PCI_DSS_v4Requirement 10voice-validated
PCI_DSS_v4 R10: Requirement 10
PCI_DSS_v4
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Logging mechanisms and the ability to track user activities are critical in preventing, detecting, or minimising the impact of a data compromise. The presence of logs on all system components and in the CDE allows thorough tracking, alerting, and analysis when something does go wrong.
ATT&CK techniques this article tests · 15
| Technique | Why it maps | Confidence |
|---|---|---|
| T1070.001 | 1. Attackers clear Windows Event Logs to evade detection. Requirement 10 mandates logging, making this technique directly detectable through log integrity checks. | 90% |
| T1070.002 | 1. Attackers clear Linux or macOS Event Logs to remove traces. Requirement 10's logging mechanisms are designed to detect such defense evasion. | 90% |
| T1078 | 1. Valid Accounts are used for initial access and persistence. Requirement 10 requires tracking user activities, including successful and failed login attempts, to detect misuse of valid accounts. | 80% |
| T1136 | 1. Creating new accounts establishes persistence. Requirement 10 mandates logging system changes, including new user account creation, to identify unauthorized access. | 80% |
| T1003 | 1. OS Credential Dumping involves accessing sensitive system memory. Requirement 10's logging can capture process execution, file access, or security events indicative of credential theft. | 70% |
| T1055 | 1. Process Injection allows code execution in other processes. Requirement 10's comprehensive logging can detect unusual process behavior or unauthorized code execution attempts. | 70% |
| T1562.002 | 1. Disabling or modifying system firewalls evades defenses. Requirement 10 requires logging system configuration changes, which would include firewall alterations, to maintain security posture. | 80% |
| T1021 | 1. Remote Services are used for lateral movement. Requirement 10 mandates logging remote access attempts and successful connections, enabling detection of unauthorized network traversal. | 80% |
| T1005 | 1. Data from Local System involves accessing sensitive files. Requirement 10's logging capabilities can track file access, modification, and deletion events on critical systems. | 70% |
| T1041 | 1. Exfiltration Over C2 Channel involves data egress. Requirement 10's network logging and monitoring can identify unusual outbound data transfers or command-and-control communications. | 70% |
| T1486 | 1. Data Encrypted for Impact disrupts operations. Requirement 10's system and file integrity logging can detect unusual file encryption activities or process executions associated with ransomware. | 70% |
| T1087 | 1. Account Discovery identifies potential targets. Requirement 10's logging of failed authentication attempts or directory queries can reveal reconnaissance activities. | 70% |
| T1190 | 1. Exploiting Public-Facing Applications is a common initial access vector. Requirement 10 mandates logging web server and application access, enabling detection of exploitation attempts. | 80% |
| T1543.003 | 1. Creating or Modifying System Processes, like Windows Services, establishes persistence. Requirement 10 requires logging system service changes, which helps detect unauthorized modifications. | 80% |
| T1071 | 1. Application Layer Protocol usage for C2 can bypass traditional firewalls. Requirement 10's network flow and proxy logs can identify suspicious application-layer communications. | 70% |
Defending mitigations · 5
| Mitigation | What it does | Confidence |
|---|---|---|
| M1047 | 1. Audit processes, including regular review of logs, are essential for detecting anomalies as mandated by PCI DSS v4 Requirement 10. | 90% |
| M1048 | 1. Account Use Policies define expected user behavior. Requirement 10's logging tracks adherence to these policies, identifying deviations. | 80% |
| M1039 | 1. Privilege Account Management ensures that actions performed by privileged accounts are meticulously logged, a key aspect of PCI DSS v4 Requirement 10. | 80% |
| M1051 | 1. Software Configuration ensures logging mechanisms are correctly implemented and maintained, supporting PCI DSS v4 Requirement 10's objectives. | 70% |
| M1018 | 1. User Account Management practices are critical for tracking individual user activities, directly supporting the goals of PCI DSS v4 Requirement 10. | 80% |
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-778 | 1. Insufficient Logging directly undermines PCI DSS v4 Requirement 10, as it prevents effective tracking and detection of security incidents. | 90% |
| CWE-284 | 1. Improper Access Control allows unauthorized users to disable or tamper with logging mechanisms, directly violating PCI DSS v4 Requirement 10's intent. | 80% |
| CWE-200 | 1. Exposure of Sensitive Information to an Unauthorized Actor can occur if logs themselves are not adequately protected, compromising the integrity of evidence required by PCI DSS v4 Requirement 10. | 70% |
| CWE-532 | 1. Inclusion of Sensitive Information in Log Files makes logs a target for attackers, potentially leading to data compromise despite PCI DSS v4 Requirement 10's logging mandate. | 70% |
| CWE-798 | 1. Use of Hard-coded Credentials can compromise systems responsible for logging, allowing attackers to disable or manipulate logs, contrary to PCI DSS v4 Requirement 10. | 60% |
| CWE-863 | 1. Incorrect Authorization allows unauthorized actions to occur without proper logging, directly conflicting with the tracking requirements of PCI DSS v4 Requirement 10. | 80% |
| CWE-922 | 1. Insecure Storage of Sensitive Information, including log data, compromises the integrity and availability of audit trails, undermining PCI DSS v4 Requirement 10. | 70% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0179 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation