CC6.6 Protect Against Threats From Outside Sources
Policy Control – System Access Policy is in place
Policy Control – IDS Policy is in place
Policy Control – Data Integrity Policy is in place
Inherited Control – Amazon Web Services (AWS) has established information security framework and policies which have integrated the ISO 27001 certifiable framework based on ISO 27002 controls, American Institute of Certified Public Accountants (AICPA) Trust Services Principles, and PCI DSS v3.1. AWS Third Party requirements are reviewed by independent external.
Technical Control – EBS volumes are encrypted
Technical Control – RDS instances are not publicly accessible
Technical Control – Security Groups does not open SSH, FTP, SMTP ports to public
Technical Control – Security Groups does not DB ports to the public