PCI DSS v4.0.1 — Requirement 9

Restrict Physical Access to Cardholder Data
Environment: hptprod | us-east-2  |  Account: 501****  |  Generated: 2026-07-07 05:52 UTC

⚠ Critical items requiring immediate attention

Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Shared-responsibility framing for physical controls (AWS) and customer-side media protection, backup and retention.
1
Critical
2
Gap
0
Needs Review
2
Compliant
1
AWS-Managed
1
N/A
PhysicalMedia encBackupsLog retention
Physical security of the underlying data centers is an AWS responsibility under the Shared Responsibility Model. Evidence is provided by AWS via AWS Artifact (SOC 2, PCI DSS AOC). Customer responsibility covers protection of stored media (encryption), backups, and retention.

9.x — AWS-Managed Physical Controls

ControlDescriptionProvisionStatus
9.1–9.4Physical facility access, media handling, device securityAWS data centers (SOC/PCI AOC via AWS Artifact)AWS-Managed
9.5POI/POS device protectionNo point-of-interaction devices in cloud scopeN/A

9.4 — Customer Media Protection (Encryption at Rest)

Media TypeEncryptionStatus
S3 objects21/21 encryptedCompliant
EBS volumes2/2 encryptedCompliant
RDS storage1/2 encryptedCritical

9.4 — Backup & Retention

Backup VaultRecovery PointsImmutable (Locked)Encrypted
Default0NoCompliant
HP-BACKUP-VAULT3NoCompliant

Control Mapping

ControlDescriptionStatusEvidence
9.1.1Physical access controls to data centersAWS-ManagedAWS Shared Responsibility — obtain AOC via AWS Artifact
9.5.1POI device inventory/inspectionN/ANo physical POI/POS devices in this environment
9.4.1 (Media)Stored media encrypted / access-controlledCriticalS3 0 / EBS 0 / RDS 1 unencrypted
9.4.1 (Backup)Backups protected & retainedCompliant2 vault(s), 3 recovery point(s); 1 backup plan(s)
9.4.1 (DLM)Snapshot lifecycle policies healthyGap1 DLM policy(ies); one in ERROR state
9.4.1 (Logs)Log retention ≥90 daysGap50/74 log groups retain ≥90 days
9.5.1 (KMS)Cryptographic media keys managedCompliant10 KMS keys enabled protecting stored media

Recommendations

ProcessDownload and retain the current AWS PCI DSS Attestation of Compliance (AOC) from AWS Artifact as physical-control evidence (PCI 9 / 12.8/12.9).
HighEncrypt RDS storage to satisfy media-at-rest protection.
MediumConsider AWS Backup Vault Lock (immutable/WORM) for tamper-resistant retention of backups.
MediumInvestigate the DLM lifecycle policy in ERROR state so EBS snapshot retention is enforced.
LowSet explicit log-group retention (≥90 days, ≥365 for audit) rather than never-expire/unset.