We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

PCI DSS v4.0.1 · Requirement 10 of 12

Requirement 10: Log and Monitor All Access to System Components and Cardholder Data

Requirement 10 decides whether a breach is a bad week or an existential event. v4’s change with operational bite: daily log review must use automated mechanisms — a human eyeballing syslog no longer scales or complies.

Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series

The controls that decide your assessment

10.2.1.x
The events that must be logged

Individual user access to cardholder data, all admin actions, access to audit logs, invalid attempts, authentication changes, log initialisation/stops, and creation/deletion of system objects.

10.3.1–10.3.4
Logs protected

Audit logs readable only by need, protected from modification, backed up promptly to a central/secured location, with integrity monitoring on log files.

10.4.1 + 10.4.1.1
Daily review — automated

Security events, CDE component logs and critical-system logs reviewed daily using automated mechanisms (fully effective 31 March 2025); other logs periodically per TRA.

10.5.1
Twelve-month retention

Audit log history retained at least 12 months, with the most recent three months immediately available for analysis.

10.6.1–10.6.3
Synchronised, protected time

System clocks synchronised via time-synchronisation technology from industry-accepted sources; time data protected from unauthorised change.

10.7.2–10.7.3
Detect and respond to control failures

Failures of critical security control systems (NSCs, IDS, FIM, anti-malware, the SIEM itself) are detected, alerted and responded to promptly with documented process.

Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.

Where programmes actually fail

Collection without review

A SIEM full of unreviewed events fails 10.4.1 exactly as loudly as no SIEM — the evidence is triage records and tickets, not license spend.

Log sources missing from coverage

Databases holding PAN and the application tier are the classic gaps; assessors reconcile SIEM sources against the asset inventory.

Retention that quietly truncates

Storage pressure trims logs to 30-90 days; 10.5.1 requires 12 months, three immediately searchable.

Nobody watches the watchers

10.7 asks what happens when the SIEM agent, FIM or IDS dies — silence for a week is itself the finding.

Evidence a QSA accepts

A policy document proves intent; configuration proves control. Bring these to the assessment:

  • SIEM source coverage reconciled against in-scope asset inventory
  • Daily-review evidence: alert queues, triage tickets, escalation records
  • Retention configuration + a 12-month-old log retrieval demonstration
  • NTP configuration and time-integrity protections
  • Alerting and response records for a security-control failure (10.7)

Requirement 10 FAQ

Is a SIEM mandatory?

The standard mandates outcomes: daily review of specified logs using automated mechanisms (10.4.1.1) and protected central retention. In practice that means SIEM-class tooling for any non-trivial environment.

How long must PCI logs be kept?

At least 12 months, with the most recent three months immediately available (10.5.1).

What changed in v4 for log review?

The daily review must be performed with automated mechanisms as of 31 March 2025 (10.4.1.1) — manual-only review is no longer a compliant control.

← Requirement 9: Physical SecurityRequirement 11: Security Testing

Requirement 10 in your environment

A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.