Requirement 10: Log and monitor all access to system components and cardholder data
Logging and monitoring let you detect, alert on, and investigate suspicious activity.
Sub-requirements
Processes and mechanisms are defined and understood
2 defined requirementsDocument logging and monitoring policy.
View defined requirements →Audit logs are implemented to support anomaly detection
9 defined requirementsLog access, admin actions, and key events with enough detail to investigate.
View defined requirements →Audit logs are protected from destruction and modification
4 defined requirementsRestrict and protect logs; forward to a central, tamper-resistant store.
View defined requirements →Audit logs are reviewed to identify anomalies
5 defined requirementsReview logs (ideally with automation/SIEM) and act on findings.
View defined requirements →Audit log history is retained
1 defined requirementRetain at least 12 months, with the most recent 3 readily available.
View defined requirements →Time-synchronisation mechanisms are in place
3 defined requirementsSync clocks to an authoritative source so logs correlate.
View defined requirements →Failures of critical security controls are detected and responded to
3 defined requirementsAlert on and promptly respond to failures of security controls.
View defined requirements →Tips
- ›Centralise logs in a SIEM, manual review rarely scales or convinces an assessor.
- ›Set alerting on the failures named in 10.7 (firewalls, anti-malware, logging itself).
Evidence to keep
- ✓Logging policy
- ✓SIEM configuration and retention settings
- ✓Sample alert/review records
Example
All components ship logs to a SIEM with 13-month retention, NTP keeps clocks aligned, and alerts fire on control failures and suspicious access.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.