PCI DSS FAQ - Payment Card Industry (PCI) Data Security Standard Discussion Forum  

Go Back   PCI DSS FAQ - Payment Card Industry (PCI) Data Security Standard Discussion Forum > Payment Card Industry Data Security Standard Frequently Asked Questions (PCI DSS FAQ) > Regularly Monitor and Test Networks > [PCI-DSS] Requirement 10: Track and monitor all access to network resources and cardholder data

[PCI-DSS] Requirement 10: Track and monitor all access to network resources and cardholder data Logging mechanisms and the ability to track user activities are critical. The presence of logs in all environments allows thorough tracking and analysis when something does go wrong. Determining the cause of a compromise is very difficult without system activity logs.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 03-18-2007, 03:26 AM
admin's Avatar
admin admin is offline
Administrator
 
Join Date: Jul 2002
Posts: 229
Default 10.2.2 All actions taken by any individual with root or administrative privileges

10.2.2 Actions taken by any individual with root or administrative privileges
Reply With Quote
  #2  
Old 01-28-2010, 12:12 PM
mike.vella mike.vella is offline
Junior Member
 
Join Date: Jan 2010
Location: London
Posts: 2
Default

Hi,
Any advice on what constitutes "all actions", the logs would be considerably large if all acions where to be logged by admins.
Reply With Quote
  #3  
Old 03-16-2010, 10:45 AM
Roger Nebel Roger Nebel is offline
Moderator
 
Join Date: Mar 2007
Posts: 43
Default

All actions by users with privilege that involve card holder information must be logged. This is necessary in case of a breach to forensically determine what happened. Failing to log could make you grossly negligent and result in big fines. Big disks are cheap compared to a fine.
Reply With Quote
  #4  
Old 04-22-2010, 06:48 AM
jycegrcia jycegrcia is offline
Junior Member
 
Join Date: Apr 2010
Posts: 2
Default

Quote:
Originally Posted by admin View Post
10.2.2 Actions taken by any individual with root or administrative privileges
As far as I know this requirement is a bit vague. What is an action? Assuming that they mean executed commands, you can meet this requirement by using the ex audit class.
__________________
compromise agreements
Reply With Quote
  #5  
Old 05-20-2010, 09:48 AM
agentgreen agentgreen is offline
Junior Member
 
Join Date: May 2010
Posts: 6
Default

Does anyone have real world examples on how to accomplish this in a Windows environment?
Reply With Quote
  #6  
Old 05-20-2010, 09:59 AM
Roger Nebel Roger Nebel is offline
Moderator
 
Join Date: Mar 2007
Posts: 43
Default

Database logging, application-specific logging, etc. All actions performed on sensitive CHD must be logged. This facilitates investigating suspected breaches or other irregularities.
Reply With Quote
Reply

Bookmarks
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
10.1 Establish a process for linking all access to system components (especially access done with administrative privileges such as root) to each individual user. admin [PCI-DSS] Requirement 10: Track and monitor all access to network resources and cardholder data 0 03-18-2007 03:25 AM
[PCI-DSS] 2.3 Encrypt all non-console administrative access. Use technologies such as SSH, VPN, or SSL/TLS for web-based management and other non-console administrative access. admin [PCI-DSS] Requirement 2: Do not use vendor-supplied defaults for system passwords and other security 0 03-18-2007 02:51 AM


All times are GMT -4. The time now is 04:16 AM.


All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest ©1997 - 2010 by PCIDSSFAQ.ORG, except where noted otherwise.
Powered by vBulletin, Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
PCI-DSS Forum  |  PA-DSS Forum