10.5 Audit log history is retained
How to meet it
Retain at least 12 months, with the most recent 3 readily available.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 10.5, in plain English.
10.5.1Audit log history is retained at least 12 months, with the most recent three months immediately available.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Logging and monitoring policyUse for ISO 27001 A.8.15, A.8.16, A.8.17, SOC 2 Security, and PCI DSS requirements 10 and 11.AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Human resources security policyUse for ISO 27001 A.6.1 to A.6.6, A.6.8, SOC 2 Security, and personnel security controls.Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.
Open the control-to-policy map← 10.4 Audit logs are reviewed to identify anomalies10.6 Time-synchronisation mechanisms are in place →
Back to Requirement 10, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.