r10.5 Timely detection and alerting of critical control failures
Detect, alert on, and address failures of critical security controls (e.g. logging, firewalls, anti-malware) in a timely manner to minimize the exposure window.
AWS services
Requirement 10
Log and Monitor All Access to System Components and Cardholder Data
PCI sub-requirements covered
- 10.7 Failures of critical security control systems are detected, reported, and responded to promptly
How to implement on AWS
Monitor the health of critical controls (CloudTrail active, GuardDuty enabled, Config recording on, WAF active) with AWS Config conformance packs and alarms. Automatically alert on failures via EventBridge/SNS and create incidents. Document response and remediation times.
Practical implementation
How this control is implemented in each reference architecture:
Monitor the health of critical controls (CloudTrail on, Config recording, GuardDuty enabled, WAF active) with Config conformance packs and alarms; alert via EventBridge/SNS in the account.
Single-account, 3-tier →Monitor critical-control health org-wide from the security tooling account (conformance packs + Config aggregator), so a disabled control in any CDE account raises a central alert and is tracked to remediation.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine documentation to verify processes are defined for prompt detection and reporting of failures of critical security controls, and observe alerting processes to confirm a failure generates an alert (10.7.2.a, 10.7.2.b).
- Examine records to verify failures are documented with cause, duration (start/end), and remediation details, and responded to per the requirement (10.7.3.a, 10.7.3.b).
Evidence in AWS
- Config conformance packs / rules that monitor the state of critical controls.
- EventBridge rules and SNS notifications on control failures.
- Incident records and remediation times for control failures.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 10.7 — Failures in critical security control systems are promptly identified and addressed.
Learning resources
References
- PCI DSS v4.0.1 Requirement 10.7
PCI DSS Security Maturity Model