PCI DSS v4.0.1 — Requirement 8

Identify Users and Authenticate Access to System Components
Environment: hptprod | us-east-2  |  Account: 501****  |  Generated: 2026-07-07 05:52 UTC
Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Authentication strength: root protection, per-user MFA, password policy, credential rotation and network admin exposure.
0
Critical
3
Gap
1
Needs Review
4
Compliant
0
AWS-Managed
1
N/A
Root MFAUser MFAPassword policyKey rotation

8.3 — Root Account Protection

CheckValueStatus
Root MFA enabledYesCompliant
Root access keysNoneCompliant

8.4 — Per-User MFA (Console)

UserConsole LoginMFAStatus
ali-prodYesNoGap
craigprodNoYesN/A
farhanprodYesYesCompliant
hptproduiNoNoN/A
payalkprodYesNoGap
rakheeprodYesNoGap
ses-smtp-user.20200903-084439NoNoN/A
ses-smtp-user.20230729-183444NoNoN/A
waris-prodYesNoGap

8.3 — Password Policy

SettingValueStatus
Minimum length12Compliant
Max age (days)90Compliant
Reuse prevention5Compliant
Complexity (upper/lower/number/symbol)TrueCompliant
Stale access keys (>365 days): craigprod (1782d), craigprod (1258d), ses-smtp-user.20200903-084439 (1074d), ses-smtp-user.20200903-084439 (2132d), ses-smtp-user.20230729-183444 (1073d).
Secrets Manager: 1 secret(s); 1 without automatic rotation (names/metadata only — values never read).

Control Mapping

ControlDescriptionStatusEvidence
8.3.1 (Root)Root/administrative access uses MFACompliantRoot MFA=on
8.4.1MFA for all console/interactive accessGap4 console user(s) without MFA: ali-prod, payalkprod, rakheeprod, waris-prod
8.4.2MFA for all access into the CDEGap4 interactive user(s) lack MFA
8.3.6Password strength (≥12 chars, complexity)Compliantmin length=12
8.3.9Password change frequency / max ageCompliantmax age=90d
8.3.9 (Keys)Programmatic credential rotationGap5 active key(s) >365d old: craigprod (1782d), craigprod (1258d), ses-smtp-user.20200903-084439 (1074d), ses-smtp-user.20200903-084439 (2132d), ses-smtp-user.20230729-183444 (1073d)
8.x (Network)Admin access (SSH/RDP) not open to InternetCompliantNo security group exposes port 22 to 0.0.0.0/0
8.6.2 (Secrets)Stored application credentials rotatedNeeds Review1/1 Secrets Manager secrets without auto-rotation
8.4 (Cognito)Customer IdP MFAN/ANo Cognito user pools present

Recommendations

HighEnforce MFA for console user(s): ali-prod, payalkprod, rakheeprod, waris-prod. Several are members of the 'admin' group (PCI 8.4.1/8.4.2).
MediumRotate long-lived access keys: craigprod (1782d), craigprod (1258d), ses-smtp-user.20200903-084439 (1074d), ses-smtp-user.20200903-084439 (2132d), ses-smtp-user.20230729-183444 (1073d) (rotate ≤90 days; remove unused keys).
MediumEnable automatic rotation on 1 Secrets Manager secret(s).
ProcessDocument identity lifecycle: onboarding/offboarding, unique IDs, and 90-day inactive account disablement (PCI 8.2).