PCI DSS v4.0.1 — Requirement 3

Protect Stored Account Data
Environment: hptprod | us-east-2  |  Account: 501****  |  Generated: 2026-07-07 05:52 UTC

⚠ Critical items requiring immediate attention

Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Encryption-at-rest posture for S3/RDS/EBS plus a masked scan for clear-text PAN and Sensitive Authentication Data in logs.
1
Critical
1
Gap
1
Needs Review
5
Compliant
0
AWS-Managed
0
N/A
S3 encRDS encEBS encPAN in logsSAD scan

3.5 — Stored Data Encryption (S3)

BucketDefault EncryptionVersioningStatus
adm****AES256OffCompliant
aws-cloudtrail-logs-501****-aa073ab8AES256OffCompliant
bac****AES256OffCompliant
cdk-hnb659fds-assets-501****-us-east-1aws:kmsEnabledCompliant
cf-templates-e4zlcd7q18st-us-east-2AES256OffCompliant
cod****AES256OffCompliant
for****AES256OffCompliant
hp-cf-loggingAES256OffCompliant
hp-vpc-flowlogAES256OffCompliant
hptuat-mongodumpsAES256OffCompliant
hptwarmeetingAES256OffCompliant
log****AES256OffCompliant
por****AES256OffCompliant
regionalapi-s3bucketaccesslogs-wrzn070su9k7AES256OffCompliant
rev****AES256OffCompliant
v1-501****-hpg-artifactstoreAES256OffCompliant
v1-501****-hpg-artifactstore-backupAES256OffCompliant
v1-501****-hpg-secretstoreAES256OffCompliant
v1-501****-hpt-itemstoreAES256EnabledCompliant
v1-501****-hpt-patientdocsAES256OffCompliant
v1-501****-hpt-uploadpatientstoreAES256EnabledCompliant

3.5 — RDS Storage Encryption

DB InstanceEngineVersionEncryptedKMSStatus
vm1lxyp9qd594ipmysql8.0.44YesYesCompliant
vm1lxyp9qd594ip-2mysql8.0.44NONoCritical

3.5 — EBS Volume Encryption

VolumeSizeEncryptedStateStatus
vol-0****50 GiBYesin-useCompliant
vol-0****8 GiBYesin-useCompliant

3.3 / 3.4 — PAN & SAD Exposure Scan (CloudWatch Logs, last 7 days)

Scanned 25 log group(s) via Logs Insights. Potential PAN (13–19 digit runs, Luhn-validated) matches are shown masked as first4****last4. SAD (CVV/track/PIN) keyword matches are flagged without printing any value.
No Luhn-valid PAN candidates detected in scanned logs.
SAD keyword hits (CVV/CVC/track/PIN): 12 occurrence(s) — values intentionally NOT displayed. Manual review required.

Control Mapping

ControlDescriptionStatusEvidence
3.5.1Render stored account data unreadable (S3 default encryption)Compliant21/21 buckets with default encryption
3.5.1 (RDS)Storage encryption for databases holding account dataCritical1/2 DB instances encrypted
3.5.1 (EBS)Encryption of block storage volumesCompliant2/2 volumes encrypted
3.5.1 (Snapshots)Manual DB snapshots encryptedCompliant5/5 manual snapshots encrypted
3.3.1Sensitive Authentication Data (SAD) not stored after authorizationNeeds Review12 CVV/track/PIN keyword hit(s) in logs
3.4.1PAN masked / not exposed in logsCompliant0 Luhn-valid PAN candidate(s) in logs
3.6.1Cryptographic keys protected (KMS)Compliant10 KMS keys enabled; 1 customer-managed
3.7.4Key rotation implementedGap0/1 customer keys with rotation

Recommendations

HighEncrypt RDS instance(s) vm1lxyp9qd594ip-2 at rest (snapshot → restore into an encrypted instance; cannot enable in place). This is a PCI 3.5.1 requirement.
HighReview CVV/track/PIN keyword hits in logs — SAD must never be stored post-authorization (PCI 3.3.1).
MediumEnable customer-managed KMS key rotation on the auditlog-hipaa key.
LowEnable S3 versioning on data buckets to support tamper-evidence and recovery.
ProcessDocument data-retention & secure-deletion policy for stored account data (PCI 3.2.1).