How to Make your Infrastructure Compliant With PCI-DSS on AWS

A few hours ago Google announced that Google Cloud Platform is now certified for compliance with PCI-DSS. Payment Card Industry – Data Security Standard are security standards built by the Payment Card Industry Council to minimize the credit card frauds. These standards are applicable to organizations who deal with payment cards including credit cards and debit cards and have to ensure that cardholder’s data is completely protected from misuse of their personal information. Compliance with this standard enables customers to hold, process, or exchange cardholder information from any branded credit card.

Amazon Web Services works upon a shared security responsibility model where AWS responsibility is to secure the underlying infrastructure and it is your responsibility to secure any connection made to and any data put upon that infrastructure. For example, it is AWS’s responsibility to ensure the security of their physical infrastructure, facilities, virtual infrastructure while when it is client’s responsibility when it comes to OS patching, data encryption, and of course the application itself.
PCI-DSS on AWS
AWS has already achieved PCI-DSS compliance for shared hosting providers and has successfully validated for Level-1 service provider under PCI-DSS version 3.0. In this post, we will see how you can achieve PCI-DSS compliance for your infrastructure on top of AWS. In any case, you should always ask for an independent Quality Security Assessor (QSA) to validate that your environment is PCI-DSS compliant. Nevertheless, the following 12-item checklist can really help you harden your infrastructure and protect your customers from frauds.

Make your application compliant with PCI-DSS on AWS: a 12-items checklist

1- Install and Maintain a Firewall configuration to protect cardholder data

  • Ensure your environment is configured under Virtual Private Cloud (VPC) where components are segregated into public and private subnets, the former acting as DMZ zones.
  • Ensure all critical data (like cardholder data) is stored in private subnets, not directly accessible from the Internet.
  • Use a correct combination of security groups and network ACLs.
  • Limit access to critical components.
  • Ensure that along with ingress and egress rules for security groups and network ACLs are also controlled for critical components.
  • Use Unified Threat Management (UTM) tools in DMZ zones as an additional layer of security.
  • Enable a formal process of approval to all changes made to network configuration, security groups, network ACLs, etc.

2- Do not use vendor-supplied defaults for system passwords and other security parameters

  • One primary function per instance, that is: using a single instance for multiple functions (like a web server, plus an SFTP, plus a database server, etc) lowers the security level for your environment. The functions with lower security levels will introduce security weaknesses for other functions.
  • Remove unwanted packages, services, and scripts from your instances.
  • Enable additional security measures on required services like passphrases on SSH key pairs or implement passwords for restarting services.

3- Protect stored cardholder data

  • Encrypt Cardholders Data at rest:
    • If cardholder data is stored on a database on EC2, the client can leverage full disk encryption to encrypt the data. There are multiple tools available on AWS Marketplace which helps us to encrypt root and additional EBS volumes.
    • If cardholder data is stored on a database on RDS, the client can either leverage on transparent data encryption (TDE) or encrypt data over SQL queries. Oracle and SQL server on RDS supports transparent data encryption. If you are using MySQL or PostgreSQL, you have to rely on SQL queries to encrypt data.
  • Ensure only minimal required cardholder data is stored.
  • Define policies for sensitive data retention period and processes for secure deletion of sensitive data.
  • Rotate encryption keys and store at fewest possible locations.
  • There are multiple ways to store your encryption keys:
    • using key-encrypting keys – do it yourself
    • rely on AWS partner solutions on AWS Marketplace
    • use the recently launched AWS Key Management service which integrates with S3, EBS, and Redshift
    • use AWS CloudHSM
  • Limit cardholder’s data access to necessary individuals only.

4- Encrypt transmission of cardholder data across open, public networks

  • It is important to encrypt sensitive information during transmission over public networks. To enable secure transmission over public networks, you need to use the appropriate certificates on EC2 instances or ELB.
  • AWS Elastic Load Balancers provides support for SSL certificates which allow you to perform SSL termination at the load balancing layer.

5- Maintain a Vulnerability Management Program

  • Configure anti-virus softwares on EC2 instances and ensure all of them are timely updated.
  • Use vulnerability scanners in your AWS environment. They help you to prepare for PCI-DSS audits too.

6- Develop and Maintain secure systems and applications

  • Ensure all security patches are reviewed, tested and timely applied on your EC2 instances and other AWS resources.
  • Keep looking at AWS related security bulletins.
  • Develop your internal and external software according to PCI-DSS guidelines.
  • It is a best practice to segregate your development, staging and production environment.
  • Use IAM groups, roles, and users. Ensure there are no test IAM users.
  • Enable MFA for IAM users with a strong password policy.
  • Rotate IAM users access key and secret access key on regular intervals.
  • Enable Cloudtrail logs and integrate them with Cloudwatch. Setup alerts on Cloudtrail activity. For example, send an alert email for failed user login after 3 attempts.
  • If you are serving web application, ensure common coding vulnerabilities (SQL injection, Cross site scripting, directory traversal, etc) are taken care at the application level or use a web application firewall in front of your web servers.
  • Any changes made to your environment has to be approved and documented.
  • Perform a regular security audit of your environment.
  • Avoid manual deployment. Leverage on automation.

7- Restrict access to cardholders data

  • Use strict IAM user policies – limit AWS services access to individuals whose job requires such access.
  • If your organization supports SAML, you can enable single sign-on (SSO) and let users of your organization directly authenticate to AWS management console without having IAM identities.

8- Identify and authenticate access to system components

  • Ensure that everyone (even administrators) access the AWS management console via IAM accounts. Root account credentials shouldn’t be used in any case.
  • Enable two-factor authentication for AWS accounts. AWS has support for virtual and hardware MFA devices. For virtual MFA devices, you need to install apps on your mobile phone. It supports iPhone, Android, Windows and Blackberry phones.
  • There shouldn’t be any shared credentials. Assign unique IDs to individuals. This holds true for IAM accounts and EC2 instances.
  • Build production ready AMI’s and launch them without key pairs. This way no one will be able to login into your instances.

9- Restrict physical access to cardholder’s data

  • AWS is already PCI-DSS compliant, so that removes the burden of physically securing your cardholder’s data. No action needed here.

10- Regularly monitor and test networks

  • Perform regular audits of your Cloudtrail logs to identify login details, creation, and deletion of resources, etc.
  • Deploy intrusion detection and prevention systems which helps us to monitor instance login details, security events, file integrity, change detection, etc.
  • Ensure all instances and resources are in the same time zone and synchronized with the same NTP server.

11- Regularly test security systems and processes

  • Perform vulnerability scanning, penetration testing, file integrity monitoring, log inspection, etc. on your environment at regular intervals. It is necessary to inform AWS before performing penetration testing.
  • Perform third party audit of your environment.

12- Maintain a policy that addresses information security for all personnel

  • All security policies should be documented properly and pass to individuals.
  • AWS inventory, login information, resource details should be regularly updated.
  • Implement an incident response plan incase of a security breach. A 24×7 monitoring team can help you to immediately respond to alerts.

Avatar

Written by

Sanket Dangi

Head of Managed Services at REAN Cloud. Before joining REAN Cloud, I was CEO and Founder of StraightArc Solutions which was later acquired by REAN Cloud. I started my career working on cloud computing. Loves to talk about DevOps, System Administration, Scalability, High Availability, Disaster Recovery and Cloud Security. Apart from work, I love to meet people, travel and watch sports.


Related Posts

Amanda Cross
Amanda Cross
— January 7, 2021

New Content: AWS Terraform, Java Programming Lab Challenges, Azure DP-900 & DP-300 Certification Exam Prep, Plus Plenty More Amazon, Google, Microsoft, and Big Data Courses

This month our Content Team continues building the catalog of courses for everyone learning about AWS, GCP, and Microsoft Azure. In addition, this month’s updates include several Java programming lab challenges and a couple of courses on big data. In total, we released five new learning...

Read more
  • AWS
  • Azure
  • DevOps
  • Google Cloud Platform
  • Machine Learning
  • programming
Avatar
Stuart Scott
— December 17, 2020

Where Should You Be Focusing Your AWS Security Efforts?

Another day, another re:Invent session! This time I listened to Stephen Schmidt’s session, “AWS Security: Where we've been, where we're going.” Amongst covering the highlights of AWS security during 2020, a number of newly added AWS features/services were discussed, including: AWS Audit...

Read more
  • AWS
  • AWS re:Invent
  • cloud security
Joe Nemer
Joe Nemer
— December 4, 2020

AWS re:Invent: 2020 Keynote Top Highlights and More

We’ve gotten through the first five days of the special all-virtual 2020 edition of AWS re:Invent. It’s always a really exciting time for practitioners in the field to see what features and services AWS has cooked up for the year ahead.  This year’s conference is a marathon and not a...

Read more
  • AWS
  • AWS Glue Elastic Views
  • AWS re:Invent
Bryony Harrower
Bryony Harrower
— November 6, 2020

WARNING: Great Cloud Content Ahead

At Cloud Academy, content is at the heart of what we do. We work with the world’s leading cloud and operations teams to develop video courses and learning paths that accelerate teams and drive digital transformation. First and foremost, we listen to our customers’ needs and we stay ahea...

Read more
  • AWS
  • Azure
  • content roadmap
  • GCP
Joe Nemer
Joe Nemer
— October 25, 2020

Excelling in AWS, Azure, and Beyond – How Danut Prisacaru Prepares for the Future

Meet Danut Prisacaru. Danut has been a Software Architect for the past 10 years and has been involved in Software Engineering for 30 years. He’s passionate about software and learning, and jokes that coding is basically the only thing he can do well (!). We think his enthusiasm shines t...

Read more
  • AWS
  • careers
  • champions
  • upskilling
Joe Nemer
Joe Nemer
— October 14, 2020

New Content: AWS Data Analytics – Specialty Certification, Azure AI-900 Certification, Plus New Learning Paths, Courses, Labs, and More

This month our Content Team released two big certification Learning Paths: the AWS Certified Data Analytics - Speciality, and the Azure AI Fundamentals AI-900. In total, we released four new Learning Paths, 16 courses, 24 assessments, and 11 labs.  New content on Cloud Academy At any ...

Read more
  • AWS
  • Azure
  • DevOps
  • Google Cloud Platform
  • Machine Learning
  • programming
Joe Nemer
Joe Nemer
— September 15, 2020

New Content: Azure DP-100 Certification, Alibaba Cloud Certified Associate Prep, 13 Security Labs, and Much More

This past month our Content Team served up a heaping spoonful of new and updated content. Not only did our experts release the brand new Azure DP-100 Certification Learning Path, but they also created 18 new hands-on labs — and so much more! New content on Cloud Academy At any time, y...

Read more
  • AWS
  • Azure
  • DevOps
  • Google Cloud Platform
  • Machine Learning
  • programming
Joe Nemer
Joe Nemer
— August 28, 2020

AWS Certification Practice Exam: What to Expect from Test Questions

If you’re building applications on the AWS cloud or looking to get started in cloud computing, certification is a way to build deep knowledge in key services unique to the AWS platform. AWS currently offers 12 certifications that cover major cloud roles including Solutions Architect, De...

Read more
  • AWS
  • AWS Certifications
Patrick Navarro
Patrick Navarro
— August 25, 2020

Overcoming Unprecedented Business Challenges with AWS

From auto-scaling applications with high availability to video conferencing that’s used by everyone, every day —  cloud technology has never been more popular or in-demand. But what does this mean for experienced cloud professionals and the challenges they face as they carve out a new p...

Read more
  • AWS
  • Cloud Adoption
  • digital transformation
Avatar
Andrew Larkin
— August 18, 2020

Constant Content: Cloud Academy’s Q3 2020 Roadmap

Hello —  Andy Larkin here, VP of Content at Cloud Academy. I am pleased to release our roadmap for the next three months of 2020 — August through October. Let me walk you through the content we have planned for you and how this content can help you gain skills, get certified, and...

Read more
  • alibaba
  • AWS
  • Azure
  • content roadmap
  • Content updates
  • DevOps
  • GCP
  • Google Cloud
  • New content
Alisha Reyes
Alisha Reyes
— August 5, 2020

New Content: Alibaba, Azure AZ-303 and AZ-304, Site Reliability Engineering (SRE) Foundation, Python 3 Programming, 16 Hands-on Labs, and Much More

This month our Content Team did an amazing job at publishing and updating a ton of new content. Not only did our experts release the brand new AZ-303 and AZ-304 Certification Learning Paths, but they also created 16 new hands-on labs — and so much more! New content on Cloud Academy At...

Read more
  • AWS
  • Azure
  • DevOps
  • Google Cloud Platform
  • Machine Learning
  • programming
Alisha Reyes
Alisha Reyes
— July 16, 2020

Blog Digest: Which Certifications Should I Get?, The 12 Microsoft Azure Certifications, 6 Ways to Prevent a Data Breach, and More

This month, we were excited to announce that Cloud Academy was recognized in the G2 Summer 2020 reports! These reports highlight the top-rated solutions in the industry, as chosen by the source that matters most: customers. We're grateful to have been nominated as a High Performer in se...

Read more
  • AWS
  • Azure
  • blog digest
  • Certifications
  • Cloud Academy
  • OWASP
  • OWASP Top 10
  • Security
  • VPCs