Log Management

PCIComplianceHubLast updated

The lifecycle around log data: collecting it from across the estate, centralising it, protecting it from alteration or deletion, retaining it for a defined period, reviewing it and disposing of it. PCI DSS requires at least 12 months of retention with the most recent three months immediately available, daily review of security-critical logs, and, under v4.x, automated mechanisms to perform that review. Centralising logs onto a separate hardened system matters because an attacker who controls a host can otherwise edit the evidence of the intrusion.