Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
Azure logo

PCI DSS 3.2.1

21 controls
31 checks mapped

The Payment Card Industry Data Security Standard (PCI DSS) protects cardholder data through requirements for secure networks, strong access control, encryption, and continuous monitoring.

Controls assessed

PCI DSS 1.3.22

Limit inbound Internet traffic to IP addresses within the DMZ.

PCI DSS 1.3.42

Do not allow unauthorized outbound traffic from the cardholder data environment to the Internet.

PCI DSS 3.25

Do not store sensitive authentication data after authorization (even if it is encrypted). Render all sensitive authentication data unrecoverable upon completion of the authorization process. Issuers and related entities may store sensitive authentication data if there is a business justification, and the data is stored securely.

PCI DSS 3.48

Render PAN unreadable anywhere it is stored - including on portable digital media, backup media, in logs, and data received from or stored by wireless networks. Technology solutions for this requirement may include strong one-way hash functions of the entire PAN, truncation, index tokens with securely stored pads, or strong cryptography.

PCI DSS 4.18

Use strong cryptography and security protocols to safeguard sensitive cardholder data during transmission over open, public networks (eg. Internet, wireless technologies, cellular technologies, General Packet Radio Service \[GPRS\], satellite communications). Ensure wireless networks transmitting cardholder data or connected to the cardholder data environment use industry best practices to implement strong encryption for authentication and transmission.

PCI DSS 6.5.38

Insecure cryptographic storage.

PCI DSS 7.1.12

Define access needs for each role, including: - System components and data resources that each role needs to access for their job function - Level of privilege required (for example, user, administrator, etc.) for accessing resources.

PCI DSS 7.1.22

Restrict access to privileged user IDs to least privileges necessary to perform job responsibilities.

PCI DSS 7.1.32

Assign access based on individual personnel's job classification and function.

PCI DSS 7.2.15

Coverage of all system components.

PCI DSS 8.2.36

Passwords/phrases must meet the following: - Require a minimum length of at least seven characters. - Contain both numeric and alphabetic characters. Alternatively, the passwords/phrases must have complexity and strength at least equivalent to the parameters specified above.

PCI DSS 8.2.56

Do not allow an individual to submit a new password/phrase that is the same as any of the last four passwords/phrases he or she has used.

PCI DSS 8.3.15

Incorporate multi-factor authentication for all non-console access into the CDE for personnel with administrative access.

PCI DSS 10.5.43

Write logs for external-facing technologies onto a secure, centralized, internal log server or media device.

PCI DSS 11.2.13

Perform quarterly internal vulnerability scans and rescans as needed, until all “high-risk” vulnerabilities (as identified in Requirement 6.1) are resolved. Scans must be performed by qualified personnel.

PCI DSS 5.13

Deploy anti-virus software on all systems commonly affected by malicious software (particularly personal computers and servers). For systems not affected commonly by malicious software, perform periodic evaluations to evaluate evolving malware threats and confirm whether such systems continue to not require anti-virus software.

PCI DSS 6.23

Protect all system components and software from known vulnerabilities by installing applicable vendor-supplied security patches. Install critical security patches within one month of release.

PCI DSS 6.63

Ensure all public-facing web applications are protected against known attacks, either by performing application vulnerability assessment at least annually and after any changes, or by installing an automated technical solution that detects and prevents web-based attacks (for example, a web-application firewall) in front of public-facing web applications, to continually check all traffic.

PCI DSS 8.1.25

Control addition, deletion, and modification of user IDs, credentials, and other identifier objects.

PCI DSS 8.1.32

Immediately revoke access for any terminated users.

PCI DSS 8.1.55

Manage IDs used by thid parties to access, support, or maintain system components via remote access. Remote access are as follows: - Enabled only during the time period needed and disabled when not in use. - Monitored when in use.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.