⚠ Critical items requiring immediate attention
- Unencrypted RDS instance(s): vm1lxyp9qd594ip-2 — stored data at rest is NOT encrypted.
Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Encryption-at-rest posture for S3/RDS/EBS plus a masked scan for clear-text PAN and Sensitive Authentication Data in logs.
S3 encRDS encEBS encPAN in logsSAD scan
3.5 — Stored Data Encryption (S3)
| Bucket | Default Encryption | Versioning | Status |
|---|
| adm**** | AES256 | Off | Compliant |
| aws-cloudtrail-logs-501****-aa073ab8 | AES256 | Off | Compliant |
| bac**** | AES256 | Off | Compliant |
| cdk-hnb659fds-assets-501****-us-east-1 | aws:kms | Enabled | Compliant |
| cf-templates-e4zlcd7q18st-us-east-2 | AES256 | Off | Compliant |
| cod**** | AES256 | Off | Compliant |
| for**** | AES256 | Off | Compliant |
| hp-cf-logging | AES256 | Off | Compliant |
| hp-vpc-flowlog | AES256 | Off | Compliant |
| hptuat-mongodumps | AES256 | Off | Compliant |
| hptwarmeeting | AES256 | Off | Compliant |
| log**** | AES256 | Off | Compliant |
| por**** | AES256 | Off | Compliant |
| regionalapi-s3bucketaccesslogs-wrzn070su9k7 | AES256 | Off | Compliant |
| rev**** | AES256 | Off | Compliant |
| v1-501****-hpg-artifactstore | AES256 | Off | Compliant |
| v1-501****-hpg-artifactstore-backup | AES256 | Off | Compliant |
| v1-501****-hpg-secretstore | AES256 | Off | Compliant |
| v1-501****-hpt-itemstore | AES256 | Enabled | Compliant |
| v1-501****-hpt-patientdocs | AES256 | Off | Compliant |
| v1-501****-hpt-uploadpatientstore | AES256 | Enabled | Compliant |
3.5 — RDS Storage Encryption
| DB Instance | Engine | Version | Encrypted | KMS | Status |
|---|
| vm1lxyp9qd594ip | mysql | 8.0.44 | Yes | Yes | Compliant |
| vm1lxyp9qd594ip-2 | mysql | 8.0.44 | NO | No | Critical |
3.5 — EBS Volume Encryption
| Volume | Size | Encrypted | State | Status |
|---|
| vol-0**** | 50 GiB | Yes | in-use | Compliant |
| vol-0**** | 8 GiB | Yes | in-use | Compliant |
3.3 / 3.4 — PAN & SAD Exposure Scan (CloudWatch Logs, last 7 days)
Scanned 25 log group(s) via Logs Insights. Potential PAN (13–19 digit runs, Luhn-validated) matches are shown masked as first4****last4. SAD (CVV/track/PIN) keyword matches are flagged without printing any value.
No Luhn-valid PAN candidates detected in scanned logs.
SAD keyword hits (CVV/CVC/track/PIN): 12 occurrence(s) — values intentionally NOT displayed. Manual review required.
Control Mapping
| Control | Description | Status | Evidence |
|---|
| 3.5.1 | Render stored account data unreadable (S3 default encryption) | Compliant | 21/21 buckets with default encryption |
| 3.5.1 (RDS) | Storage encryption for databases holding account data | Critical | 1/2 DB instances encrypted |
| 3.5.1 (EBS) | Encryption of block storage volumes | Compliant | 2/2 volumes encrypted |
| 3.5.1 (Snapshots) | Manual DB snapshots encrypted | Compliant | 5/5 manual snapshots encrypted |
| 3.3.1 | Sensitive Authentication Data (SAD) not stored after authorization | Needs Review | 12 CVV/track/PIN keyword hit(s) in logs |
| 3.4.1 | PAN masked / not exposed in logs | Compliant | 0 Luhn-valid PAN candidate(s) in logs |
| 3.6.1 | Cryptographic keys protected (KMS) | Compliant | 10 KMS keys enabled; 1 customer-managed |
| 3.7.4 | Key rotation implemented | Gap | 0/1 customer keys with rotation |
Recommendations
HighEncrypt RDS instance(s) vm1lxyp9qd594ip-2 at rest (snapshot → restore into an encrypted instance; cannot enable in place). This is a PCI 3.5.1 requirement.
HighReview CVV/track/PIN keyword hits in logs — SAD must never be stored post-authorization (PCI 3.3.1).
MediumEnable customer-managed KMS key rotation on the auditlog-hipaa key.
LowEnable S3 versioning on data buckets to support tamper-evidence and recovery.
ProcessDocument data-retention & secure-deletion policy for stored account data (PCI 3.2.1).