PCI DSS v4.0.1 — Requirement 4

Protect Cardholder Data with Strong Cryptography During Transmission
Environment: hptprod | us-east-2  |  Account: 501****  |  Generated: 2026-07-07 05:52 UTC
Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
TLS posture across CloudFront, ACM certificates, API Gateway, load balancers and S3 transport policy.
0
Critical
2
Gap
0
Needs Review
2
Compliant
0
AWS-Managed
1
N/A
CloudFront TLSCert validityS3 TLS-onlyAPI TLS

4.2 — CloudFront Viewer TLS

DistributionMin TLSViewer PolicyStatus
adm****TLSv1.2_2019redirect-to-httpsCompliant
api****TLSv1.2_2019redirect-to-httpsCompliant
log****TLSv1.2_2019redirect-to-httpsCompliant
for****TLSv1.2_2019redirect-to-httpsCompliant
log****TLSv1.2_2021redirect-to-httpsCompliant
for****TLSv1.2_2021redirect-to-httpsCompliant
por****TLSv1.2_2021redirect-to-httpsCompliant

4.2 — ACM Certificate Validity

DomainStatusDays to ExpiryIn Use ByStatus
hel****EXPIRED-19350Gap
*.rev****ISSUED562Needs Review
*.hel****ISSUED1304Compliant
por****ISSUED1231Compliant
No Application/Network Load Balancers present — public TLS termination handled at CloudFront/API Gateway.

4.2 — API Gateway Stages (managed TLS)

APIStageTransportAccess LogsStatus
Payment Gateway APIv1TLS (managed edge)YesCompliant
Security Automations - WAF Bad Bot APICFDeploymentStageTLS (managed edge)NoCompliant
Security Automations - WAF Bad Bot APIProdStageTLS (managed edge)NoCompliant

4.2 — S3 aws:SecureTransport Enforcement

BucketDeny insecure transportStatus
adm****NOGap
aws-cloudtrail-logs-501****-aa073ab8NOGap
bac****NOGap
cdk-hnb659fds-assets-501****-us-east-1YesCompliant
cf-templates-e4zlcd7q18st-us-east-2NOGap
cod****NOGap
for****NOGap
hp-cf-loggingNOGap
hp-vpc-flowlogNOGap
hptuat-mongodumpsNOGap
hptwarmeetingNOGap
log****NOGap
por****NOGap
regionalapi-s3bucketaccesslogs-wrzn070su9k7NOGap
rev****NOGap
v1-501****-hpg-artifactstoreNOGap
v1-501****-hpg-artifactstore-backupNOGap
v1-501****-hpg-secretstoreNOGap
v1-501****-hpt-itemstoreNOGap
v1-501****-hpt-patientdocsNOGap
v1-501****-hpt-uploadpatientstoreNOGap

Control Mapping

ControlDescriptionStatusEvidence
4.2.1 (CDN)Strong TLS for public HTTPS (CloudFront TLS1.2+ & HTTPS redirect)Compliant7/7 distributions TLS1.2+ & HTTPS-only/redirect
4.2.1 (Certs)Valid, non-expired TLS certificatesGap1 expired, 1 expiring<60d, of 4 certs
4.2.1 (ALB)Load balancer TLSN/ANo ELBv2 load balancers in account
4.2.1 (API)API Gateway enforces HTTPS (AWS-managed TLS endpoint)Compliant2 REST API(s), TLS terminated by AWS
4.2.1 (S3 TLS)S3 bucket policy denies non-TLS (aws:SecureTransport=false)Gap1/21 buckets enforce TLS-only

Recommendations

MediumRemove or replace EXPIRED ACM certificate(s): hel**** (not currently in use, but should be cleaned up).
MediumRenew certificate(s) approaching expiry (<60 days): *.rev****.
HighAdd an aws:SecureTransport=false Deny statement to bucket policies for 20 bucket(s) to reject clear-text HTTP access.
ProcessMaintain an inventory of trusted keys/certs used to protect PAN in transit (PCI 4.2.1.1).