Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Authentication strength: root protection, per-user MFA, password policy, credential rotation and network admin exposure.
Root MFAUser MFAPassword policyKey rotation
8.3 — Root Account Protection
| Check | Value | Status |
|---|
| Root MFA enabled | Yes | Compliant |
| Root access keys | None | Compliant |
8.4 — Per-User MFA (Console)
| User | Console Login | MFA | Status |
|---|
| ali-prod | Yes | No | Gap |
| craigprod | No | Yes | N/A |
| farhanprod | Yes | Yes | Compliant |
| hptprodui | No | No | N/A |
| payalkprod | Yes | No | Gap |
| rakheeprod | Yes | No | Gap |
| ses-smtp-user.20200903-084439 | No | No | N/A |
| ses-smtp-user.20230729-183444 | No | No | N/A |
| waris-prod | Yes | No | Gap |
8.3 — Password Policy
| Setting | Value | Status |
|---|
| Minimum length | 12 | Compliant |
| Max age (days) | 90 | Compliant |
| Reuse prevention | 5 | Compliant |
| Complexity (upper/lower/number/symbol) | True | Compliant |
Stale access keys (>365 days): craigprod (1782d), craigprod (1258d), ses-smtp-user.20200903-084439 (1074d), ses-smtp-user.20200903-084439 (2132d), ses-smtp-user.20230729-183444 (1073d).
Secrets Manager: 1 secret(s); 1 without automatic rotation (names/metadata only — values never read).
Control Mapping
| Control | Description | Status | Evidence |
|---|
| 8.3.1 (Root) | Root/administrative access uses MFA | Compliant | Root MFA=on |
| 8.4.1 | MFA for all console/interactive access | Gap | 4 console user(s) without MFA: ali-prod, payalkprod, rakheeprod, waris-prod |
| 8.4.2 | MFA for all access into the CDE | Gap | 4 interactive user(s) lack MFA |
| 8.3.6 | Password strength (≥12 chars, complexity) | Compliant | min length=12 |
| 8.3.9 | Password change frequency / max age | Compliant | max age=90d |
| 8.3.9 (Keys) | Programmatic credential rotation | Gap | 5 active key(s) >365d old: craigprod (1782d), craigprod (1258d), ses-smtp-user.20200903-084439 (1074d), ses-smtp-user.20200903-084439 (2132d), ses-smtp-user.20230729-183444 (1073d) |
| 8.x (Network) | Admin access (SSH/RDP) not open to Internet | Compliant | No security group exposes port 22 to 0.0.0.0/0 |
| 8.6.2 (Secrets) | Stored application credentials rotated | Needs Review | 1/1 Secrets Manager secrets without auto-rotation |
| 8.4 (Cognito) | Customer IdP MFA | N/A | No Cognito user pools present |
Recommendations
HighEnforce MFA for console user(s): ali-prod, payalkprod, rakheeprod, waris-prod. Several are members of the 'admin' group (PCI 8.4.1/8.4.2).
MediumRotate long-lived access keys: craigprod (1782d), craigprod (1258d), ses-smtp-user.20200903-084439 (1074d), ses-smtp-user.20200903-084439 (2132d), ses-smtp-user.20230729-183444 (1073d) (rotate ≤90 days; remove unused keys).
MediumEnable automatic rotation on 1 Secrets Manager secret(s).
ProcessDocument identity lifecycle: onboarding/offboarding, unique IDs, and 90-day inactive account disablement (PCI 8.2).