PCI DSS v4.0
AWS 51 automated checks
Payment Card Industry Data Security Standard v4.0 compliance checks for AWS resources
Access Control
Authentication
Data Protection
Encryption in Transit
Incident Response
Logging & Monitoring
Malware Protection
Network Security
- Security group must not allow unrestricted ingress (0.0.0.0/0)
- RDS instance must not be publicly accessible
- Redshift cluster must not be publicly accessible
- S3 bucket must block all public access
- Redshift cluster should use enhanced VPC routing
- Organization should maintain current network diagrams
- Organization should maintain cardholder data flow diagrams
Personnel Security
Physical Security
Risk Assessment
Secure Configuration
Secure Development
Security Awareness
Security Policies
Security Policy
Security Testing
Service Providers
Testing
Measure your PCI DSS v4.0 posture
CGPulse maps live Azure and AWS findings to these controls and tracks drift over time.