- Cloud Native Applications
- Application Security
- Application Security
- Web Application Security
- Application Security Posture Management (ASPM)
- Microsegmentation
- Python Security
- SaaS Security
- Node.JS Security
- PHP Security
- AI in Cyber Security
- Cybersecurity for Financial Services
- The Principle of Least Privilege (PoLP)
- Identity and Access Management
- Cybersecurity in Banking
- Threat Detection and Response
- Cyber Kill Chain
- Threat Hunting
- Zero Trust Security
- Zero Trust Architecture
- Fileless Attacks
- DSPM
- Container Scanning
- Kubernetes
- Kubernetes
- Kubernetes Alternatives
- Kubernetes Namespace
- Kubernetes Architecture
- Kubernetes Cluster
- Kubernetes Nodes
- Kubernetes Pods
- Kubernetes Jobs
- Kubernetes Workloads
- Kubernetes Monitoring
- Kubernetes Security
- Kubernetes RBAC
- Secret Scanning
- Kubernetes Security Posture Management (KSPM)
- Kubernetes on AWS
- Kubernetes on VMware
- Kubernetes Vulnerability Scanning
- Managing Containers in Kubernetes
- K3s
- eBPF in Kubernetes
- Kubernetes Dashboard
- Kubernetes Operators
- Kubernetes Services
- Kubernetes Devops
- Kubernetes Networking
- Kubernetes ConfigMap
- Kubernetes Management
- Kubernetes Helm
- Kubernetes as a Service
- Kubernetes Serverless
- Kubernetes Tutorials
- Cloud Attacks
- Cloud Attacks
- Malware Attacks
- Zero Day Attack
- Top 10 Cyber Security Threats
- Arbitrary Code Execution
- Cryptojacking
- AI Attacks
- Prompt Injection
- Backdoor Attacks
- Reverse Shell Attack
- Remote Code Execution
- Defense Evasion
- Honeypots in Cybersecurity
- Malware Analysis
- AI Malware
- Lateral Movement
- Advanced Malware Protection
- CNAPP
- AI Security
- Container Platforms
- Containerized Architecture
- Containerized Architecture
- Docker Secrets
- Container Runtime Interface
- Container Images
- Image Scanning
- Container Compliance
- Docker Security Best Practices
- Container Security
- Container Security Best Practices
- Container Security Tools
- ECS Security
- Network Segmentation
- Istio security
- runC
- Service Mesh
- Image Repository
- Container Escape
- Container Runtime
- Docker Container
- OSS Container Image Scanning Tools
- What Is a Container?
- Docker Images
- Containerization 101
- VM vs. Container
- Containerization vs. Virtualization
- Containerized Applications
- Microservices and Containerization
- Registry Scanning
- Docker CVEs
- Docker Monitoring
- Securing Containers with Docker Scanning
- Docker CIS Benchmark
- Seccomp
- Docker Alpine
- Docker API
- Docker Tools
- 100 Best Docker Tutorials
- Docker Alternatives
- Docker Swarm
- Docker Containers vs. Virtual Machines (VMs)
- Docker Architecture
- Docker Networking
- Docker Registries
- Docker Orchestration
- OpenShift vs Docker
- Container Cloud Computing
- Container DevOps
- Docker in Production
- Container Monitoring
- Container Advantages
- Docker Hub
- Serverless Architecture
- Supply Chain Security
- Supply Chain Compliance
- SolarWinds Attack
- Supply Chain Security
- Secure Software Development Lifecycle
- Software Supply Chain Attacks
- Dependency Confusion Attack
- SLSA
- SSDF
- Software Composition Analysis
- Security Misconfigurations
- Repojacking
- Privilege Escalation
- CI/CD Security
- SAST Security
- GitLab Security
- GitHub Secret Scanning
- OWASP Dependency-Check
- Software Bill of Materials
- SBOM Tools
- NPM Vulnerabilities
- Log4j Vulnerability
- Text4Shell
- Secrets Management
- Jenkins Security
- Yarn vs. NPM
- Source Code Leaks
- Container Image Signing
- Open Source Licenses
- Vulnerability Management
- Vulnerability Management Tools
- Vulnerability Scanning Process
- Vulnerability Management
- Vulnerability Scanning
- Vulnerability Prioritization
- Open Source Vulnerability Scanning
- Vulnerability Remediation
- Vulnerability Scanner
- Risk-Based Vulnerability Management
- Vulnerability Exploitability eXchange (VEX)
- Malware Detection
- Fileless Malware
- Attack Vectors
- Malicious Code
- Risk Posture
- Alert Fatigue in Cybersecurity
- Cyber Security Posture
- MITRE ATT&CK
- MITRE ATT&CK Framework
- LLM Security
- Code Scanning
- Attack Surface
- Attack Surface Management
- What Are Indicators of Compromise (IoC)?
- Secure Code
- Configuration Drift
- Trivy
- DevSecOps
- DevSecOps
- DevSecOps Pipeline
- DevSecOps Best Practices
- DevSecOps vs SecDevOps
- Threat Modeling
- Mean Time to Repair (MTTR)
- eBPF Linux
- Cloud DevOps
- DevOps Tools
- GitOps vs DevOps
- Code Security
- Secure Code Review
- DevOps Security
- Infrastructure as Code (IaC) Security
- Infrastructure as Code DevOps
- Executive Order 14028 (U.S. Cybersecurity Executive Order)
- Open Source Security
- Shift-Left Security
- Shift Right Testing and Security
- What Is SecOps (Security Operations)?
- SecDevOps
- DevSecOps Tools
- Linux Security
- Rocky Linux
- Azure DevOps
- Cloud Security
- Cloud Security
- Cloud Security Challenges
- Cloud Security Tools
- Code to Cloud
- Cloud Protection
- Cloud Security Frameworks
- Cloud Security Standards
- Cloud Security Controls
- Cloud Security Posture Management (CSPM)
- AI Workloads
- Cloud Digital Forensics
- Cloud Computing Security Architecture
- What Is Enterprise Cloud Security?
- Virtualized Security
- CSPM Tools
- Vulnerabilities in Cloud Computing
- Top 7 Risks of Cloud Computing
- Cloud Security Assessment
- Cloud Visibility
- Cloud Governance
- Cloud Security Strategy
- Cloud Security Policy
- DFIR
- Cloud Workloads
- Public Cloud Security
- Private Cloud vs. Public Cloud
- Runtime Security
- Azure Cloud Security
- Azure Security Best Practices
- Azure Security vs. AWS Security
- AWS GovCloud: Basics & How It Compares to Azure & GCP
- S3 Security
- Cloud Misconfiguration
- Terraform Security
- Hybrid Cloud Security
- Multi-Cloud Strategy
- Agentless vs. Agent-Based Security & Monitoring
- Cloud Infrastructure Security
- Gartner CSPM
- Cloud Security Scanner
- AWS CIS Benchmark
- Cloud Configuration Management
- Cloud Workload Protection (CWP)
- Cloud Workload Protection Platforms (CWPP)
- Cloud Workload Security
- Cloud Vulnerabilities and Tools that Can Help
- Google Cloud Security
- Shared Responsibility Model
- AWS Shared Responsibility Model
- AWS Cloud Security
- Multi Cloud Security
- Cloud Compliance
- Kubernetes in Production
- Cloud Detection And Response
How AWS PCI Compliance Works & 6 Customer Responsibilities
What is AWS PCI Compliance?
PCI compliance involves adhering to the Payment Card Industry Data Security Standard (PCI DSS). PCI DSS standards are designed to secure credit and payment card transactions by reducing fraud and data breaches.
Being PCI compliant on AWS means that the cloud infrastructure provided by Amazon, and workloads managed by customers on this infrastructure, meet the necessary security standards for processing, storing, or transmitting credit card information.
This is part of a series of articles about cloud compliance.
In this article:
- AWS PCI Compliance and the Shared Responsibility Model
- Which AWS Services Are PCI Compliant?
- AWS PCI Tools to Help Your Compliance Strategy
- Customer Responsibilities for Achieving PCI Compliance on AWS
AWS PCI Compliance and the Shared Responsibility Model
PCI compliance on AWS operates under a shared responsibility model, which means both AWS and its customers have roles to play. AWS is responsible for the security “of” the cloud, which includes protecting the infrastructure that runs all of the services offered in the AWS Cloud. This covers areas like physical security of data centers, hardware maintenance, and the virtualization layer. Customers are responsible for security “in” the cloud. This means customers must manage their own operating systems, platforms, and data, including how they configure and use AWS services in a secure manner.
For example, while AWS ensures that the underlying hardware and managed services are secure and compliant, customers must configure their instances, data, and applications to meet PCI DSS requirements. Misconfigurations by the user, such as making an S3 bucket public, can lead to non-compliance even if the service itself is secure. Thus, AWS provides the tools and frameworks necessary for security and compliance, but the responsibility for implementing these tools correctly lies with the customer.
The complexity of PCI compliance increases with the breadth of services and configurations. While AWS provides documentation, security controls, and compliant infrastructure, customers must ensure that they implement these controls properly. This includes managing user access, ensuring data encryption, and maintaining an updated and secure environment. AWS offers guidance and resources, but ultimately, the responsibility for maintaining PCI DSS compliance rests with the customer.
Which AWS Services Are PCI Compliant?
The following Amazon services are AWS compliant. The information was shared by Amazon and updated as of December, 2023.
| Category | AWS Services |
| Compute | Amazon EC2, AWS Lambda, Amazon ECS, Amazon EKS, AWS Elastic Beanstalk |
| Storage | Amazon S3, Amazon EFS, Amazon FSx, AWS Backup, Amazon S3 Glacier |
| Database | Amazon RDS, Amazon DynamoDB, Amazon Redshift, Amazon DocumentDB, Amazon Neptune |
| Networking & Content Delivery | Amazon VPC, Elastic Load Balancing, Amazon CloudFront, AWS Direct Connect |
| Security, Identity, & Compliance | AWS IAM, AWS KMS, AWS Artifact, Amazon GuardDuty, AWS Security Hub |
| Management & Governance | AWS CloudTrail, AWS Config, AWS Control Tower, AWS Systems Manager |
| Analytics | Amazon Athena, Amazon EMR, Amazon QuickSight, AWS Glue |
| Machine Learning | Amazon SageMaker, Amazon Comprehend, Amazon Rekognition, Amazon Lex |
| Application Integration | Amazon API Gateway, Amazon SNS, Amazon SQS, AWS Step Functions |
| Developer Tools | AWS CodeBuild, AWS CodeCommit, AWS CodePipeline, AWS Cloud9 |
| End User Computing | Amazon WorkSpaces, Amazon AppStream 2.0 |
| IoT | AWS IoT Core, AWS IoT Greengrass, AWS IoT SiteWise, AWS IoT Events |
| Media Services | AWS Elemental MediaConvert, AWS Elemental MediaLive, AWS Elemental MediaPackage |
| Migration & Transfer | AWS Migration Hub, AWS DataSync, AWS Transfer Family, AWS Application Migration Service |
| Customer Engagement | Amazon Connect, Amazon Pinpoint |
| Robotics | AWS RoboMaker |
| Satellite | AWS Ground Station |
| Blockchain | Amazon Managed Blockchain, Amazon QLDB |
AWS PCI Tools to Help Your Compliance Strategy
AWS offers several tools that can help organizations ensure PCI compliance.
Amazon GuardDuty
Amazon GuardDuty is a threat detection service that continuously monitors AWS accounts and workloads for malicious activity. Using machine learning, anomaly detection, and integrated threat intelligence, GuardDuty provides alerts to help pinpoint potential security vulnerabilities or unauthorized behaviors.
Amazon Inspector
Amazon Inspector is an automated security assessment service that automatically checks applications for vulnerabilities or deviations from best practices. For organizations subject to PCI DSS, Inspector’s assessments help ensure that applications handling cardholder data are protected against common exploits and misconfigurations.
AWS Artifact
AWS Artifact provides on-demand access to AWS’s compliance documentation and agreements, including PCI DSS reports. It allows customers to download AWS compliance reports, helping them to conduct audits and manage their own compliance in accordance with PCI standards.
Customer Responsibilities for Achieving PCI Compliance on AWS
Here are the primary customer responsibilities when deploying PCI-compliant systems on AWS.
1. Firewalls
Firewalls serve as a barrier between secure internal networks and potential external threats. In PCI-compliant environments on AWS, customers are responsible for setting up and maintaining firewalls to protect data environments. Proper configuration of firewalls ensures that only authorized traffic is allowed, conforming to PCI DSS requirements.
2. Data Encryption
On AWS, customers must ensure that all cardholder data is encrypted both at rest and during transmission. AWS provides tools like AWS KMS (Key Management Service) to manage encryption keys securely.
3. User Authentication and Authorization
AWS customers must ensure that access controls are set up to allow only authorized personnel to retrieve or process payment data. This includes implementing strong authentication methods and maintaining strict user role definitions. AWS provides services like IAM (Identity and Access Management) to help manage user access, but customers are responsible for configuring them.
4. Monitoring and Logging
AWS customers must implement comprehensive logging mechanisms that capture and keep records of all access to and manipulation of cardholder data. AWS offers tools like CloudTrail for logging and monitoring user activities, but it is up to customers to configure these tools to capture adequate and necessary information.
5. AWS Master Accounts
The AWS master accounts structure helps in managing multiple AWS accounts securely. Customers must design their AWS environments to segregate duties, limit the risk of unauthorized access, and manage resources efficiently. The master account oversees user access and resource usage, ensuring consistent compliance across all sub-accounts.
6. Virtual Private Cloud Peering
Virtual Private Cloud (VPC) peering allows connectivity between two VPCs in AWS, enabling resources to communicate across different virtual networks securely. For PCI compliance, it is essential that all transferred data through VPC peering routes is encrypted and movements are monitored. Proper configuration and management of VPC peering involves implementing appropriate firewall rules, establishing precise routing policies, and monitoring network traffic.
Related content: Read our guide to AWS cloud security
- 8 Cloud Compliance Standards & 7 Steps to Achieving Compliance
- PCI DSS Compliance
- Digital Operational Resilience Act (DORA)
- Azure Compliance: Standards, Tools, and 6 Critical Best Practices
- What Is FedRAMP Compliance?
- What Is FedRAMP High Impact Level?
- AWS FedRAMP: How AWS Complies with FedRAMP for U.S. Government Agencies
Aqua Cloud Native Application Protection Platform (CNAPP)
Go cloud native with the experts!