Requirement 10: Log and Monitor All Access to System Components and Cardholder Data
Requirement 10 decides whether a breach is a bad week or an existential event. v4’s change with operational bite: daily log review must use automated mechanisms — a human eyeballing syslog no longer scales or complies.
Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series
The controls that decide your assessment
Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.
Where programmes actually fail
A SIEM full of unreviewed events fails 10.4.1 exactly as loudly as no SIEM — the evidence is triage records and tickets, not license spend.
Databases holding PAN and the application tier are the classic gaps; assessors reconcile SIEM sources against the asset inventory.
Storage pressure trims logs to 30-90 days; 10.5.1 requires 12 months, three immediately searchable.
10.7 asks what happens when the SIEM agent, FIM or IDS dies — silence for a week is itself the finding.
Evidence a QSA accepts
A policy document proves intent; configuration proves control. Bring these to the assessment:
- SIEM source coverage reconciled against in-scope asset inventory
- Daily-review evidence: alert queues, triage tickets, escalation records
- Retention configuration + a 12-month-old log retrieval demonstration
- NTP configuration and time-integrity protections
- Alerting and response records for a security-control failure (10.7)
Requirement 10 FAQ
Is a SIEM mandatory?
The standard mandates outcomes: daily review of specified logs using automated mechanisms (10.4.1.1) and protected central retention. In practice that means SIEM-class tooling for any non-trivial environment.
How long must PCI logs be kept?
At least 12 months, with the most recent three months immediately available (10.5.1).
What changed in v4 for log review?
The daily review must be performed with automated mechanisms as of 31 March 2025 (10.4.1.1) — manual-only review is no longer a compliant control.
Requirement 10 in your environment
A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.
