PCI-DSS
The Payment Card Industry Data Security Standard: a set of security requirements for any organisation that stores, processes, or transmits cardholder data.
Definition
PCI-DSS (Payment Card Industry Data Security Standard) sets out technical and operational requirements for protecting cardholder data, covering network security, access control, encryption, monitoring, and regular testing. AWS infrastructure can be configured to meet PCI-DSS requirements, but compliance is a shared responsibility: AWS provides a compliant platform, while the customer is still responsible for configuring it, and for how applications built on top of it handle cardholder data.
In Practice
A retail client processing card payments through an AWS-hosted checkout flow needs network segmentation, encryption in transit and at rest, and audit logging configured correctly; PCI-DSS compliance is not something the underlying AWS services provide automatically.