The PCI DSS compliance package checks your cloud resources against PCI DSS v4.0 data protection baselines to help you meet payment card industry security requirements.
Background
PCI DSS (Payment Card Industry Data Security Standard) is a global standard that provides technical and operational baselines for protecting cardholder data.
This compliance package is based on the data protection baselines of PCI DSS v4.0 and provides recommended compliance checks for cloud resource management.
The full standard is available on the PCI Security Standards website.
Scenarios
Use this package if you operate in the finance industry, handle sensitive payment card data, or have high data security requirements.
Default rules
Compliance package templates provide a general framework for specific scenarios. A compliant resource adheres to the rule's description, but this does not guarantee full compliance with specific regulations or industry standards.
|
Rule name |
Rule description |
|
A resource is compliant if log collection is enabled for all domain names protected by WAF 2.0. |
|
|
A resource is compliant if the flow log feature is enabled for the VPC. |
|
|
Domain names bound to API groups in API Gateway are protected by WAF |
A resource is compliant if a custom domain name is bound to an API group in API Gateway and is protected by WAF. |
|
Specified protection modules are enabled for domain names protected by WAF |
A resource is compliant if the specified protection modules are enabled for a domain name protected by WAF. |
|
A resource is compliant if an inbound rule set to Allow does not have both the port range set to -1/-1 and the source set to 0.0.0.0/0. A resource is also compliant if a rule with a higher priority denies access. This rule does not apply to security groups used by Alibaba Cloud services or virtual server providers. |
|
|
High-risk ports for a specified protocol are not exposed to all CIDR blocks in security groups |
A resource is compliant if the port range of a specified protocol does not contain specified high-risk ports when the inbound CIDR block of a security group is 0.0.0.0/0. If the inbound CIDR block is not 0.0.0.0/0, the resource is compliant even if the port range contains the specified high-risk ports. A resource is also compliant if a rule with a higher priority denies access to a detected high-risk port. This rule does not apply to security groups used by Alibaba Cloud services or virtual server providers. |
|
Inbound rules for non-whitelisted ports in security groups are valid |
A resource is compliant if no inbound rule allows access from the 0.0.0.0/0 source for any port except for the specified whitelisted ports. This rule does not apply to security groups used by Alibaba Cloud services or virtual server providers. |
|
A resource is compliant if an authorization policy is configured for a public OSS bucket and the policy does not grant read or write permissions to anonymous accounts. This rule does not apply to OSS buckets with private access control lists (ACLs). |
|
|
A resource is compliant if no public IPv4 address or Elastic IP Address is directly associated with the ECS instance. |
|
|
An RDS instance is non-compliant if it allows public access and its IP address whitelist is set to 0.0.0.0/0. |
|
|
A PolarDB instance is non-compliant if it allows public access and its IP address whitelist is set to 0.0.0.0/0. |
|
|
A resource is compliant if all assets are protected by Cloud Firewall. This rule applies only to users of paid editions of Cloud Firewall. If you have not activated Cloud Firewall or if you use the free edition, your resources are compliant by default. |
|
|
Security protection is enabled for running ECS instances in Security Center |
Security Center provides security protection for your hosts after you install the Security Center agent. A resource is compliant if the Security Center agent is installed. This rule does not apply to instances that are not in the running state. |
|
A resource is compliant if you use Security Center Enterprise Edition or a later edition. |
|
|
A resource is compliant if no vulnerabilities of the specified type and risk level need to be fixed for the ECS instance in Security Center. This rule does not apply to instances that are not in the running state. |
|
|
A resource is compliant if SQL Audit is enabled for the RDS instance. |
|
|
A resource is compliant if a trail is enabled in ActionTrail to record all events in all regions. For a member account in a resource directory, the account is compliant if the administrator creates a trail that applies to all member accounts. |
|
|
The retention period of SQL audit logs for RDS instances meets requirements |
A resource is compliant if SQL Audit is enabled for an ApsaraDB RDS for MySQL instance and the log retention period is greater than or equal to the specified value. The default value is 180 days. |
|
The retention period of automatic snapshots for ECS instances meets requirements |
A resource is compliant if the snapshot retention period specified in the automatic snapshot policy for an ECS instance is longer than the specified number of days. The default value is 7 days. |
|
The level-1 backup retention period for PolarDB clusters meets requirements |
A resource is compliant if the level-1 backup retention period of a PolarDB cluster is greater than or equal to the specified number of days. The default value is 7 days. |
|
A resource is compliant if transparent data encryption (TDE) is enabled for the PolarDB cluster. |
|
|
Automatic rotation is enabled for credentials in Key Management Service |
A resource is compliant if automatic rotation is enabled for credentials in Key Management Service (KMS). |
|
Automatic rotation is enabled for customer master keys in Key Management Service |
A resource is compliant if automatic rotation is enabled for customer master keys (CMKs) in KMS. |
|
A resource is compliant if deletion protection is enabled for KMS customer master keys. |
|
|
A resource is compliant if the OSS bucket is encrypted using a custom KMS key. |
|
|
A resource is compliant if TDE is enabled for the RDS instance using a custom key. |
|
|
A resource is compliant if TDE is enabled for the Redis instance using a custom key. |
|
|
A resource is compliant if HTTPS is enabled for the accelerated domain name. |
|
|
A resource is compliant if APIs in API Gateway that are publicly accessible are configured to use HTTPS. This rule does not apply to APIs that can be invoked only over the private network. |
|
|
A resource is compliant if the Elasticsearch instance uses the HTTPS protocol. |
|
|
Secure access is configured in the authorization policies of OSS buckets |
A resource is compliant if the authorization policy of an OSS bucket specifies that read and write operations must use HTTPS or that access over HTTP is denied. This rule does not apply to OSS buckets with empty authorization policies. |
|
HTTPS listeners of SLB instances use the specified security policy suite |
A resource is compliant if all HTTPS listeners of an SLB instance use the specified version of the security policy suite. This rule does not apply to SLB instances without HTTPS listeners. |
|
Function Compute functions are bound to custom domain names and a specific TLS version is enabled |
A resource is compliant if a Function Compute function is bound to a custom domain name and the specified TLS version is enabled. |
|
The Security Center agent is installed on all ECS instances under the account |
A resource is compliant if the Security Center agent is installed on all ECS instances under the account. |
|
Vulnerability scanning of a specified risk level is configured in Security Center |
A resource is compliant if vulnerability scanning for a specified risk level is configured in Security Center. |
|
Notification methods are configured for notification items in Security Center |
A resource is compliant if notification methods are configured for all notification items in Security Center. |
|
A reasonable maintenance window is configured for RDS instances |
A resource is compliant if the maintenance window of an RDS instance is within one of the time ranges specified by the parameter. Your business may be affected if the maintenance window overlaps with business peak hours. |
|
A reasonable maintenance window is configured for PolarDB clusters |
A resource is compliant if the maintenance window of a PolarDB cluster is within one of the time ranges specified by the parameter. Your business may be affected if the maintenance window overlaps with business peak hours. |
|
RAM users and their user groups are not attached with access policies that meet specified conditions |
A resource is compliant if a RAM user is not attached with an access policy that meets the parameter conditions. This includes policies inherited from user groups. The default parameter value specifies administrative permissions. A resource is non-compliant if a RAM user has administrative permissions. |
|
A resource is compliant if no RAM user, RAM user group, or RAM role has super administrator permissions where Resource is * and Action is *. |
|
|
AccessKey pairs of RAM users are rotated within a specified period |
A resource is compliant if the AccessKey pair of a RAM user was created within the specified number of days from the check date. The default value is 90 days. |
|
All RAM users are assigned to RAM user groups and considered compliant. |
|
|
Access modes for RAM users are separated for human and programmatic access |
A resource is compliant if a RAM user does not have both console access and API access enabled. |
|
A resource is compliant if no AccessKey pair in any state exists for the Alibaba Cloud account. |
|
|
A resource is compliant if single sign-on (SSO) is enabled for the RAM user. |
|
|
A resource is compliant if the number of days since the last use of a RAM user's AccessKey pair is less than the value specified by the parameter. The default value is 90 days. |
|
|
A resource is compliant if a RAM user has logged on in the last 90 days. If the last logon time is empty, the update time is checked instead. The resource is compliant if the update occurred within the last 90 days. This rule does not apply to users without console access. |
|
|
A resource is compliant if a RAM access policy is attached to at least one RAM user group, RAM role, or RAM user. |
|
|
A RAM user group is considered compliant if it contains at least one RAM user. |
|
|
A resource is compliant if all settings in the password policy for RAM users meet the specified parameter values. |
|
|
A resource is compliant if multi-factor authentication (MFA) is enabled for the Alibaba Cloud account. |
|
|
A resource is compliant if MFA is enabled for RAM users who have console access. |
|
|
A resource is compliant if no leaked AccessKey pair information is detected by Security Center. |
|
|
A resource is compliant if SQL Audit is enabled for the PolarDB cluster. |
|
|
If log backup is not enabled, you cannot restore data if binary logs are lost. A resource is compliant if log backup is enabled for the RDS instance. |
|
|
A resource is compliant if a backup plan is created for the NAS file system. |
|
|
The log backup retention period for PolarDB clusters meets requirements |
A resource is compliant if the log backup retention period of a PolarDB cluster is greater than or equal to the specified number of days. The default value is 30 days. A resource is non-compliant if log backup is disabled or the retention period is less than the specified number of days. |
|
If zone-redundant storage (ZRS) is not enabled, OSS cannot provide consistent service when a data center becomes unavailable, which affects data restoration. A resource is compliant if ZRS is enabled for the OSS bucket. |
|
|
Data encryption is configured for Logstores in Simple Log Service |
A resource is compliant if data encryption is configured for the Logstore in Simple Log Service. |
|
A resource is compliant if server-side encryption with fully managed OSS keys is enabled for the OSS bucket. |
|
|
A resource is compliant if the event log for historical events is enabled for the RDS instance. |
|
|
The default time zone parameter for PolarDB clusters is not set to System |
A resource is compliant if the |
|
You can standardize the OS versions within your enterprise and require all hosts in the production environment to use the same OS version. You must also promptly upgrade operating systems that are no longer officially maintained to prevent security vulnerabilities. A resource is compliant if the English name of the operating system used by an ECS instance is on the specified whitelist or not on the specified blacklist. |
|
|
The CloudMonitor agent is installed on running ECS instances |
A resource is compliant if the CloudMonitor agent is installed and running on an ECS instance. This rule does not apply to instances that are not in the running state. |
|
CloudMonitor alert rules are configured for specified Alibaba Cloud services |
A resource is compliant if at least one alert rule is configured in CloudMonitor for an Alibaba Cloud service in the specified namespace. |
|
A resource is compliant if encryption is enabled for the ECS data disk. |
|
|
A resource is compliant if disk encryption is enabled for the RDS instance. |