PCI DSS v4.0.1 — Requirement 12

Support Information Security with Organizational Policies and Programs
Environment: hptprod | us-east-2  |  Account: 501****  |  Generated: 2026-07-07 05:52 UTC
Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Governance, cryptographic inventory, incident-response readiness, and a consolidated master summary of Requirements 3–12.
0
Critical
3
Gap
7
Needs Review
1
Compliant
0
AWS-Managed
0
N/A
Crypto inventoryIR alertingSecurity HubTagging

12.3 — Cryptographic Inventory

Asset ClassInventoryStatus
KMS keys10 total, 1 customer-managedCompliant
ACM certificates3/4 ISSUEDCompliant

12.10 — Incident Response Readiness

CapabilityStateStatus
SNS alert subscriptions5 email, 0 SMSCompliant
Systems Manager Incident Manager0 response plan(s)Gap
Amazon Macie (data-exposure detection)Not enabledGap
GuardDuty (threat alerting)ENABLEDCompliant

12.1 — Governance Documentation Checklist

Governance ItemProvisionStatus
Information security policy (annual review)Process document — verify existence & sign-offNeeds Review
Risk assessment (annual + on change)Process documentNeeds Review
Roles & responsibilities definedProcess documentNeeds Review
Third-party / TPSP due diligence & AOCsProcess document (AWS AOC via Artifact)Needs Review
Security awareness trainingProcess documentNeeds Review
Incident response plan tested annuallyProcess + Incident ManagerGap

Master Summary — Requirements 3–12

ReqFocusCriticalGapNeeds ReviewCompliantAWS-Mgd/N/A
3Protect stored data11150
4Encryption in transit02021
5Anti-malware01130
6Secure software03140
7Access control20220
8Authentication03141
9Physical (SRM)12022
10Logging & monitoring03150
11Security testing04310
12Policy & governance00000
Total4191028

QSA Engagement Roadmap (Phased)

PhaseFocus
Phase 1 — Stop the bleeding (0–30d)Remediate all Critical items: encrypt RDS, lock down public S3/RDS, enable root & admin MFA, scope wildcard trust.
Phase 2 — Detective controls (30–60d)CloudTrail→CloudWatch + 12 CIS alarms, enable Inspector, extend WAF & VPC flow logs, set log retention.
Phase 3 — Program & evidence (60–90d)Documented policies, ASV/pen-test engagement, FIM deployment, formal crypto & asset inventory, IR plan test.
Phase 4 — Formal assessment (90d+)Engage a QSA; gather AWS AOC via Artifact; complete RoC/SAQ with collected evidence.

Control Mapping

ControlDescriptionStatusEvidence
12.3.3Cryptographic cipher/key inventory maintainedNeeds Review10 KMS keys + 4 ACM certs enumerated — formalize into documented inventory
12.10.1Incident response plan / alerting in placeGap5 email alert sub(s); Incident Manager plans=0
12.10.5Security alerts monitored (IDS/FIM/change-detection)CompliantGuardDuty feeds alerting; Security Hub not subscribed
12.x (Posture)Central security posture managementGapAWS Security Hub not subscribed
12.5.1 (Inventory)Resource inventory / taggingNeeds Review0% of S3 buckets tagged (0/21)
12.1.xInformation security policy (annual review)Needs ReviewProcess document — verify existence & sign-off
12.1.xRisk assessment (annual + on change)Needs ReviewProcess document
12.1.xRoles & responsibilities definedNeeds ReviewProcess document
12.1.xThird-party / TPSP due diligence & AOCsNeeds ReviewProcess document (AWS AOC via Artifact)
12.1.xSecurity awareness trainingNeeds ReviewProcess document
12.1.xIncident response plan tested annuallyGapProcess + Incident Manager

Recommendations

HighFormalize an Incident Response plan and test annually; consider AWS Systems Manager Incident Manager (0 response plans today) (PCI 12.10).
MediumEnable AWS Security Hub for centralized, standard-mapped posture management and evidence.
MediumAdd SMS/on-call escalation to critical SNS alert topics (currently email-only).
ProcessAuthor/refresh the core PCI governance document set (security policy, risk assessment, roles, TPSP management, awareness training) and obtain the AWS PCI AOC from AWS Artifact (PCI 12.1/12.8).
ProcessDrive Critical/Gap items from Reqs 3–11 to closure before engaging a QSA for formal assessment.