PCI DSS 10.4.2.1: The frequency of periodic log reviews for all other system components

PCI DSS v4.0.1 control 10.4.2.1: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 10.4.

Requirement 10: Log and Monitor All Access to System Components and Cardholder Data › Section 10.4

The frequency of periodic log reviews for all other system components (not defined in Requirement 10.4.1) is defined in the entity’s targeted risk analysis, which is performed according to all elements specified in Requirement 12.3.1

Summary

You choose how often the non-daily logs get reviewed, and you have to justify the interval with a risk analysis.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
10.4.2.1.a Examine the entity’s targeted risk analysis for the frequency of periodic log reviews for all other system components (not defined in Requirement 10.4.1) to verify the risk analysis was performed in accordance with all elements specified at Requirement 12.3.1.
10.4.2.1.b Examine documented results of periodic log reviews of all other system components (not defined in Requirement 10.4.1) and interview personnel to verify log reviews are performed at the frequency specified in the entity’s targeted risk analysis performed for this requirement.

The frequency behind 10.4.2, and the third control in the standard built on the same pattern as 8.6.3 and 12.10.4.1: the interval is yours, conditional on a targeted risk analysis performed according to all elements specified in 12.3.1. Two procedures test the two halves separately, and they fail independently. 10.4.2.1.a examines the analysis against 12.3.1's elements; 10.4.2.1.b examines documented results of the reviews and interviews the people doing them, so a defensible interval that is not being met fails just as surely as no analysis at all. Note the scope: all other system components, meaning everything outside the daily list in 10.4.1, which is usually the larger population.

What to prepare

  • The targeted risk analysis for this frequency specifically.
  • The list of system components it covers, defined by exclusion from 10.4.1.
  • Documented results of the reviews at the chosen interval, which 10.4.2.1.b examines.
  • The 12-month review of the analysis that 12.3.1 requires.

How to implement it

1. Define the population by writing down 10.4.1's list first. This control covers everything else, so it cannot be scoped until the daily list exists.

2. Choose an interval you will actually meet. 10.4.2.1.b compares records against your own number, so a modest interval honoured beats an ambitious one skipped.

3. Record the review, not just the finding. "Reviewed, nothing anomalous" is the documented result the procedure asks for, and silence is not.

4. Connect it to 10.4.3. Anything the review turns up has to be addressed, so the two are one process with two controls over it.

Where this commonly fails

  • A sensible interval with no analysis behind it, which fails 10.4.2.1.a on the evidence.
  • One generic risk analysis cited for every frequency the standard leaves open, addressing none of them specifically.
  • Reviews performed and not recorded, leaving 10.4.2.1.b nothing to examine.
  • The population never defined, so nobody can say which components this covers.

This control refers to 10.4.1, 12.3.1.

Others in section 10.4:

Control What it requires
10.4.1 The following audit logs are reviewed at least once daily…
10.4.1.1 Automated mechanisms are used to perform audit log reviews
10.4.2 Logs of all other system components (those not specified in Requirement 10.4.1) are reviewed…
10.4.3 Exceptions and anomalies identified during the review process are addressed

10.4.2 · All controls · 10.4.3

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.