Cross-cloud security rules
112 checks CGPulse evaluates against live Cross-cloud resources.
General
- Block storage volumes must be encrypted
- Cache service security hardening
- Cache services must enforce TLS encryption in transit
- Container registry security hardening
- Database authentication must use managed identities
- Databases must not be publicly accessible
- IAM password policy must require minimum length of 14
- Key management service security hardening
- Kubernetes clusters must restrict public API access
- Load balancers must have access logging enabled
- NoSQL database security hardening
- Object storage must have encryption at rest enabled
- Organization should appoint a Data Protection Officer where required
- Organization should assess and monitor third-party vendor risks
- Organization should assign PCI DSS security responsibilities
- Organization should classify data by confidentiality level
- Organization should classify information according to confidentiality requirements
- Organization should collect and analyze threat intelligence
- Organization should communicate security responsibilities to all personnel
- Organization should conduct annual PCI risk assessments
- Organization should conduct Data Protection Impact Assessments for high-risk processing
- Organization should conduct formal risk assessments
- Organization should conduct HIPAA-compliant risk analysis
- Organization should conduct internal information security audits
- Organization should conduct penetration testing at least annually
- Organization should conduct risk assessments (RA-3)
- Organization should conduct security assessments (CA-2)
- Organization should conduct security awareness training for all personnel
- Organization should define and enforce data retention schedules
- Organization should define and protect physical security perimeters
- Organization should define governance structure and oversight responsibilities
- Organization should define information security roles and responsibilities
- Organization should define risk appetite and tolerance levels
- Organization should define security responsibilities upon termination
- Organization should designate a HIPAA Security Officer
- Organization should develop a contingency plan (CP-2)
- Organization should develop a system security plan (PL-2)
- Organization should develop an incident response plan (IR-1)
- Organization should document lawful basis for all personal data processing
- Organization should enforce separation of duties (AC-5)
- Organization should establish access control policies (AC-1)
- Organization should establish configuration management policy (CM-1)
- Organization should establish incident management procedures
- Organization should have a disciplinary process for security violations
- Organization should have breach notification procedures
- Organization should have breach notification procedures
- Organization should have data processing agreements with all processors
- Organization should have procedures for evidence collection and preservation
- Organization should have procedures to handle data subject access requests
- Organization should have processes for external security communications
- Organization should have safeguards for international data transfers
- Organization should have secure data disposal procedures
- Organization should identify applicable legal and regulatory requirements
- Organization should implement a secure software development lifecycle
- Organization should implement change detection mechanisms
- Organization should implement clear desk and clear screen policies
- Organization should implement data protection by design and by default
- Organization should implement device and media controls
- Organization should implement facility access controls
- Organization should implement physical access controls to the CDE
- Organization should implement right to erasure procedures
- Organization should implement security incident response procedures
- Organization should implement valid consent mechanisms
- Organization should implement workforce clearance procedures
- Organization should implement workforce termination procedures
- Organization should implement workstation security policies
- Organization should integrate security into business continuity management
- Organization should integrate security into project management
- Organization should maintain a code of conduct and ethics policy
- Organization should maintain a comprehensive information security policy
- Organization should maintain a contingency plan for ePHI
- Organization should maintain a PCI incident response plan
- Organization should maintain a Plan of Action and Milestones (CA-5)
- Organization should maintain a sanctions policy for violations
- Organization should maintain an information security policy approved by management
- Organization should maintain an inventory of information assets
- Organization should maintain Business Associate Agreements
- Organization should maintain capacity and availability planning
- Organization should maintain cardholder data flow diagrams
- Organization should maintain contact with relevant authorities
- Organization should maintain current network diagrams
- Organization should maintain documented information security policies
- Organization should maintain formal change management procedures
- Organization should maintain logical access policies and procedures
- Organization should manage information security in supplier relationships
- Organization should manage information system accounts (AC-2)
- Organization should manage removable media securely
- Organization should manage service provider PCI compliance
- Organization should manage supply chain risks (SA-12)
- Organization should monitor and remediate control deficiencies
- Organization should monitor system operations and detect anomalies
- Organization should perform background checks for CDE access personnel
- Organization should perform background checks for security-relevant roles
- Organization should perform personnel screening
- Organization should perform quarterly vulnerability scans
- Organization should perform vulnerability scanning (RA-5)
- Organization should provide GDPR awareness training to all staff
- Organization should provide HIPAA security awareness training
- Organization should provide information security awareness and training
- Organization should provide role-based security training (AT-3)
- Organization should provide security awareness training (AT-2)
- Organization should provide transparent privacy notices
- Organization should regularly review information system activity
- Organization should review and analyze audit records (AU-6)
- Organization should securely destroy cardholder data media
- Organization should support data portability requests
- Organization should test contingency plans periodically
- Organization should test incident response capability (IR-3)
- Organization should test the contingency plan (CP-4)
- Organization should test the incident response plan annually
- Organization should train incident response personnel (IR-2)
- Relational database security hardening