PCI DSS 10.4.2: Logs of all other system components (those not specified in Requirement 10.4.1) are reviewed
PCI DSS v4.0.1 control 10.4.2: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 10.4.
Requirement 10: Log and Monitor All Access to System Components and Cardholder Data › Section 10.4
Logs of all other system components (those not specified in Requirement 10.4.1) are reviewed periodically.
Summary
The logs that are not on the daily list still get reviewed, on a frequency you have chosen and can defend.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 10.4.2.a | Examine security policies and procedures to verify that processes are defined for reviewing logs of all other system components periodically. |
| 10.4.2.b | Examine documented results of log reviews and interview personnel to verify that log reviews are performed periodically. |
The counterpart to 10.4.1. That control names four categories reviewed daily; this one covers everything else, periodically. Two things follow. First, its scope is defined by subtraction, so if you never listed your system components you cannot show what falls here. Second, "periodically" is your number, set by the targeted risk analysis at 10.4.2.1 and then binding: an undefined frequency cannot be met, and a defined one you miss is a clear finding.
What to prepare
- The frequency you defined, and the risk analysis behind it.
- The list of components in this category, which is the inventory minus 10.4.1’s four.
- Review records at that frequency, including the uneventful ones.
How to implement it
1. Derive the scope from the inventory. This control is the remainder of a subtraction, and a remainder is only knowable if the whole is. An incomplete inventory silently shrinks it.
2. Choose a frequency you will actually hit. Monthly performed is stronger evidence than weekly intended. The requirement lets you decide; it does not let you drift.
3. Automate the collection, keep the judgement. As with 10.4.1, tooling can surface exceptions; what cannot be absent is someone looking and a record of it.
4. Say what a review looks like. Without a defined output, "we look at the dashboards" leaves nothing for a procedure to examine.
Where this commonly fails
- No defined frequency, so there is nothing to be measured against and nothing to pass.
- Scope taken as "the rest" without an inventory that says what the rest is.
- Reviews performed and unrecorded, so the evidence is an assertion.
- The frequency defined in policy and a longer one in practice.
Related controls
This control refers to 10.4.1.
Others in section 10.4:
| Control | What it requires |
|---|---|
| 10.4.1 | The following audit logs are reviewed at least once daily… |
| 10.4.1.1 | Automated mechanisms are used to perform audit log reviews |
| 10.4.2.1 | The frequency of periodic log reviews for all other system components… |
| 10.4.3 | Exceptions and anomalies identified during the review process are addressed |
← 10.4.1.1 · All controls · 10.4.2.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.