r10.4 Automated log review and anomaly detection
Review audit logs in an automated way to identify anomalous or suspicious activity, going beyond daily manual review through automatic mechanisms.
AWS services
Requirement 10
Log and Monitor All Access to System Components and Cardholder Data
PCI sub-requirements covered
- 10.4 Audit logs are reviewed to identify anomalies or suspicious activity
How to implement on AWS
Analyze logs with CloudWatch Logs Insights and anomaly detection. Correlate signals with GuardDuty and consolidate in Security Hub. Define alarms and metrics for critical security events. Document the daily review of high-risk events through automated mechanisms.
Practical implementation
How this control is implemented in each reference architecture:
Analyze logs with CloudWatch Logs Insights and GuardDuty in the account, define alarms for critical events, and document the automated daily review of high-risk events.
Single-account, 3-tier →Aggregate logs and detections into the security tooling account (Security Hub + optionally OpenSearch/Detective over the central logs) so anomaly review spans all CDE accounts from a single pane.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine policies and observe processes to verify the required logs are reviewed at least once daily (10.4.1.a, 10.4.1.b).
- Examine log-review mechanisms and interview personnel to verify automated mechanisms are used to perform the reviews (10.4.1.1).
- Observe processes and interview personnel to verify exceptions and anomalies identified during review are addressed (10.4.3.b).
Evidence in AWS
- CloudWatch Logs Insights queries/alarms on security events.
- GuardDuty findings consolidated in Security Hub.
- Evidence of automated review of high-risk logs.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 10.4 — Potentially suspicious or anomalous activities are quickly identified to minimize impact.
Learning resources
References
- AWS Security Maturity Model: Alarms and analysis
- PCI DSS v4.0.1 Requirement 10.4
PCI DSS Security Maturity Model