Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
Google Cloud logo

PCI DSS v3.2.1

20 controls
58 checks mapped

The Payment Card Industry Data Security Standard (PCI DSS) protects cardholder data through requirements for secure networks, strong access control, encryption, and continuous monitoring.

Controls assessed

1.2.1 - Restrict inbound and outbound traffic to that which is necessary for the cardholder data environment, and specifically deny all other traffic32

Customers are responsible for implementing GCP firewall rules and limiting inbound/outbound traffic to only business justified and necessary traffic. Customers must define explicit GCP firewall rules and deny all other traffic. Customers are responsible for verifying inbound and outbound traffic for their CDE which includes GCP GCE and GCS, and GCP VPCs. Customers are responsible for denying any traffic that is not explicitly required for the GCP Product to function.

1.3 - Prohibit direct public access between the Internet and any system component in the cardholder data environment2

Customers are responsible for implementing firewall rules and limiting ingress traffic to defined ports and protocols necessary for GCE instances within their DMZ.

1.3.2 - Limit inbound Internet traffic to IP addresses within the DMZ2

Customers are responsible for implementing firewall rules and limiting ingress traffic to defined ports and protocols necessary for GCE instances within their DMZ.

1.3.4 - Do not allow unauthorized outbound traffic from the cardholder data environment to the Internet1

Customers are responsible for implementing perimeter firewalls and configuring firewall rules and ACLs for their in-scope GCP Products. Customers are responsible for developing appropriate firewall rules or using additional firewall technologies to develop appropriate DMZ and internal networks.

1.3.7 - Do not disclose private IP addresses and routing information to unauthorized parties1

Customers are responsible for developing appropriate configuration on GCP GCE to prevent the disclosure of IP Addresses and routing information.

2.1 - Always change vendor-supplied defaults and remove or disable unnecessary default accounts before installing a system on the network1

Customers are responsible for changing vendor-supplied defaults on GCP products as applicable deployed within the customers CDE.

2.2 - Develop configuration standards for all system components3

Customers are responsible for documenting, developing and implementing configuration standards for the GCP products in use that are within the CDE. This includes configuration standards for GCE, VPC, and GCS based on industry standards and hardening guidelines.

3.5 - Document and implement procedures to protect keys used to secure stored cardholder data against disclosure and misuse2

Customers are responsible for maintaining appropriate data retention policies and procedures, encryption technologies and key management processes for maintaining PCI DSS requirements.

3.5.2 - Restrict access to cryptographic keys to the fewest number of custodians necessary1

Customers are responsible for maintaining appropriate data retention policies and procedures, encryption technologies and key management processes for maintaining PCI DSS requirements.

4.1 - Use strong cryptography and security protocols to safeguard sensitive cardholder data during transmission over open, public networks3

GCP customers are responsible for strong cryptography and security protocols for connections to any storage system that is transmitting cardholder data. Customers are responsible for ensuring the data is encrypted in transit over open, public networks. Customers are responsible for using web browsers and client endpoints that do not support TLS1.0 or ciphers that are weaker than AES128.

6.6 - For public-facing web applications, address new threats and vulnerabilities on an ongoing basis and ensure these applications are protected against known attacks1

Customers are responsible for Web Application Filtering or application security reviews for web applications deployed on customer-managed GCE instances.

7.1 - Limit access to system components and cardholder data to only those individuals whose job requires such access5

GCP Customers are responsible for managing access to all GCP products (GCE, VPC, GCS) that are included in their CDE. GCP provides various mechanisms for controlling access to the services including IAM for integration with corporate directories and granular access controls to the GCP Management Console.

7.1.2 - Restrict access to privileged user IDs to least privileges necessary3

GCP Customers are responsible for managing access to all GCP products (GCE, VPC, GCS) that are included in their CDE. GCP provides various mechanisms for controlling access to the services including IAM for integration with corporate directories and granular access controls to the GCP Management Console.

10.1 - Implement audit trails to link all access to system components to each individual user4

GCP customers are responsible for configuring logging parameters, when available. Customers are responsible to log and monitor their GCE, and GKE instances, systems and applications in alignment with PCI DSS requirements.

10.2 - Implement automated audit trails for all system components to reconstruct the events4

GCP customers are responsible for configuring logging parameters, when available. Customers are responsible to log and monitor their GCE, and GKE instances, systems and applications in alignment with PCI DSS requirements.

10.2.2 - All actions taken by any individual with root or administrative privileges1

GCP customers are responsible for configuring logging parameters, when available. Customers are responsible to log and monitor their GCE, and GKE instances, systems and applications in alignment with PCI DSS requirements.

10.2.7 - Creation and deletion of system-level objects1

GCP customers are responsible for configuring logging parameters, when available. Customers are responsible to log and monitor their GCE, and GKE instances, systems and applications in alignment with PCI DSS requirements.

10.4 - Using time-synchronization technology, synchronize all critical system clocks and times1

GCP customers are responsible for appropriately managing network time protocol (NTP) configuration for their GCE and GKE instances.

10.4.3 - Time settings are received from industry-accepted time sources1

GCP customers are responsible for appropriately managing network time protocol (NTP) configuration for their GCE and GKE instances.

10.5 - Secure audit trails so they cannot be altered3

GCP Customers are responsible for setting permissions and access controls for audit logs. Identity Access Management (IAM) can be used to set permissions for accounts with access to online and offline log storage locations. Customers are responsible to log and monitor their GCE and GKE systems and instances in alignment with PCI DSS requirements.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.