PCI DSS v4.0.1 — Requirement 11

Test Security of Systems and Networks Regularly
Environment: hptprod | us-east-2  |  Account: 501****  |  Generated: 2026-07-07 05:52 UTC
Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Vulnerability scanning, intrusion detection, WAF coverage, FIM and external attack-surface review.
0
Critical
4
Gap
3
Needs Review
1
Compliant
0
AWS-Managed
0
N/A
InspectorGuardDuty IDSWAFPen-test/ASV

11.3 — Vulnerability Scanning

CapabilityStateStatus
Amazon Inspector v2DISABLEDGap
GuardDuty (IDS/anomaly)ENABLEDCompliant

11.5 — File Integrity Monitoring (FIM)

Note: SSM Run Command inspection unavailable in this environment (aws-cli send-command incompatibility; prior attempt returned send-failed) — instance-level checks require manual review.

11.4 — Public Attack Surface

TypePublic Endpoint / Resource
CloudFrontadm****
CloudFrontapi****
CloudFrontlog****
CloudFrontfor****
CloudFrontlog****
CloudFrontfor****
CloudFrontpor****
RDS (public)vm1lxyp9qd594ip
RDS (public)vm1lxyp9qd594ip-2
S3 (public)log****
S3 (public)por****
S3 (public)v1-501****-hpg-artifactstore
S3 (public)v1-501****-hpt-itemstore
S3 (public)v1-501****-hpt-patientdocs
S3 (public)v1-501****-hpt-uploadpatientstore

Control Mapping

ControlDescriptionStatusEvidence
11.3.1Internal vulnerability scans performedGapInspector DISABLED — continuous internal scanning NOT active
11.3.2External vulnerability (ASV) scansGapNo ASV scan evidence — requires PCI-approved scanning vendor (manual/vendor engagement)
11.5.1Intrusion detection / anomaly detectionCompliantGuardDuty ENABLED as network/anomaly IDS
11.5.1 (WAF)Web-layer attack detection (WAF)Gap4/7 public distributions behind WAF
11.5.2Change-detection / FIM on critical filesNeeds ReviewAIDE/Wazuh/auditd presence could not be confirmed via SSM — manual review required
11.4.1 (Surface)Known/managed external attack surfaceNeeds Review15 public entry point(s); includes 8 data-service exposure(s)
11.4.1 (PenTest)Annual penetration testingGapNo penetration-test evidence — requires qualified tester (no active scanning performed by this tool)
11.4.4Remediation of exploitable vulnerabilitiesNeeds ReviewDepends on Inspector findings (Inspector disabled) — manual review

Recommendations

HighEnable Amazon Inspector to provide continuous internal vulnerability scanning evidence (PCI 11.3.1).
HighEngage a PCI Approved Scanning Vendor (ASV) for quarterly external scans and a qualified party for annual penetration testing (PCI 11.3.2 / 11.4.1). This tool performs NO active scanning.
MediumExtend WAF to the 3 public distribution(s) without a Web ACL.
MediumDeploy FIM (AIDE/Wazuh/auditd) on EC2 hosts and centralize change alerts (PCI 11.5.2).
ProcessDocument scope, segmentation testing and remediation SLAs for the testing program (PCI 11.4.5/11.6).