Skip to contentSkip to content
Regularly Monitor and Test Networks
10

Log and Monitor All Access to System Components and Cardholder Data

Logging mechanisms and the ability to track user activities are critical for detecting, preventing, and responding to security incidents. PCI DSS 4.0.1 now requires automated log review mechanisms and broader scope of logging to include all system components, not just those in the CDE.

Control Intent

Enable detection, investigation, and response to security events by implementing comprehensive logging across all CDE system components and establishing mechanisms to review logs for anomalies and suspicious activity.

Common Failures

  • Automated log review mechanisms not implemented, relying solely on manual review that cannot keep pace with volume
  • Incomplete logging — not all events specified by PCI DSS are captured in audit trails
  • Clock synchronisation not configured, making event correlation across systems impossible
  • Audit logs not retained for the full 12-month period, with only recent logs available
  • Audit logs accessible to non-authorised personnel or modifiable by system administrators