Requirement 10: Log and Monitor All Access to System Components and Cardholder Data
Logging mechanisms and the ability to track user activities are critical in preventing, detecting, or minimizing the impact of a data compromise.
Logging and log monitoring are critical tools in maintaining the security of sensitive systems. Audit trails must be maintained for all critical system components of the CDE, including workstations, servers, firewalls, routers, switches, wireless access points, etc. All access to cardholder data, access to audit logs, administrative actions, successful login attempts, and failed login attempts must be logged. Each log must include the user name, type of event, date and time, success or failure indication, IP address of the user, and the impacted system(s).
Logs should be centrally backed up and protected against unauthorized access and tampering. File-integrity monitoring should be configured on log records to detect and alert administrators of any unauthorized changes (new additions should not trigger an alert).
Review logs of all in-scope CDE systems daily, per the log-review scope defined in Requirement 10.4.1; other system components may be reviewed periodically based on a targeted risk analysis (Requirement 10.4.2.1). Since March 31, 2025, an automated log-review mechanism (similar to Splunk or LogRhythm) is required to perform this daily review (Requirement 10.4.1.1). Audit logs must be maintained for at least one year (with three months immediately available for analysis.)
Time synchronization (Windows Time and/or NTP) is a critical part of maintaining accurate logs. All systems should synchronize time with select internal timeserver(s). Only the designated internal timeserver(s) should synchronize with reputable external time source(s).
Requirement 10.7.2 requires that a process is implemented for the timely detection, alerting, and response to failures of critical security control systems, including firewalls, IDS/IPS, file-integrity monitoring, anti-malware, physical and logical access controls, audit logging mechanisms, and automated security-testing tools. Since March 31, 2025, this requirement applies to all entities, not just service providers.
Go on to Requirement 11 - Regular Security Testing.
Go back to Requirement 9 - Physical Access Restrictions.