r10.1 Enable CloudTrail across the organization
Log all API calls and access to system components with an AWS CloudTrail organization trail, the foundation for reconstructing events and tying actions to individual users.
AWS services
Requirement 10
Log and Monitor All Access to System Components and Cardholder Data
PCI sub-requirements covered
- 10.2 Audit logs are implemented to support the detection of anomalies and suspicious activity
How to implement on AWS
Create an AWS CloudTrail organization trail covering all accounts and Regions, delivered to a centralized S3 bucket in a dedicated logging account. Enable data events for CDE resources when necessary. Verify coverage with Security Hub/Config.
Practical implementation
How this control is implemented in each reference architecture:
Enable an AWS CloudTrail trail (management and, for the CDE, data events) delivering to an S3 bucket in the account; verify coverage with Config/Security Hub.
Single-account, 3-tier →Create an organization trail from the management/log-archive account so every CDE account is logged automatically to the centralized, dedicated log-archive bucket, with data events enabled for CDE resources.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Interview the administrator and examine configurations to verify audit logs are enabled and active for all system components (10.2.1).
- Examine audit log configurations and log data to verify capture of individual user access to CHD, all administrative actions, access to audit logs, invalid access attempts, credential changes, and creation/deletion of system-level objects (10.2.1.1 through 10.2.1.7).
Evidence in AWS
- CloudTrail organization trail active across all accounts/Regions.
- Log delivery to the centralized S3 bucket in the logging account.
- Data-events configuration for CDE resources where applicable.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 10.2 — Records of all activities affecting system components and cardholder data are captured.
Learning resources
References
- AWS Security Maturity Model: API audit logging
PCI DSS Security Maturity Model