CompTIA CySA+ (CS0-003)Reporting and CommunicationEasy
A security analyst is preparing a compliance report for the Payment Card Industry Data Security Standard (PCI DSS) Requirement 10, which mandates logging and monitoring of all access to cardholder data. The organization uses a SIEM system to aggregate logs. Which of the following log snippets, if consistently missing, would indicate a direct non-compliance with this requirement?
- AWeb server access logs showing requests for static content.
- BDatabase audit logs showing successful and failed attempts to access cardholder data tables.
- CFirewall logs showing blocked inbound connection attempts.
- DOperating system logs showing successful user logins to non-cardholder data systems.
Show answer & explanationAnswer & explanation
Correct answer: B. Database audit logs showing successful and failed attempts to access cardholder data tables.
PCI DSS Requirement 10 specifically focuses on logging and monitoring all access to cardholder data. Database audit logs showing access attempts to cardholder data tables directly address this requirement. Missing these logs would be a clear indication of non-compliance.
Why the other options are wrong
- A. While web server logs are important, requests for static content don't directly relate to cardholder data access monitoring as required by PCI DSS 10.
- C. Firewall logs are crucial for network security, but they don't specifically detail 'access to cardholder data' as required by PCI DSS 10.
- D. Operating system logins are important, but if they are for non-cardholder data systems, their absence doesn't directly constitute non-compliance with the specific 'access to cardholder data' aspect of PCI DSS 10.
PCI DSS Requirement 10
A PCI DSS requirement mandating the tracking and monitoring of all access to network resources and cardholder data, ensuring that all actions are logged, reviewed, and retained.
- Focuses on logging and monitoring.
- Applies to all access to cardholder data and network resources.
- Requires audit trails to be linked to individual users.
Memory trick: PCI 10: Cardholder Data Access Must Be Logged & Tracked.