PCI DSS v4.0.1 — Requirement 7

Restrict Access to System Components and Cardholder Data by Business Need to Know
Environment: hptprod | us-east-2  |  Account: 501****  |  Generated: 2026-07-07 05:52 UTC

⚠ Critical items requiring immediate attention

Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Least-privilege posture for IAM users/roles and public-exposure checks on S3 and RDS.
2
Critical
0
Gap
2
Needs Review
2
Compliant
0
AWS-Managed
0
N/A
Admin sprawlWildcard trustS3 publicRDS public

7.2 — Privileged Access (IAM Users)

UserPrivilege SourceAttached PoliciesStatus
ali-prodadmin group(via group)Needs Review
craigprodscoped(via group)Compliant
farhanprodadmin group(via group)Needs Review
hptproduiscopedAmazonS3FullAccessCompliant
payalkprodadmin group(via group)Needs Review
rakheeprodadmin group(via group)Needs Review
ses-smtp-user.20200903-084439scoped(via group)Compliant
ses-smtp-user.20230729-183444scoped(via group)Compliant
waris-prodadmin group(via group)Needs Review

7.2 — S3 Public-Access Restriction

BucketPublic Access BlockEffectiveStatus
adm****0/4privateGap
aws-cloudtrail-logs-501****-aa073ab84/4privateCompliant
bac****4/4privateCompliant
cdk-hnb659fds-assets-501****-us-east-14/4privateCompliant
cf-templates-e4zlcd7q18st-us-east-20/4privateGap
cod****4/4privateCompliant
for****0/4privateGap
hp-cf-logging4/4privateCompliant
hp-vpc-flowlog4/4privateCompliant
hptuat-mongodumps0/4privateGap
hptwarmeeting4/4privateCompliant
log****0/4PUBLICCritical
por****0/4PUBLICCritical
regionalapi-s3bucketaccesslogs-wrzn070su9k74/4privateCompliant
rev****4/4privateCompliant
v1-501****-hpg-artifactstore0/4PUBLICCritical
v1-501****-hpg-artifactstore-backup4/4privateCompliant
v1-501****-hpg-secretstore4/4privateCompliant
v1-501****-hpt-itemstore3/4PUBLICCritical
v1-501****-hpt-patientdocs3/4PUBLICCritical
v1-501****-hpt-uploadpatientstore3/4PUBLICCritical
IAM Access Analyzer active findings (external/public access): 12 — review each for unintended cross-account/public exposure.

Control Mapping

ControlDescriptionStatusEvidence
7.2.1Access limited to least privilege / need-to-knowNeeds Review5 user(s) with account-admin: ali-prod, farhanprod, payalkprod, rakheeprod, waris-prod
7.2.2Privileges assigned by role/functionNeeds Review5 users in 'admin' group — verify each needs full admin
7.2.5 (Roles)No overly-permissive role trust policiesCompliant0 role(s) with wildcard trust of 59 total
7.2.1 (S3)S3 buckets restricted from public accessCritical6 bucket(s) evaluate as public; 11/21 have full PAB
7.2.1 (RDS)Databases not publicly reachableCritical2 DB(s) PubliclyAccessible: vm1lxyp9qd594ip, vm1lxyp9qd594ip-2
7.2.5 (Analyzer)Access review tooling enabled (IAM Access Analyzer)Compliant12 active external-access finding(s)

Recommendations

HighRemediate public S3 buckets (log****, por****, v1-501****-hpg-artifactstore, v1-501****-hpt-itemstore, v1-501****-hpt-patientdocs, v1-501****-hpt-uploadpatientstore): enable all 4 Public Access Block settings and remove public bucket policies/ACLs. Confirm no cardholder/patient data is exposed.
HighDisable PubliclyAccessible on RDS instance(s) vm1lxyp9qd594ip, vm1lxyp9qd594ip-2 and place behind private subnets/security groups.
MediumReview the 5-member 'admin' group and apply least privilege / just-in-time elevation.
ProcessPerform documented access reviews at least every 6 months (PCI 7.2.4).