Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Vulnerability scanning, intrusion detection, WAF coverage, FIM and external attack-surface review.
InspectorGuardDuty IDSWAFPen-test/ASV
11.3 — Vulnerability Scanning
| Capability | State | Status |
|---|
| Amazon Inspector v2 | DISABLED | Gap |
| GuardDuty (IDS/anomaly) | ENABLED | Compliant |
11.5 — File Integrity Monitoring (FIM)
Note: SSM Run Command inspection unavailable in this environment (aws-cli send-command incompatibility; prior attempt returned send-failed) — instance-level checks require manual review.
11.4 — Public Attack Surface
| Type | Public Endpoint / Resource |
|---|
| CloudFront | adm**** |
| CloudFront | api**** |
| CloudFront | log**** |
| CloudFront | for**** |
| CloudFront | log**** |
| CloudFront | for**** |
| CloudFront | por**** |
| RDS (public) | vm1lxyp9qd594ip |
| RDS (public) | vm1lxyp9qd594ip-2 |
| S3 (public) | log**** |
| S3 (public) | por**** |
| S3 (public) | v1-501****-hpg-artifactstore |
| S3 (public) | v1-501****-hpt-itemstore |
| S3 (public) | v1-501****-hpt-patientdocs |
| S3 (public) | v1-501****-hpt-uploadpatientstore |
Control Mapping
| Control | Description | Status | Evidence |
|---|
| 11.3.1 | Internal vulnerability scans performed | Gap | Inspector DISABLED — continuous internal scanning NOT active |
| 11.3.2 | External vulnerability (ASV) scans | Gap | No ASV scan evidence — requires PCI-approved scanning vendor (manual/vendor engagement) |
| 11.5.1 | Intrusion detection / anomaly detection | Compliant | GuardDuty ENABLED as network/anomaly IDS |
| 11.5.1 (WAF) | Web-layer attack detection (WAF) | Gap | 4/7 public distributions behind WAF |
| 11.5.2 | Change-detection / FIM on critical files | Needs Review | AIDE/Wazuh/auditd presence could not be confirmed via SSM — manual review required |
| 11.4.1 (Surface) | Known/managed external attack surface | Needs Review | 15 public entry point(s); includes 8 data-service exposure(s) |
| 11.4.1 (PenTest) | Annual penetration testing | Gap | No penetration-test evidence — requires qualified tester (no active scanning performed by this tool) |
| 11.4.4 | Remediation of exploitable vulnerabilities | Needs Review | Depends on Inspector findings (Inspector disabled) — manual review |
Recommendations
HighEnable Amazon Inspector to provide continuous internal vulnerability scanning evidence (PCI 11.3.1).
HighEngage a PCI Approved Scanning Vendor (ASV) for quarterly external scans and a qualified party for annual penetration testing (PCI 11.3.2 / 11.4.1). This tool performs NO active scanning.
MediumExtend WAF to the 3 public distribution(s) without a Web ACL.
MediumDeploy FIM (AIDE/Wazuh/auditd) on EC2 hosts and centralize change alerts (PCI 11.5.2).
ProcessDocument scope, segmentation testing and remediation SLAs for the testing program (PCI 11.4.5/11.6).