CyberTRIZPEDIA

Implement Audit Log Management for CDE

Control
PCI-LOG-001
Regulation
PCI DSS
Category
operational
Priority
high
Frequency
annually
Type
operational

What this control requires

Implement audit logging for all CDE system components capturing: all individual user access, all actions taken by root/administrator, all access to audit logs, all failed authentication attempts, all changes to authentication mechanisms, and all application and system alerts. Retain audit logs for minimum 12 months with 3 months immediately available. Review logs daily.

Other PCI DSS controls