Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 9136787
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 17, 20262026-06-17T08:59:56+00:00 2026-06-17T08:59:56+00:00

Is using VPC required for PCI on a platform level ? Or can PCI

  • 0

Is using VPC required for PCI on a platform level? Or can PCI be achieved by security groups alone?

I’m only asking this because I’ve gotten mixed responses from Amazon on this question, the sales reps state VPC is required to be PCI compliant, however several engineers have asserted VPC isn’t required and standard security groups is enough.

I broke down some of the PCI-DSS requirements and I hope we can hash this out as a community.

Questionable Things:

1.3.5 Do not allow unauthorized outbound traffic from the cardholder data environment to the Internet. – I should be able to do this at the software level, since standard security groups don’t allow for it.

Things that should be fine:

1.1.3 Requirements for a firewall at each Internet connection and between any demilitarized zone (DMZ) and the internal network zone. – Both allow for this.

1.2 Build firewall and router configurations that restrict connections between untrusted networks and any system components in the cardholder data environment. – I can easily create a security group for application servers and databases, then only allow applications to access the database group.

1.3 Prohibit direct public access between the Internet and any system component in the cardholder data environment. – I can disallow all public access with security groups.

1.3.1 Implement a DMZ to limit inbound traffic to only system components that provide authorized publicly accessible services, protocols, and ports. – I’ll utilize a loadbalancer for this task.

1.3.2 Limit inbound Internet traffic to IP addresses within the DMZ. – The loadbalancer will be the only publicly accessible server.

1.3.6 Implement stateful inspection, also known as dynamic packet filtering. (That is, only ―established‖ connections are allowed into the network.) – Standard security groups perform stateful inspection.

Based on that list, I don’t think here is anything stopping me from achieving PCI compliance with security groups alone. Please let me know if you agree/disagree.

**Also, i’m not storing any PANs, It’s a clean pass through.

I appreciate the feedback.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-17T08:59:57+00:00Added an answer on June 17, 2026 at 8:59 am

    1.3.5 Do not allow unauthorized outbound traffic from the cardholder data environment to the Internet. – I should be able to do this at the software level, since standard security groups don’t allow for it.

    Filtering egress traffic is only possible using VPC security groups. You do not want to rely upon your application to do this; it must be done at the network level (what happens when an attacker comprises your app or simply installs another app to steal your data?). Using VPC, you can also use network ACLs to implement a multilayered approach to filter egress traffic there as well–“security in-depth is security done right.”

    Really, this criterion alone is enough for a VPC to be the obvious choice. Why the reluctance? VPC doesn’t cost anything more, greatly increases security, and offers some additional functionality not found with EC2 (Elastic Network Interfaces, multiple IPs per instance, IPSec VPN, etc).

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

using this http://bl.ocks.org/950642 we can see how to add images to nodes, the question
Using range() in Underscore I can make something like this: _.range(10); >> [0, 1,
Using CI for the first time and i'm smashing my head with this seemingly
Using Location.getBearing(); I seem to get randomly changing bearings. Aka, I can turn the
Using RestKit 0.10.1, I have objects served similar to this json format: {objects: [
Using System.Diagnostics.EventLog .NET type one can programmatically create logs into the Event Viewer application.
Using PL/SQL, how can I remove sentences, except the first occurrence of a sentence
Using PostgreSQL 8.4 and with a table such as this: create table log (
Using knockoutjs mapping plugin is it possible to only make the child elements observables?
This is my first try with VPC. I just changed my template to use

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.