PCI DSS 4.0
Req 10: Logging and Monitoring

PCI DSS 4.0 10.7.2: 10.7.2 Detect and alert on critical security control failures

When a critical security control system fails, the failure must be detected, alerted and addressed promptly, covering at least failures of: IDS/IPS; network security controls; anti-malware; change-detection tools; logical access controls; physical access controls; segmentation controls where used; audit logging mechanisms; mechanisms for reviewing audit logs; and any automated security testing tools in use. Applies to all entities, service providers included. Applicability: takes the place of 10.7.1 from 31 March 2025 and adds two control systems that 10.7.1 did not list (the mechanisms for reviewing audit logs and automated security testing tools). Objective under the customized approach: any failure of a critical security control system is spotted and dealt with promptly. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 66 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 5 controls

  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.11 Tune Security Event Alerting Thresholds
  • CIS-13.3 Deploy a Network Intrusion Detection Solution
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-8.9 Centralize Audit Logs

ISO 27001:2022 · 5 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.15 Logging
  • 8.16 Monitoring activities
  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.MA-02 Incident reports are triaged and validated

NIST SP 800-53 Rev 5 · 5 controls

FedRAMP High · 4 controls

  • AU-5 Response to Audit Logging Process Failures
  • SI-4 System Monitoring
  • SI-4(5) System-Generated Alerts
  • SI-6 Security and Privacy Function Verification (SI-6)

FedRAMP Moderate · 4 controls

  • AU-5 Response to Audit Logging Process Failures
  • SI-4 System Monitoring
  • SI-4(5) System-Generated Alerts
  • SI-6 Security and Privacy Function Verification (SI-6)

HIPAA Security Rule · 4 controls

ISO 27002:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation
  • 5.26 Response to information security incidents
  • 8.15 Logging
  • 8.16 Monitoring activities

NIST SP 800-66 Rev 2 · 4 controls

NIST SP 800-172 · 3 controls

  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • 3.14.7e Verify Correctness of Security Functions
  • 3.4.2e Automated Detection and Remediation of Unauthorized Software

SOC 2 · 3 controls

  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-30 Endpoint detection and response (Very Good)
  • ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources

CMMC 2.0 · 2 controls

ISO 27701:2019 · 2 controls

  • 6.13.1 Management of information security incidents and improvements
  • 6.9.4 Logging and monitoring

ISO/IEC 42001:2023 · 2 controls

  • 10.2 Nonconformity and corrective action
  • 9.1 Monitoring, measurement, analysis and evaluation
  • P2-2.3.2 P2-2.3.2 Security control failures detected and responded to
  • P2-3.3.2 P2-3.3.2 Application protection mechanisms monitored and maintained

APRA CPS 234 · 1 control

  • SEC04-BP04 Initiate remediation for non-compliant resources

C5 (Germany) · 1 control

  • C5-OPS-17 Logging and Monitoring - Availability of the Monitoring Software

NIS2 Directive · 1 control

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • 03.03.04 Response to Audit Logging Process Failures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 10: Logging and Monitoring

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 10.7.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 66 it maps to, and the evidence behind each claim, over MCP and REST.