  • Security Hub dashboard with in-transit encryption controls.
  • History of automatic remediation of non-compliant listeners.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 4.2 — Cleartext PAN cannot be read or intercepted from any transmissions over open, public networks.

Learning resources

References

  • AWS Security Maturity Model: Continuous compliance monitoring