CyberTRIZPEDIA

Audit Log Management and Daily Review

Control
PCI-R10-001
Regulation
PCI DSS
Category
technical
Priority
critical
Frequency
daily
Type
technical

What this control requires

Implement audit logging for all CDE system components. Logs must capture: user access, administrative actions, access to logs, invalid access attempts, authentication mechanism changes, and system events. Review logs daily. Retain 12 months (3 months immediately available). Protect log integrity with FIM.

Other PCI DSS controls