Regularly monitor and test networks

Requirement 10: Log and monitor all access to system components and cardholder data

Logging and monitoring let you detect, alert on, and investigate suspicious activity.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILPCI Req 10 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Sub-requirements

Tips

  • Centralise logs in a SIEM, manual review rarely scales or convinces an assessor.
  • Set alerting on the failures named in 10.7 (firewalls, anti-malware, logging itself).

Evidence to keep

  • Logging policy
  • SIEM configuration and retention settings
  • Sample alert/review records

Example

All components ship logs to a SIEM with 13-month retention, NTP keeps clocks aligned, and alerts fire on control failures and suspicious access.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map