Audit Log / Audit Trail

Also: Audit Log, Audit Trail, Log

PCIComplianceHubLast updated

A chronological record of activity on a system: who did what, to which resource, from where and when. PCI DSS Requirement 10 sets out what must be captured for system components in scope, including all access to account data, all actions taken by users with administrative privilege, access to the logs themselves, invalid access attempts, changes to accounts and credentials, and the starting, stopping or pausing of logging. Logs must be protected against alteration, retained for at least 12 months, and the most recent three months kept immediately available for analysis. Audit logs are often the only evidence available after a compromise, which is why their integrity is treated as a control in its own right.