PCI DSS Security Maturity Model·AWS v1.0.0
Quick Wins Threat Detection 🤝 Shared

r10.1 Enable CloudTrail across the organization

Log all API calls and access to system components with an AWS CloudTrail organization trail, the foundation for reconstructing events and tying actions to individual users.

Quick Wins
Foundational
Efficient
Optimized
Effort: Low Impact: High Applies to CDE: Yes

AWS services

AWS CloudTrail Amazon S3 AWS Organizations

Requirement 10

Log and Monitor All Access to System Components and Cardholder Data

PCI sub-requirements covered

  • 10.2 Audit logs are implemented to support the detection of anomalies and suspicious activity

How to implement on AWS

Create an AWS CloudTrail organization trail covering all accounts and Regions, delivered to a centralized S3 bucket in a dedicated logging account. Enable data events for CDE resources when necessary. Verify coverage with Security Hub/Config.

Practical implementation

How this control is implemented in each reference architecture:

Enable an AWS CloudTrail trail (management and, for the CDE, data events) delivering to an S3 bucket in the account; verify coverage with Config/Security Hub.

Single-account, 3-tier →

Create an organization trail from the management/log-archive account so every CDE account is logged automatically to the centralized, dedicated log-archive bucket, with data events enabled for CDE resources.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineobserve

Testing procedures

  • Interview the administrator and examine configurations to verify audit logs are enabled and active for all system components (10.2.1).
  • Examine audit log configurations and log data to verify capture of individual user access to CHD, all administrative actions, access to audit logs, invalid access attempts, credential changes, and creation/deletion of system-level objects (10.2.1.1 through 10.2.1.7).

Evidence in AWS

  • CloudTrail organization trail active across all accounts/Regions.
  • Log delivery to the centralized S3 bucket in the logging account.
  • Data-events configuration for CDE resources where applicable.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 10.2 — Records of all activities affecting system components and cardholder data are captured.

Learning resources

References

  • AWS Security Maturity Model: API audit logging