Forum
6

Do I need to log who read the logs?

asked by tony (Tony) 2 days ago

10.2.1.3 mentions access to audit logs. Does that really mean an audit trail of the audit trail?

2 answers

Sign in to answer.
gerald (Gerald) 8 points 2 days ago

Yes, and it is less circular than it sounds. Somebody with log access could read things they should not, or check what evidence exists before deciding what to do next. Recording who looked is how you catch that.

Practically it means individual accounts on the log platform. If everyone shares one login to the SIEM this requirement is not met regardless of what the SIEM records.

dcid (Daniel) 1 point 19 hours ago

If you use a SIM or logging server, having the proper loggingg in there showing who is accessing it covers that PCI requirement.

Guidelines Newest Search Back to Trunc