PCI DSS Security Maturity Model·AWS v1.0.0
Efficient Threat Detection 🤝 Shared

r10.4 Automated log review and anomaly detection

Review audit logs in an automated way to identify anomalous or suspicious activity, going beyond daily manual review through automatic mechanisms.

Quick Wins
Foundational
Efficient
Optimized
Effort: Medium Impact: Medium Applies to CDE: Yes

AWS services

Amazon CloudWatch Amazon GuardDuty AWS Security Hub Amazon OpenSearch Service

Requirement 10

Log and Monitor All Access to System Components and Cardholder Data

PCI sub-requirements covered

  • 10.4 Audit logs are reviewed to identify anomalies or suspicious activity

How to implement on AWS

Analyze logs with CloudWatch Logs Insights and anomaly detection. Correlate signals with GuardDuty and consolidate in Security Hub. Define alarms and metrics for critical security events. Document the daily review of high-risk events through automated mechanisms.

Practical implementation

How this control is implemented in each reference architecture:

Analyze logs with CloudWatch Logs Insights and GuardDuty in the account, define alarms for critical events, and document the automated daily review of high-risk events.

Single-account, 3-tier →

Aggregate logs and detections into the security tooling account (Security Hub + optionally OpenSearch/Detective over the central logs) so anomaly review spans all CDE accounts from a single pane.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineobserve

Testing procedures

  • Examine policies and observe processes to verify the required logs are reviewed at least once daily (10.4.1.a, 10.4.1.b).
  • Examine log-review mechanisms and interview personnel to verify automated mechanisms are used to perform the reviews (10.4.1.1).
  • Observe processes and interview personnel to verify exceptions and anomalies identified during review are addressed (10.4.3.b).

Evidence in AWS

  • CloudWatch Logs Insights queries/alarms on security events.
  • GuardDuty findings consolidated in Security Hub.
  • Evidence of automated review of high-risk logs.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 10.4 — Potentially suspicious or anomalous activities are quickly identified to minimize impact.

Learning resources

References

  • AWS Security Maturity Model: Alarms and analysis
  • PCI DSS v4.0.1 Requirement 10.4