⚠ Critical items requiring immediate attention
- Unencrypted RDS storage undermines media-at-rest protection (cross-refs Req 3).
Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Shared-responsibility framing for physical controls (AWS) and customer-side media protection, backup and retention.
PhysicalMedia encBackupsLog retention
Physical security of the underlying data centers is an AWS responsibility under the Shared Responsibility Model. Evidence is provided by AWS via AWS Artifact (SOC 2, PCI DSS AOC). Customer responsibility covers protection of stored media (encryption), backups, and retention.
9.x — AWS-Managed Physical Controls
| Control | Description | Provision | Status |
|---|
| 9.1–9.4 | Physical facility access, media handling, device security | AWS data centers (SOC/PCI AOC via AWS Artifact) | AWS-Managed |
| 9.5 | POI/POS device protection | No point-of-interaction devices in cloud scope | N/A |
9.4 — Customer Media Protection (Encryption at Rest)
| Media Type | Encryption | Status |
|---|
| S3 objects | 21/21 encrypted | Compliant |
| EBS volumes | 2/2 encrypted | Compliant |
| RDS storage | 1/2 encrypted | Critical |
9.4 — Backup & Retention
| Backup Vault | Recovery Points | Immutable (Locked) | Encrypted |
|---|
| Default | 0 | No | Compliant |
| HP-BACKUP-VAULT | 3 | No | Compliant |
Control Mapping
| Control | Description | Status | Evidence |
|---|
| 9.1.1 | Physical access controls to data centers | AWS-Managed | AWS Shared Responsibility — obtain AOC via AWS Artifact |
| 9.5.1 | POI device inventory/inspection | N/A | No physical POI/POS devices in this environment |
| 9.4.1 (Media) | Stored media encrypted / access-controlled | Critical | S3 0 / EBS 0 / RDS 1 unencrypted |
| 9.4.1 (Backup) | Backups protected & retained | Compliant | 2 vault(s), 3 recovery point(s); 1 backup plan(s) |
| 9.4.1 (DLM) | Snapshot lifecycle policies healthy | Gap | 1 DLM policy(ies); one in ERROR state |
| 9.4.1 (Logs) | Log retention ≥90 days | Gap | 50/74 log groups retain ≥90 days |
| 9.5.1 (KMS) | Cryptographic media keys managed | Compliant | 10 KMS keys enabled protecting stored media |
Recommendations
ProcessDownload and retain the current AWS PCI DSS Attestation of Compliance (AOC) from AWS Artifact as physical-control evidence (PCI 9 / 12.8/12.9).
HighEncrypt RDS storage to satisfy media-at-rest protection.
MediumConsider AWS Backup Vault Lock (immutable/WORM) for tamper-resistant retention of backups.
MediumInvestigate the DLM lifecycle policy in ERROR state so EBS snapshot retention is enforced.
LowSet explicit log-group retention (≥90 days, ≥365 for audit) rather than never-expire/unset.