Forum
15

PCI 10.7, detecting failures of security controls. What does an assessor want to see?

asked by tony (Tony) 11 days ago

It stopped being future dated in March 2025 and I would rather be ready than surprised.

2 answers

Sign in to answer.
dcid (Daniel) 19 points 11 days ago

Short version is you have to notice when your logging stops.

10.7.2 lists the controls whose failure must be detected and the audit logging mechanism is one of them. So if a server stops sending logs, something has to raise it.

This is genuinely hard because a source going quiet produces no event anywhere. There is no log line that says nothing is happening. Everything looks calm and the one system you cannot see is the one you should worry about.

What they want is a mechanism comparing expected sources against actual, an alert when the gap appears, and evidence you acted on it when it fired. That last part is the one people forget.

gerald (Gerald) 8 points 10 days ago

Our assessor asked for three months of alert history and picked one at random to ask what we did about it. Have the answer ready.

Guidelines Newest Search Back to Trunc