▲
15
PCI 10.7, detecting failures of security controls. What does an assessor want to see?
It stopped being future dated in March 2025 and I would rather be ready than surprised.
It stopped being future dated in March 2025 and I would rather be ready than surprised.
Short version is you have to notice when your logging stops.
10.7.2 lists the controls whose failure must be detected and the audit logging mechanism is one of them. So if a server stops sending logs, something has to raise it.
This is genuinely hard because a source going quiet produces no event anywhere. There is no log line that says nothing is happening. Everything looks calm and the one system you cannot see is the one you should worry about.
What they want is a mechanism comparing expected sources against actual, an alert when the gap appears, and evidence you acted on it when it fired. That last part is the one people forget.