Using AWS EC2 makes me PCI DSS Compliant

230 Views Asked by At

If I'm using AWS EC2 server so that AWS will give me certificate for PCI DSS Compliant. I'm a bit confuse regarding this please help me out.. Thanks

1

There are 1 best solutions below

2
SmartCoder On

AWS is a PCI-compliant Level 1 Service Provider. Thus, companies can use AWS, but in the context of a shared responsibility model. This means that AWS customers share the responsibility for PCI compliance. Since AWS is a PCI-compliant service provider, organizations using AWS do not need to assess AWS infrastructure. An assessor can validate the compliance of the AWS infrastructure simply by reviewing AWS’s Attestation of Compliance (AOC) and Responsibility Matrix documents.

https://www.threatstack.com/blog/what-is-aws-pci-compliance

Hence, for AWS compliance, you have to provide an auditor PCI compliance reports available in AWS artifacts.

But, remember that compliance is shared responsibility. So, you have to ensure that applications that you are running on EC2 are also PCI compliant