Audit Log Management and Daily Review
What this control requires
Implement audit logging for all CDE system components. Logs must capture: user access, administrative actions, access to logs, invalid access attempts, authentication mechanism changes, and system events. Review logs daily. Retain 12 months (3 months immediately available). Protect log integrity with FIM.
Other PCI DSS controls
PCI_DSS-CTRL-001 - Daily safeguarding reconciliationPCI_DSS-CTRL-002 - Critical ICT incident reportingPCI_DSS-CTRL-003 - GDPR breach notification workflowPCI_DSS-CTRL-004 - AML suspicious transaction monitoringPCI_DSS-CTRL-005 - Quarterly PCI vulnerability assessmentPCI_DSS-CTRL-006 - Outsourcing provider oversightPCI_DSS-CTRL-007 - DORA Register of Information maintenancePCI_DSS-CTRL-008 - CTIF suspicious activity escalationPCI_DSS-CTRL-009 - NIS2 cyber resilience testingPCI_DSS-CTRL-010 - Instant payment availability monitoringPCI-AUTH-001 - Implement Strong Access Control for Cardholder DataPCI-ENCRYPT-001 - Protect Stored Cardholder Data with Strong Cryptography