Network exposure in production is tight. In production us-e****-1 there are 8 security groups and exactly one permits inbound traffic from 0.0.0.0/0 — the application load balancer's group, on ports 80 and 443 only. In production us-e****-2 there are 3 security groups and none is open to the internet. No production security group exposes SSH, RDP or a database port to the world. The application tier sits behind the load balancer and the production Aurora cluster is not publicly accessible. Segmentation between the native (us-e****-1) and legacy (us-e****-2) tiers is by separate VPCs and regions.
Each row takes a statement from Policy 12 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.
| The rule | Current state | Verdict |
|---|---|---|
| Rules restrict traffic to only what is required, default deny | Security groups are allow-list only. Production exposes 80/443 on the load balancer and nothing else. | Meets |
| No unnecessary ports or services exposed to the internet | True in production (both regions). Not true in dev us-e****-2. | Partial |
| Inbound administrative access (SSH) from the internet not allowed | No production security group allows 22 from 0.0.0.0/0. Two dev security groups do. | Partial |
| The cardholder data environment is segmented from untrusted networks | Native and legacy tiers are in separate accounts' VPCs and separate regions; the production database tier is not internet-reachable in us-e****-1. The legacy MySQL instances in us-e****-2 are publicly accessible (Procedure 07). | Partial |
| Network rules reviewed every [X] months | No review evidence exists; the stale dev rules below are the visible consequence. | Gap |
default, launch-wizard-1 and launch-wizard-2 carry inbound 0.0.0.0/0 rules including TCP 22 (SSH) and TCP 3306 (MySQL).default group opens TCP 3306; launch-wizard-1 opens 22, 80, 443, 3306, 8082 and 9000; launch-wizard-2 opens 22, 80 and 443. The policy applies to all environments and explicitly prohibits inbound administrative access from the public internet.launch-wizard-* naming indicates these groups were created ad hoc through the EC2 launch wizard rather than through infrastructure-as-code, so they sit outside the change-controlled path.