PCI DSS 10.4.1.1: Automated mechanisms are used to perform audit log reviews

PCI DSS v4.0.1 control 10.4.1.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 10.4.

Requirement 10: Log and Monitor All Access to System Components and Cardholder Data › Section 10.4

Automated mechanisms are used to perform audit log reviews.

Summary

The daily log review is performed with automated mechanisms, not by reading.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
10.4.1.1 Examine log review mechanisms and interview personnel to verify that automated mechanisms are used to perform log reviews.

One sentence, and it settles a question entities used to argue about: automation is required, not optional. 10.4.1 says the security-relevant logs are reviewed daily; this says the review uses automated mechanisms. The reasoning is arithmetic. A real environment produces a log volume no person can read daily, so a manual daily review is either not happening or not covering what it claims, and the standard now says so directly rather than leaving it to be discovered. The procedure examines the mechanisms and interviews personnel, which is worth noting: automation performs the review, and people still have to understand what it looks for and what it does when it finds something.

What to prepare

  • The tooling performing the review, and what rules or correlation it applies.
  • Evidence the automation covers the sources named in 10.4.1.
  • Personnel who can describe what it looks for.
  • What happens to what it surfaces, which is 10.4.3.

How to implement it

1. Let the tooling triage and people investigate. That division is what the two controls together describe, and it is also the only workable one.

2. Check coverage rather than deployment. A SIEM ingesting three of ten source types automates a review of three of ten.

3. Tune deliberately and record why. Suppressed alerts are decisions about what the daily review no longer covers, so they belong in the procedure rather than in a console.

4. Make sure someone can explain it. The procedure interviews personnel, and a black box nobody understands is a weak answer.

Where this commonly fails

  • Automation deployed over a fraction of the log sources.
  • Rules never revisited, so the review covers yesterday's threats.
  • Suppressions accumulated in the console with no record of the decisions.
  • Nobody able to describe what the automation does, which the interview surfaces.

Others in section 10.4:

Control What it requires
10.4.1 The following audit logs are reviewed at least once daily…
10.4.2 Logs of all other system components (those not specified in Requirement 10.4.1) are reviewed…
10.4.2.1 The frequency of periodic log reviews for all other system components…
10.4.3 Exceptions and anomalies identified during the review process are addressed

10.4.1 · All controls · 10.4.2

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.