TL;DR

['AWS updates its PCI DSS compliance package by including additional services and a new region. This update helps customers meet stringent security standards globally.']

What happened

['Amazon Web Services (AWS) expanded its Payment Card Industry Data Security Standard (PCI DSS) certification to cover two new AWS services: AWS Security Incident Response and AWS Transform.', 'The PCI DSS scope also includes a new AWS Region - Asia Pacific (Taipei).']

Why it matters for ops

['This expansion helps customers achieve compliance with PCI DSS standards, ensuring secure processing and storage of cardholder data across more regions and services.', 'It provides enhanced capabilities for incident response and data transformation in the financial sector.']

Mitigation

  • Review updated PCI DSS certification details for new services and regions.
  • Ensure your environment aligns with the expanded standards to avoid compliance issues.

Action items

  • Update configurations and compliance checks to include newly certified AWS services and region
  • Consult AWS documentation for the latest guidance on PCI DSS requirements

Detection IOCs

  • New AWS services and region added to PCI DSS compliance documentation
  • Changes in service offerings related to security and compliance

Source link

https://aws.amazon.com/blogs/security/fall-2025-pci-dss-compliance-package-available-now/