Compliance, Mapped to Your Cloud
Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

PCI DSS 3.2.1
The Payment Card Industry Data Security Standard (PCI DSS) protects cardholder data through requirements for secure networks, strong access control, encryption, and continuous monitoring.
Controls assessed
Limit inbound Internet traffic to IP addresses within the DMZ.
Do not allow unauthorized outbound traffic from the cardholder data environment to the Internet.
Do not store sensitive authentication data after authorization (even if it is encrypted). Render all sensitive authentication data unrecoverable upon completion of the authorization process. Issuers and related entities may store sensitive authentication data if there is a business justification, and the data is stored securely.
Render PAN unreadable anywhere it is stored - including on portable digital media, backup media, in logs, and data received from or stored by wireless networks. Technology solutions for this requirement may include strong one-way hash functions of the entire PAN, truncation, index tokens with securely stored pads, or strong cryptography.
Use strong cryptography and security protocols to safeguard sensitive cardholder data during transmission over open, public networks (eg. Internet, wireless technologies, cellular technologies, General Packet Radio Service \[GPRS\], satellite communications). Ensure wireless networks transmitting cardholder data or connected to the cardholder data environment use industry best practices to implement strong encryption for authentication and transmission.
Insecure cryptographic storage.
Define access needs for each role, including: - System components and data resources that each role needs to access for their job function - Level of privilege required (for example, user, administrator, etc.) for accessing resources.
Restrict access to privileged user IDs to least privileges necessary to perform job responsibilities.
Assign access based on individual personnel's job classification and function.
Coverage of all system components.
Passwords/phrases must meet the following: - Require a minimum length of at least seven characters. - Contain both numeric and alphabetic characters. Alternatively, the passwords/phrases must have complexity and strength at least equivalent to the parameters specified above.
Do not allow an individual to submit a new password/phrase that is the same as any of the last four passwords/phrases he or she has used.
Incorporate multi-factor authentication for all non-console access into the CDE for personnel with administrative access.
Write logs for external-facing technologies onto a secure, centralized, internal log server or media device.
Perform quarterly internal vulnerability scans and rescans as needed, until all “high-risk” vulnerabilities (as identified in Requirement 6.1) are resolved. Scans must be performed by qualified personnel.
Deploy anti-virus software on all systems commonly affected by malicious software (particularly personal computers and servers). For systems not affected commonly by malicious software, perform periodic evaluations to evaluate evolving malware threats and confirm whether such systems continue to not require anti-virus software.
Protect all system components and software from known vulnerabilities by installing applicable vendor-supplied security patches. Install critical security patches within one month of release.
Ensure all public-facing web applications are protected against known attacks, either by performing application vulnerability assessment at least annually and after any changes, or by installing an automated technical solution that detects and prevents web-based attacks (for example, a web-application firewall) in front of public-facing web applications, to continually check all traffic.
Control addition, deletion, and modification of user IDs, credentials, and other identifier objects.
Immediately revoke access for any terminated users.
Manage IDs used by thid parties to access, support, or maintain system components via remote access. Remote access are as follows: - Enabled only during the time period needed and disabled when not in use. - Monitored when in use.
See where you stand against any framework
Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.
