r4.3 Continuous monitoring of in-transit encryption posture
Automatically detect any endpoint or connection that transmits data without strong encryption and remediate consistently to sustain continuous compliance.
AWS services
Requirement 4
Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks
PCI sub-requirements covered
- 4.2 PAN is protected with strong cryptography during transmission
How to implement on AWS
Define AWS Config rules (alb-http-to-https-redirection-check, elb-tls-https-listeners-only, cloudfront-viewer-policy-https) and consolidate in Security Hub. Automate remediation with SSM Automation. Alert on deviations via EventBridge and Security Hub.
Practical implementation
How this control is implemented in each reference architecture:
Enable the AWS Config HTTPS/TLS managed rules in the account and auto-remediate non-compliant listeners with SSM Automation; alert on drift via EventBridge.
Single-account, 3-tier →Deploy those Config rules organization-wide via a conformance pack and aggregate results in the security tooling account's Security Hub, so in-transit encryption posture is monitored uniformly across every CDE account.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine system configurations and monitoring evidence to verify strong cryptography and security protocols remain implemented across all PAN transmissions over open, public networks (4.2.1.b, 4.2.1.c).
Evidence in AWS
- AWS Config HTTPS/TLS rules in COMPLIANT state.
- Security Hub dashboard with in-transit encryption controls.
- History of automatic remediation of non-compliant listeners.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 4.2 — Cleartext PAN cannot be read or intercepted from any transmissions over open, public networks.
Learning resources
- AWS Config Managed Rules (doc)
References
- AWS Security Maturity Model: Continuous compliance monitoring
PCI DSS Security Maturity Model