![]() |
|
|||||||
| [PCI-DSS] Requirement 10: Track and monitor all access to network resources and cardholder data Logging mechanisms and the ability to track user activities are critical. The presence of logs in all environments allows thorough tracking and analysis when something does go wrong. Determining the cause of a compromise is very difficult without system activity logs. |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
||||
|
||||
|
10.2.2 Actions taken by any individual with root or administrative privileges
|
|
#2
|
|||
|
|||
|
Hi,
Any advice on what constitutes "all actions", the logs would be considerably large if all acions where to be logged by admins. |
|
#3
|
|||
|
|||
|
All actions by users with privilege that involve card holder information must be logged. This is necessary in case of a breach to forensically determine what happened. Failing to log could make you grossly negligent and result in big fines. Big disks are cheap compared to a fine.
|
|
#4
|
|||
|
|||
|
As far as I know this requirement is a bit vague. What is an action? Assuming that they mean executed commands, you can meet this requirement by using the ex audit class.
__________________
compromise agreements |
|
#5
|
|||
|
|||
|
Does anyone have real world examples on how to accomplish this in a Windows environment?
|
|
#6
|
|||
|
|||
|
Database logging, application-specific logging, etc. All actions performed on sensitive CHD must be logged. This facilitates investigating suspected breaches or other irregularities.
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| 10.1 Establish a process for linking all access to system components (especially access done with administrative privileges such as root) to each individual user. | admin | [PCI-DSS] Requirement 10: Track and monitor all access to network resources and cardholder data | 0 | 03-18-2007 03:25 AM |
| [PCI-DSS] 2.3 Encrypt all non-console administrative access. Use technologies such as SSH, VPN, or SSL/TLS for web-based management and other non-console administrative access. | admin | [PCI-DSS] Requirement 2: Do not use vendor-supplied defaults for system passwords and other security | 0 | 03-18-2007 02:51 AM |