{"id":1732,"date":"2023-11-28T12:39:24","date_gmt":"2023-11-28T11:39:24","guid":{"rendered":"https:\/\/pcihispano.com\/?p=1732"},"modified":"2026-05-06T19:16:04","modified_gmt":"2026-05-06T17:16:04","slug":"aws-publica-su-guia-de-cumplimiento-con-pci-dss-v4-0","status":"publish","type":"post","link":"https:\/\/www.pcihispano.com\/en\/aws-publica-su-guia-de-cumplimiento-con-pci-dss-v4-0\/","title":{"rendered":"AWS publishes its PCI DSS v4.0 compliance guide"},"content":{"rendered":"<p><span class=\"intro-text\">As part of its efforts to facilitate the implementation of controls of different security standards in its customers' environments, <a href=\"https:\/\/aws.amazon.com\/es\/\" target=\"_blank\" rel=\"noopener\">Amazon Web Services<\/a> (AWS), as a cloud service provider (<em>Cloud Service Provider<\/em> \u2013 CSP), published in August 2023 the update of its Compliance Guide in PCI DSS, this time aligning it with the controls of this standard in its version 4.0.<\/span><\/p>\n<p>According to the definition of <a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/145\/final\" target=\"_blank\" rel=\"noopener\">NIST<\/a>, ,<span class=\"highlight\"><em>Cloud computing is a model that enables ubiquitous, convenient and on-demand access to a shared set of configurable computing resources (e.g. networks, servers, storage, applications and services) that can be quickly provisioned and released with minimal management effort or interaction with the service provider.\u2019<\/em><\/span>. The main factors driving the growth of the global cloud computing market are the expansion of digital transformation in companies, the increase in Internet adoption (including the use of 5G), the massification of mobile devices worldwide and the increased consumption of state-of-the-art services and platforms, including IoT and industrial solutions, Big Data, <em>edge computing<\/em> and real-time analytics and Artificial Intelligence (AI), the use of which increases the value of computer technology among companies.<\/p>\n<p>Currently, the cloud services market is mature and consolidated, with Amazon Web Services (AWS) as the leading provider, followed by Microsoft Azure and Google Cloud Platform (GCP):<\/p>\n<p><a title=\"Infographic: Amazon Maintains Lead in the Cloud Market | Statista\" href=\"https:\/\/www.statista.com\/chart\/18819\/worldwide-market-share-of-leading-cloud-infrastructure-service-providers\/\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" style=\"width: 657px; height: 657px; max-width: 960px;\" src=\"https:\/\/i0.wp.com\/cdn.statcdn.com\/Infographic\/images\/normal\/18819.jpeg?resize=900%2C900&#038;ssl=1\" alt=\"Infographic: Amazon Maintains Lead in the Cloud Market | Statista\" width=\"900\" height=\"900\" \/><\/a><\/p>\n<p>Due to the innate dependence that an entity will have on its cloud service provider (<em>Cloud Service Provider<\/em> \u2013 CSP) and once you migrate your services <em>on-premises<\/em> to the cloud, it is important to consider the type of services and the responsibility that will be delegated to that provider. Likewise, if the services migrated to the cloud process, store or transmit payment card data, the scope of customer compliance may be extended to the infrastructure of the employed CSP.<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1741\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2023\/11\/cloud.png?resize=805%2C373&#038;ssl=1\" alt=\"\" width=\"805\" height=\"373\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/cloud.png?w=1302&amp;ssl=1 1302w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/cloud.png?resize=300%2C139&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/cloud.png?resize=1024%2C474&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/cloud.png?resize=768%2C356&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/cloud.png?resize=500%2C232&amp;ssl=1 500w\" sizes=\"auto, (max-width: 805px) 100vw, 805px\" \/><\/p>\n<p>In accordance with PCI DSS v4.0 requirement 12.8, an entity shall maintain a list of service providers with whom it shares card data or whose services may affect the security of managed card data. This requirement also affects cloud service providers. To support and guide entities in the process of technical, legal and compliance assessment of different cloud service providers, in April 2018 the PCI SSC published the document.<a href=\"https:\/\/docs-prv.pcisecuritystandards.org\/Guidance%20Document\/Virtualization%20and%20Cloud\/PCI_SSC_Cloud_Guidelines_v3.pdf\" target=\"_blank\" rel=\"noopener\">Information Supplement \u2013 Cloud Computing Guidelines<\/a>\u00ab, which describes the relationships between the CSP and its clients and the different considerations to be analyzed from the perspective of PCI DSS compliance, including risk analysis, due diligence (<em>due diligence<\/em>), service level agreements, continuity and disaster recovery plans, incident management and different technical safety considerations for environments <em>multi-tenancy<\/em>, hypervisor and container control, cryptography, event log management, etc.<\/p>\n<h3>Amazon Web Services (AWS) and PCI DSS<\/h3>\n<p>The relationship between AWS and PCI DSS dates back many years. AWS was one of the first CSPs to validate its own infrastructure in PCI DSS to facilitate the integration into its environment of entities affected by compliance with that standard. To this day, <a href=\"https:\/\/aws.amazon.com\/es\/compliance\/services-in-scope\/PCI\/\" target=\"_blank\" rel=\"noopener\">AWS has more than 100 services within the scope of its PCI DSS validation<\/a> and makes its compliance reports available to its customers (<em>Attestation of Compliance<\/em>) which can be unloaded in <a href=\"https:\/\/console.aws.amazon.com\/artifact\/home\" target=\"_blank\" rel=\"noopener\">AWS Artifact<\/a>.<\/p>\n<p>The fundamental element in this compliance scenario where the customer and CSP environment are involved is called <span class=\"highlight\">\u2018shared responsibility model\u2019<\/span> (<em>shared responsibility<\/em>). This model establishes the responsibility in the operation and management of both the underlying technological platform and the physical facilities and services involved in the environment. In the case of AWS, your <a href=\"https:\/\/aws.amazon.com\/es\/compliance\/shared-responsibility-model\/\" target=\"_blank\" rel=\"noopener\">shared responsibility model<\/a> states that AWS's responsibilities are limited to the security of the cloud platform (<em>responsibility for security OF the cloud<\/em>) , while the responsibility of the client entity will focus on the security of the services executed on that platform (<em>responsibility for security IN the cloud<\/em>), with a number of controls shared between the two actors. As indicated in req. 12.8.5 of PCI DSS, AWS also provides a matrix of responsibilities for each of the PCI DSS controls, which can be downloaded at <a href=\"https:\/\/console.aws.amazon.com\/artifact\/home\" target=\"_blank\" rel=\"noopener\">AWS Artifact<\/a>:<img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1744\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2023\/11\/Shared_Responsibility_Model_V2.59d1eccec334b366627e9295b304202faf7b899b.jpg?resize=694%2C380&#038;ssl=1\" alt=\"\" width=\"694\" height=\"380\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/Shared_Responsibility_Model_V2.59d1eccec334b366627e9295b304202faf7b899b.jpg?w=1212&amp;ssl=1 1212w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/Shared_Responsibility_Model_V2.59d1eccec334b366627e9295b304202faf7b899b.jpg?resize=300%2C164&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/Shared_Responsibility_Model_V2.59d1eccec334b366627e9295b304202faf7b899b.jpg?resize=1024%2C561&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/Shared_Responsibility_Model_V2.59d1eccec334b366627e9295b304202faf7b899b.jpg?resize=768%2C421&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/Shared_Responsibility_Model_V2.59d1eccec334b366627e9295b304202faf7b899b.jpg?resize=500%2C274&amp;ssl=1 500w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><\/p>\n<h3>AWS PCI DSS v4.0 Compliance Guide<\/h3>\n<p>In addition to the AWS infrastructure's PCI DSS compliance, the AWS <em>Security Assurance Services<\/em> AWS developed the document<a href=\"https:\/\/aws.amazon.com\/es\/blogs\/security\/pci-dss-v4-0-on-aws-compliance-guide-now-available\/\" target=\"_blank\" rel=\"noopener\">Payment Card Industry Data Security Standard (PCI DSS) v4.0 on AWS \u2013 Compliance Guide\u2019<\/a>, which includes a detailed description of the AWS service for environments affected by PCI DSS v4.0 compliance and different recommendations and best practices for each of the requirements groups, thus becoming an indispensable reading document for any entity that uses AWS services in its PCI DSS environment or for any QSA that has to evaluate environments deployed in this CSP.<\/p>\n<p><iframe loading=\"lazy\" src=\"http:\/\/docs.google.com\/viewer?url=https:\/\/pcihispano.com\/wp-content\/uploads\/2023\/11\/pci-dss-compliance-on-aws-v4-102023.pdf&amp;embedded=true\" width=\"800\" height=\"1200\" frameborder=\"0\"><\/iframe><\/p>\n<p>Some of the most noteworthy aspects of this guide are:<\/p>\n<ul>\n<li>Examples of flowcharts, network diagrams, and asset inventories to support PCI DSS compliance scope identification exercises.<\/li>\n<li>Integration with the tool <a href=\"https:\/\/aws.amazon.com\/es\/architecture\/well-architected\/?wa-lens-whitepapers.sort-by=item.additionalFields.sortDate&amp;wa-lens-whitepapers.sort-order=desc&amp;wa-guidance-whitepapers.sort-by=item.additionalFields.sortDate&amp;wa-guidance-whitepapers.sort-order=desc\" target=\"_blank\" rel=\"noopener\">AWS Well-Architected<\/a> to define secure, high-performance, resilient, and efficient infrastructures based on AWS best practices.<\/li>\n<li>Recommendations are provided regarding the use of the \u2018personalised approach\u2019 (<em>customized approach<\/em>) and the implementation of targeted risk analysis (<em>targeted risk analysis<\/em>).<\/li>\n<\/ul>\n<p>Among the most relevant technical recommendations are:<\/p>\n<ul>\n<li>Use of <a href=\"https:\/\/aws.amazon.com\/es\/bottlerocket\/\" target=\"_blank\" rel=\"noopener\">AWS Bottlerocket<\/a> as an operating system optimized for container execution. This operating system offers enhanced security and resource optimization in environments subject to PCI DSS compliance.<\/li>\n<li>The following are listed: <em><a href=\"https:\/\/www.pcihispano.com\/en\/analisis-de-pci-dss-v4-0-parte-ii-requerimientos-1-y-2\/\" target=\"_blank\" rel=\"noopener\">network security controls<\/a><\/em> (NSCs) affected by requirement 1 under AWS: VPCs, security groups, VPC network access control lists (network ACLs) and IAM. <span class=\"highlight\">AWS ACLs, being <em>stateless,<\/em> were not considered a valid network control in PCI DSS v3.2.1, but this has changed in PCI DSS v4.0.<\/span><\/li>\n<li>Included <a href=\"https:\/\/aws.amazon.com\/firewall-manager\/\" target=\"_blank\" rel=\"noopener\">AWS Firewall Manager<\/a> as an additional tool for configuring and managing NSC rules between accounts and applications.<\/li>\n<li>Using AWS CloudFront or Amazon API Gateway as controls to \"isolate\" card data repositories from direct access from open public networks.<\/li>\n<li>The use of <a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/WindowsGuide\/ec2config-service.html\" target=\"_blank\" rel=\"noopener\">EC2Config<\/a> for EC2 instances under Microsoft Windows to configure a local administrator password randomly and encrypted.<\/li>\n<li>The use of <a href=\"https:\/\/docs.aws.amazon.com\/systems-manager\/latest\/userguide\/session-manager.html\" target=\"_blank\" rel=\"noopener\">AWS Systems Manager Session Manager<\/a> as a \"replacement\" of traditional jump servers (<em>bastion host<\/em> o <em>jump box<\/em>).<\/li>\n<\/ul>\n<p><strong><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-1761 size-full\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2023\/11\/css-box-icon-3.png?resize=48%2C48&#038;ssl=1\" alt=\"\" width=\"48\" height=\"48\" \/>Spanish PCI Note<\/strong>: Although this guide does not explicitly mention it, you can also make use of <a href=\"https:\/\/docs.aws.amazon.com\/es_es\/cloudshell\/latest\/userguide\/welcome.html\" target=\"_blank\" rel=\"noopener\">AWS Cloud Shell<\/a> for the same purpose.<\/p>\n<ul>\n<li>As for the use of cryptography, the use of <a href=\"https:\/\/aws.amazon.com\/kms\/\" target=\"_blank\" rel=\"noopener\">AWS Key Management Service (AWS KMS)<\/a> or <a href=\"https:\/\/aws.amazon.com\/cloudhsm\/\" target=\"_blank\" rel=\"noopener\">AWS CloudHSM<\/a>, both using equipment validated in FIPS 140-2 level 3. <span class=\"highlight\">In the case where AWS KMS is used, it is important that 256-bit AES keys are used under the model<a href=\"https:\/\/docs.aws.amazon.com\/kms\/latest\/developerguide\/concepts.html#customer-cmk\" target=\"_blank\" rel=\"noopener\"> KMS Customer Managed Keys (CMKs)<\/a> in order to align with the criteria of robust cryptography (<em>strong cryptography<\/em>) as defined by the PCI SSC.<\/span><\/li>\n<\/ul>\n<p><strong><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1761 alignleft\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2023\/11\/css-box-icon-3.png?resize=48%2C48&#038;ssl=1\" alt=\"\" width=\"48\" height=\"48\" \/>Spanish PCI Note<\/strong>: Although not mentioned in this guide, AWS offers a service called <a href=\"https:\/\/aws.amazon.com\/es\/payment-cryptography\/\" target=\"_blank\" rel=\"noopener\">AWS Payment Cryptography<\/a>, which provides paid HSMs (certified in PCI HSM) that meet the controls required by PCI DSS, PCI PIN and PCI P2PE.<\/p>\n<ul>\n<li>The use of <a href=\"https:\/\/aws.amazon.com\/macie\/\" target=\"_blank\" rel=\"noopener\">Amazon Macie<\/a> for the identification, classification and protection of sensitive data stored in AWS S3.<\/li>\n<li>It is important to note that under PCI DSS v4.0, encryption of non-removable disks requires the use of an additional encryption mechanism for the protection of stored data (req. 3.5.1.2). In this case, <span class=\"highlight\">if native encryption is used for services such as AWS S3 or AWS RDS, additional encryption controls are required at the data level, using AWS KMS CMKs, for example.<\/span><\/li>\n<li>Reference is made to the <a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/field-level-encryption.html\" target=\"_blank\" rel=\"noopener\">field-level encryption<\/a> AWS CloudFront. Through this service, an additional layer of encryption can be added at the data level from its origin (in this case, the user's browser) using asymmetric cryptography to complement the channel encryption provided by TLS.<\/li>\n<\/ul>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1761 alignleft\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2023\/11\/css-box-icon-3.png?resize=48%2C48&#038;ssl=1\" alt=\"\" width=\"48\" height=\"48\" \/><strong>Spanish PCI Note<\/strong>: AWS created a spectacular manual that describes the procedure to protect card data using <em>field-level encryption<\/em>: <a href=\"https:\/\/aws.amazon.com\/es\/blogs\/security\/how-to-enhance-the-security-of-sensitive-customer-data-by-using-amazon-cloudfront-field-level-encryption\/\" target=\"_blank\" rel=\"noopener\">How to Enhance the Security of Sensitive Customer Data by Using Amazon CloudFront Field-Level Encryption<\/a>.<\/p>\n<ul>\n<li>\u00a0The use of <a href=\"https:\/\/aws.amazon.com\/certificate-manager\/\" target=\"_blank\" rel=\"noopener\">AWS Certificate Manager (ACM)<\/a> for the provisioning, management and deployment of digital certificates for TLS services. <strong><br \/>\n<\/strong><\/li>\n<li>At the malware management level, the client is responsible for the implementation of antimalware solutions in EC2 instances, containers or any service where the client operates the operating system layer. However, <span class=\"highlight\">can be made use of <a href=\"https:\/\/docs.aws.amazon.com\/guardduty\/latest\/ug\/malware-protection.html\" target=\"_blank\" rel=\"noopener\">Amazon GuardDuty Malware Protection<\/a> to scan bulk Amazon Elastic Block Store (EBS) files that are linked to an EC2 instance (AWS Fargate (EKS\/ECS) is not supported).<\/span><\/li>\n<li>For the review of potential vulnerabilities in the source code you can make use of <a href=\"https:\/\/aws.amazon.com\/codeguru\/\" target=\"_blank\" rel=\"noopener\">Amazon CodeGuru<\/a>.<\/li>\n<li>For the inspection of security vulnerabilities can be made use of <a href=\"https:\/\/aws.amazon.com\/inspector\/\" target=\"_blank\" rel=\"noopener\">Amazon Inspector<\/a> (in running instances) or <a href=\"https:\/\/docs.aws.amazon.com\/AmazonECR\/latest\/userguide\/image-scanning.html\" target=\"_blank\" rel=\"noopener\">Amazon Elastic Container Registry (ECR)<\/a> for scanning container images.<\/li>\n<li>Can be used <a href=\"https:\/\/docs.aws.amazon.com\/systems-manager\/latest\/userguide\/systems-manager-patch.html\" target=\"_blank\" rel=\"noopener\">Systems Manager Patch Manager<\/a> for the management and deployment of updates to operating systems under the responsibility of the customer.<\/li>\n<li>AWS WAF (with its <a href=\"https:\/\/aws.amazon.com\/marketplace\/solutions\/security\/waf-managed-rules\" target=\"_blank\" rel=\"noopener\">managed rules<\/a>) can be used to cover requirement 6.4 for the protection of web applications connected to public networks.<\/li>\n<li>You can make use of <a href=\"https:\/\/docs.aws.amazon.com\/IAM\/latest\/UserGuide\/what-is-access-analyzer.html\" target=\"_blank\" rel=\"noopener\">IAM Access Analyzer<\/a> to identify resource and data access issues in AWS IAM.<\/li>\n<li>By <a href=\"https:\/\/docs.aws.amazon.com\/secretsmanager\/latest\/userguide\/intro.html\" target=\"_blank\" rel=\"noopener\">AWS Secrets Manager<\/a> o <a href=\"https:\/\/docs.aws.amazon.com\/systems-manager\/latest\/userguide\/systems-manager-parameter-store.html\" target=\"_blank\" rel=\"noopener\">AWS Systems Manager Parameter Store<\/a> Clear storage of API and database connection credentials will no longer be required.<\/li>\n<li>It is the responsibility of the entity:\n<ul>\n<li>Identify and remove or disable user accounts with more than 90 days of inactivity.<\/li>\n<li>Manage session downtime.<\/li>\n<li>Blocking of accounts<\/li>\n<\/ul>\n<\/li>\n<li>MFA is available for access to management consoles, AWS CLI, and API access.<\/li>\n<\/ul>\n<p><strong><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1761 alignleft\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2023\/11\/css-box-icon-3.png?resize=48%2C48&#038;ssl=1\" alt=\"\" width=\"48\" height=\"48\" \/>Spanish PCI Note<\/strong>: From mid-2024, <a href=\"https:\/\/aws.amazon.com\/es\/blogs\/security\/security-by-design-aws-to-enhance-mfa-requirements-in-2024\/\" target=\"_blank\" rel=\"noopener\">AWS will make the use of MFA mandatory in the root account<\/a>.<\/p>\n<ul>\n<li>The entire requirement 9 (physical security) is under the responsibility of AWS<\/li>\n<li>AWS CloudTrail includes functionality for <a href=\"https:\/\/docs.aws.amazon.com\/awscloudtrail\/latest\/userguide\/cloudtrail-log-file-validation-intro.html\" target=\"_blank\" rel=\"noopener\">validate the integrity of event logs<\/a> (logs) stored on that service.<\/li>\n<li><a href=\"https:\/\/aws.amazon.com\/es\/security-hub\/\" target=\"_blank\" rel=\"noopener\">AWS Security Hub<\/a> It can be used to automate AWS security checks and centralize security alerts.<\/li>\n<li>Since 2017, AWS has been running its own redundant, satellite-connected atomic reference clock service in different regions. This service (<a href=\"https:\/\/aws.amazon.com\/es\/about-aws\/whats-new\/2017\/11\/introducing-the-amazon-time-sync-service\/\" target=\"_blank\" rel=\"noopener\">Amazon Time Sync Service<\/a>) can be used for compliance with requirement 10.6.<\/li>\n<li>As for internal vulnerability scans you can make use of Amazon Inspector.<\/li>\n<li>For network intrusion detection management (<em>Intrusion Detection System<\/em> \u2013 IDS), the traditional concept of connection at layer 2 level of the OSI model does not apply in software-defined networks (SDNs). Therefore, AWS recommends the use of <a href=\"https:\/\/aws.amazon.com\/es\/guardduty\/\" target=\"_blank\" rel=\"noopener\">AWS GuardDuty<\/a> in conjunction with information provided by other services such as AWS WAF or host-level intrusion detection (HIDS) solutions. AWS provides <a href=\"https:\/\/d1.awsstatic.com\/certifications\/foregenix_amazon_guardduty_security_review_07-2020.pdf\" target=\"_blank\" rel=\"noopener\">a guide to using and evaluating AWS GuardDuty in PCI DSS environments<\/a>.<\/li>\n<li>The entity is responsible for implementing controls to detect changes in the payment pages of its environment.<\/li>\n<li>Systems Manager, AWS Config, and Application Discovery service can be used to identify services and assets in the AWS environment.<\/li>\n<li>For security incident management, AWS developed a <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/aws-security-incident-response-guide\/welcome.html\" target=\"_blank\" rel=\"noopener\">detailed guide<\/a> for responding to security events within the AWS environment.<\/li>\n<\/ul>\n<p><strong><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1761 alignleft\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2023\/11\/css-box-icon-3.png?resize=48%2C48&#038;ssl=1\" alt=\"\" width=\"48\" height=\"48\" \/>Spanish PCI Note<\/strong>: AWS has created a series of free incident response-oriented technical courses on its cloud platform (<em>Security Incident Response Series<\/em> \u2013 CRS)<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><a href=\"https:\/\/explore.skillbuilder.aws\/learn\/course\/external\/view\/elearning\/17875\/aws-security-incident-response-overview\" target=\"_blank\" rel=\"noopener\">AWS Security Incident Response (SIR) Overview<\/a>: Description of investigative flows in common security incidents.<\/li>\n<li><a href=\"https:\/\/explore.skillbuilder.aws\/learn\/course\/external\/view\/elearning\/17796\/aws-security-incident-response-compromised-iam-credentials-use-case\" target=\"_blank\" rel=\"noopener\">AWS SIR \u2013 IAM<\/a>: Analysis of incidents involving compromised IAM credentials.<\/li>\n<li><a href=\"https:\/\/explore.skillbuilder.aws\/learn\/course\/external\/view\/elearning\/17797\/aws-security-incident-response-ransomware-use-case\" target=\"_blank\" rel=\"noopener\">AWS SIR \u2013 Ransomware<\/a>: Management of ransomware-related security incidents.<\/li>\n<li><a href=\"https:\/\/explore.skillbuilder.aws\/learn\/course\/external\/view\/elearning\/17798\/aws-security-incident-response-cryptomining-use-case\" target=\"_blank\" rel=\"noopener\">AWS SIR \u2013 Cryptomining<\/a>: Management of security incidents related to cryptocurrency mining.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Finally, this document includes an annex where the different AWS services are related to the PCI DSS controls that can be covered.<\/p>\n<p>Do you have any comments or doubts regarding this guide? Leave us your comments and subscribe to our <a href=\"https:\/\/www.pcihispano.com\/en\/suscribirse-al-portal\/\" target=\"_blank\" rel=\"noopener\">mailing list<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>As part of its efforts to facilitate the implementation of controls of different security standards in its customers' environments, Amazon Web Services (AWS), as a cloud service provider (CSP), published [\u2026]<\/p>","protected":false},"author":2,"featured_media":1733,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[54,354],"tags":[163,156,155,162,158,157,160,165,161,128,67,166,159,57,152,164,141],"class_list":["post-1732","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-noticias","category-pcidss","tag-api","tag-artifact","tag-aws","tag-cli","tag-cloud","tag-csp","tag-cumplimiento","tag-ec2","tag-guardduty","tag-hsm","tag-ids","tag-kms","tag-nube","tag-pci-dss","tag-responsabilidad","tag-vpc","tag-waf"],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/11\/aws_pcidss.png?fit=1906%2C1074&ssl=1","jetpack-related-posts":[{"id":4508,"url":"https:\/\/www.pcihispano.com\/en\/cinco-puntos-clave-del-nuevo-documento-para-la-definicion-de-alcance-y-segmentacion-en-arquitecturas-de-red-modernas\/","url_meta":{"origin":1732,"position":0},"title":"5 puntos clave del documento para la definici\u00f3n de alcance y segmentaci\u00f3n en arquitecturas de red modernas","author":"David Acosta","date":"septiembre 19, 2024","format":false,"excerpt":"En septiembre de 2025 el PCI SSC public\u00f3 un nuevo suplemento informativo para la definici\u00f3n del alcance y segmentaci\u00f3n en arquitecturas de red modernas (Information Supplement - PCI DSS Scoping and Segmentation Guidance for Modern Network Architectures). En este art\u00edculo analizamos los cinco puntos clave de ese nuevo documento y\u2026","rel":"","context":"In &quot;Contenido general&quot;","block_context":{"text":"Contenido general","link":"https:\/\/www.pcihispano.com\/en\/category\/contenido\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/09\/cloud2.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/09\/cloud2.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/09\/cloud2.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/09\/cloud2.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/09\/cloud2.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":243,"url":"https:\/\/www.pcihispano.com\/en\/que-es-pci-dss\/","url_meta":{"origin":1732,"position":1},"title":"\u00bfQu\u00e9 es PCI DSS?","author":"David Acosta","date":"agosto 18, 2024","format":false,"excerpt":"En esta nueva serie de art\u00edculos de PCI Hispano se presentar\u00e1 una descripci\u00f3n general de cada uno de los est\u00e1ndares publicados actualmente por el Consejo de Est\u00e1ndares de Seguridad de la Industria de Tarjetas de Pago (Payment Card Industry Security Standards Council \u2013 PCI SSC) para la protecci\u00f3n de los\u2026","rel":"","context":"In &quot;Destacado&quot;","block_context":{"text":"Destacado","link":"https:\/\/www.pcihispano.com\/en\/category\/destacado\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/PCIDSS.png?fit=1200%2C674&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/PCIDSS.png?fit=1200%2C674&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/PCIDSS.png?fit=1200%2C674&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/PCIDSS.png?fit=1200%2C674&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/PCIDSS.png?fit=1200%2C674&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":6491,"url":"https:\/\/www.pcihispano.com\/en\/se-pueden-usar-los-certificados-de-cumplimiento-para-demostrar-el-cumplimiento-con-pci-dss\/","url_meta":{"origin":1732,"position":2},"title":"\u00bfSe pueden usar certificados o diplomas para demostrar el cumplimiento con PCI DSS?","author":"David Acosta","date":"abril 29, 2025","format":false,"excerpt":"Continuando con nuestra campa\u00f1a en pro del buen uso de los t\u00e9rminos en el \u00e1mbito de PCI, esta vez analizamos el uso del concepto de \"certificaci\u00f3n\" y la emisi\u00f3n de certificados o diplomas posterior a la evaluaci\u00f3n formal, con el fin de evitar errores conceptuales que puedan llevar a malinterpretar\u2026","rel":"","context":"In &quot;Contenido general&quot;","block_context":{"text":"Contenido general","link":"https:\/\/www.pcihispano.com\/en\/category\/contenido\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/certificado_PCIDSS.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/certificado_PCIDSS.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/certificado_PCIDSS.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/certificado_PCIDSS.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/certificado_PCIDSS.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":11319,"url":"https:\/\/www.pcihispano.com\/en\/transparent-data-encryption-tde-cumplimiento-vs-seguridad\/","url_meta":{"origin":1732,"position":3},"title":"Transparent Data Encryption (TDE): \u00abcumplimiento\u00bb vs. \u00abseguridad\u00bb","author":"David Acosta","date":"febrero 19, 2026","format":false,"excerpt":"Transparent Data Encryption (TDE) es una tecnolog\u00eda que protege los datos sensibles en bases de datos durante su almacenamiento (data-at-rest). Sin embargo, su uso debe estar restringido a escenarios muy espec\u00edficos, fuera de los cuales el nivel de protecci\u00f3n que ofrece se reduce y puede dar lugar a una falsa\u2026","rel":"","context":"In &quot;Contenido general&quot;","block_context":{"text":"Contenido general","link":"https:\/\/www.pcihispano.com\/en\/category\/contenido\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2026\/02\/SQL.png?fit=1200%2C674&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2026\/02\/SQL.png?fit=1200%2C674&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2026\/02\/SQL.png?fit=1200%2C674&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2026\/02\/SQL.png?fit=1200%2C674&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2026\/02\/SQL.png?fit=1200%2C674&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":477,"url":"https:\/\/www.pcihispano.com\/en\/analisis-de-pci-dss-v4-0-parte-vii-requerimiento-12\/","url_meta":{"origin":1732,"position":4},"title":"An\u00e1lisis de PCI DSS v4.0 \u2013 Parte VII: Requerimiento 12","author":"David Acosta","date":"noviembre 17, 2022","format":false,"excerpt":"En este pen\u00faltimo art\u00edculo de la serie \u201cAn\u00e1lisis de PCI DSS v4.0\u201d se presenta un an\u00e1lisis a los cambios del requerimiento 12 - parte del grupo 6 \u201cMaintain an Information Security Policy\u201d- en la versi\u00f3n 4.0 del est\u00e1ndar PCI DSS. Requerimiento 12: Support Information Security with Organizational Policies and Programs\u2026","rel":"","context":"In &quot;An\u00e1lisis de PCI DSS v4.0&quot;","block_context":{"text":"An\u00e1lisis de PCI DSS v4.0","link":"https:\/\/www.pcihispano.com\/en\/category\/pci-dss-4-0\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/11\/PCIDSS_PartVII.png?fit=1200%2C671&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/11\/PCIDSS_PartVII.png?fit=1200%2C671&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/11\/PCIDSS_PartVII.png?fit=1200%2C671&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/11\/PCIDSS_PartVII.png?fit=1200%2C671&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/11\/PCIDSS_PartVII.png?fit=1200%2C671&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":6258,"url":"https:\/\/www.pcihispano.com\/en\/que-sigue-despues-de-la-entrada-en-vigor-de-los-controles-futuros-de-pci-dss-v4\/","url_meta":{"origin":1732,"position":5},"title":"\u00bfQu\u00e9 sigue despu\u00e9s de la entrada en vigor de los controles futuros de PCI DSS v4?","author":"David Acosta","date":"abril 1, 2025","format":false,"excerpt":"Debido a la complejidad en su implementaci\u00f3n, el est\u00e1ndar PCI DSS v4 estableci\u00f3 un periodo de gracia para la implementaci\u00f3n de ciertos controles de seguridad. Ese periodo expir\u00f3 el 31 de marzo de 2025. \u00bfQu\u00e9 sigue despu\u00e9s de esta fecha? El 31 de marzo de 2025 fue la fecha establecida\u2026","rel":"","context":"In &quot;Contenido general&quot;","block_context":{"text":"Contenido general","link":"https:\/\/www.pcihispano.com\/en\/category\/contenido\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/clock-scaled.jpg?fit=1200%2C800&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/clock-scaled.jpg?fit=1200%2C800&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/clock-scaled.jpg?fit=1200%2C800&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/clock-scaled.jpg?fit=1200%2C800&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/clock-scaled.jpg?fit=1200%2C800&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/1732","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/comments?post=1732"}],"version-history":[{"count":1,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/1732\/revisions"}],"predecessor-version":[{"id":11736,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/1732\/revisions\/11736"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/media\/1733"}],"wp:attachment":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/media?parent=1732"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/categories?post=1732"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/tags?post=1732"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}