Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Governance, cryptographic inventory, incident-response readiness, and a consolidated master summary of Requirements 3–12.
Crypto inventoryIR alertingSecurity HubTagging
12.3 — Cryptographic Inventory
| Asset Class | Inventory | Status |
|---|
| KMS keys | 10 total, 1 customer-managed | Compliant |
| ACM certificates | 3/4 ISSUED | Compliant |
12.10 — Incident Response Readiness
| Capability | State | Status |
|---|
| SNS alert subscriptions | 5 email, 0 SMS | Compliant |
| Systems Manager Incident Manager | 0 response plan(s) | Gap |
| Amazon Macie (data-exposure detection) | Not enabled | Gap |
| GuardDuty (threat alerting) | ENABLED | Compliant |
12.1 — Governance Documentation Checklist
| Governance Item | Provision | Status |
|---|
| Information security policy (annual review) | Process document — verify existence & sign-off | Needs Review |
| Risk assessment (annual + on change) | Process document | Needs Review |
| Roles & responsibilities defined | Process document | Needs Review |
| Third-party / TPSP due diligence & AOCs | Process document (AWS AOC via Artifact) | Needs Review |
| Security awareness training | Process document | Needs Review |
| Incident response plan tested annually | Process + Incident Manager | Gap |
Master Summary — Requirements 3–12
| Req | Focus | Critical | Gap | Needs Review | Compliant | AWS-Mgd/N/A |
|---|
| 3 | Protect stored data | 1 | 1 | 1 | 5 | 0 |
| 4 | Encryption in transit | 0 | 2 | 0 | 2 | 1 |
| 5 | Anti-malware | 0 | 1 | 1 | 3 | 0 |
| 6 | Secure software | 0 | 3 | 1 | 4 | 0 |
| 7 | Access control | 2 | 0 | 2 | 2 | 0 |
| 8 | Authentication | 0 | 3 | 1 | 4 | 1 |
| 9 | Physical (SRM) | 1 | 2 | 0 | 2 | 2 |
| 10 | Logging & monitoring | 0 | 3 | 1 | 5 | 0 |
| 11 | Security testing | 0 | 4 | 3 | 1 | 0 |
| 12 | Policy & governance | 0 | 0 | 0 | 0 | 0 |
| Total | | 4 | 19 | 10 | 28 | |
QSA Engagement Roadmap (Phased)
| Phase | Focus |
|---|
| Phase 1 — Stop the bleeding (0–30d) | Remediate all Critical items: encrypt RDS, lock down public S3/RDS, enable root & admin MFA, scope wildcard trust. |
| Phase 2 — Detective controls (30–60d) | CloudTrail→CloudWatch + 12 CIS alarms, enable Inspector, extend WAF & VPC flow logs, set log retention. |
| Phase 3 — Program & evidence (60–90d) | Documented policies, ASV/pen-test engagement, FIM deployment, formal crypto & asset inventory, IR plan test. |
| Phase 4 — Formal assessment (90d+) | Engage a QSA; gather AWS AOC via Artifact; complete RoC/SAQ with collected evidence. |
Control Mapping
| Control | Description | Status | Evidence |
|---|
| 12.3.3 | Cryptographic cipher/key inventory maintained | Needs Review | 10 KMS keys + 4 ACM certs enumerated — formalize into documented inventory |
| 12.10.1 | Incident response plan / alerting in place | Gap | 5 email alert sub(s); Incident Manager plans=0 |
| 12.10.5 | Security alerts monitored (IDS/FIM/change-detection) | Compliant | GuardDuty feeds alerting; Security Hub not subscribed |
| 12.x (Posture) | Central security posture management | Gap | AWS Security Hub not subscribed |
| 12.5.1 (Inventory) | Resource inventory / tagging | Needs Review | 0% of S3 buckets tagged (0/21) |
| 12.1.x | Information security policy (annual review) | Needs Review | Process document — verify existence & sign-off |
| 12.1.x | Risk assessment (annual + on change) | Needs Review | Process document |
| 12.1.x | Roles & responsibilities defined | Needs Review | Process document |
| 12.1.x | Third-party / TPSP due diligence & AOCs | Needs Review | Process document (AWS AOC via Artifact) |
| 12.1.x | Security awareness training | Needs Review | Process document |
| 12.1.x | Incident response plan tested annually | Gap | Process + Incident Manager |
Recommendations
HighFormalize an Incident Response plan and test annually; consider AWS Systems Manager Incident Manager (0 response plans today) (PCI 12.10).
MediumEnable AWS Security Hub for centralized, standard-mapped posture management and evidence.
MediumAdd SMS/on-call escalation to critical SNS alert topics (currently email-only).
ProcessAuthor/refresh the core PCI governance document set (security policy, risk assessment, roles, TPSP management, awareness training) and obtain the AWS PCI AOC from AWS Artifact (PCI 12.1/12.8).
ProcessDrive Critical/Gap items from Reqs 3–11 to closure before engaging a QSA for formal assessment.