10.4 Audit logs are reviewed to identify anomalies
How to meet it
Review logs (ideally with automation/SIEM) and act on findings.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 10.4, in plain English.
10.4.1Security event logs and logs of critical and CHD systems are reviewed at least once a day.
10.4.1.1Automated mechanisms are used to perform the log reviews.
10.4.2Logs of all other system components are reviewed periodically.
10.4.2.1The periodic review frequency is set in the targeted risk analysis.
10.4.3Exceptions and anomalies found during review are addressed.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.Logging and monitoring policyUse for ISO 27001 A.8.15, A.8.16, A.8.17, SOC 2 Security, and PCI DSS requirements 10 and 11.Information risk management procedureThe clause 6.1.2/6.1.3 and 8.2/8.3 engine: risk identification, analysis scales, evaluation, treatment, acceptance and review.ISMS internal audit procedureHow to plan and run internal ISMS audits under ISO 27001 clause 9.2, from programme to follow-up.
Open the control-to-policy map← 10.3 Audit logs are protected from destruction and modification10.5 Audit log history is retained →
Back to Requirement 10, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.