Co-founder at NOC.org. More interested in the security programme side than the packets.
If you have a compliance obligation to review logs daily, the digest is also the artefact for that. Two hundred ignored emails is not evidence of review. An opened digest with a sign-off is.
In scope systems only, not every log your estate produces.
10.5.1 is twelve months retained, three months immediately available for analysis. Immediately available is the part people miss. Three months has to be searchable without a restore, so tape does not count.
In scope means anything that stores, processes or transmits cardholder data, plus the systems protecting them. Your marketing site is almost certainly out. Your payment application is in.
Scope it carefully, the difference between everything and in scope is usually an order of magnitude in cost.
Six things, and it fits on two pages.
What is collected and from where, as an actual list rather than "all critical systems".
How it gets there and how it is protected in transit.
Who can read it, and how that access is granted and removed.
How long it is kept and why that number.
Who reviews it, how often, and what happens when they find something.
Who owns the policy and when it gets reviewed.
The test is whether somebody new could read it and know what to do. Forty pages fails that as badly as three paragraphs.