PCI_DSS_v4Requirement 10voice-validated

PCI_DSS_v4 R10: Requirement 10

PCI_DSS_v4

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Logging mechanisms and the ability to track user activities are critical in preventing, detecting, or minimising the impact of a data compromise. The presence of logs on all system components and in the CDE allows thorough tracking, alerting, and analysis when something does go wrong.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T1070.0011. Attackers clear Windows Event Logs to evade detection. Requirement 10 mandates logging, making this technique directly detectable through log integrity checks.
90%
T1070.0021. Attackers clear Linux or macOS Event Logs to remove traces. Requirement 10's logging mechanisms are designed to detect such defense evasion.
90%
T10781. Valid Accounts are used for initial access and persistence. Requirement 10 requires tracking user activities, including successful and failed login attempts, to detect misuse of valid accounts.
80%
T11361. Creating new accounts establishes persistence. Requirement 10 mandates logging system changes, including new user account creation, to identify unauthorized access.
80%
T10031. OS Credential Dumping involves accessing sensitive system memory. Requirement 10's logging can capture process execution, file access, or security events indicative of credential theft.
70%
T10551. Process Injection allows code execution in other processes. Requirement 10's comprehensive logging can detect unusual process behavior or unauthorized code execution attempts.
70%
T1562.0021. Disabling or modifying system firewalls evades defenses. Requirement 10 requires logging system configuration changes, which would include firewall alterations, to maintain security posture.
80%
T10211. Remote Services are used for lateral movement. Requirement 10 mandates logging remote access attempts and successful connections, enabling detection of unauthorized network traversal.
80%
T10051. Data from Local System involves accessing sensitive files. Requirement 10's logging capabilities can track file access, modification, and deletion events on critical systems.
70%
T10411. Exfiltration Over C2 Channel involves data egress. Requirement 10's network logging and monitoring can identify unusual outbound data transfers or command-and-control communications.
70%
T14861. Data Encrypted for Impact disrupts operations. Requirement 10's system and file integrity logging can detect unusual file encryption activities or process executions associated with ransomware.
70%
T10871. Account Discovery identifies potential targets. Requirement 10's logging of failed authentication attempts or directory queries can reveal reconnaissance activities.
70%
T11901. Exploiting Public-Facing Applications is a common initial access vector. Requirement 10 mandates logging web server and application access, enabling detection of exploitation attempts.
80%
T1543.0031. Creating or Modifying System Processes, like Windows Services, establishes persistence. Requirement 10 requires logging system service changes, which helps detect unauthorized modifications.
80%
T10711. Application Layer Protocol usage for C2 can bypass traditional firewalls. Requirement 10's network flow and proxy logs can identify suspicious application-layer communications.
70%

Defending mitigations · 5

MitigationWhat it doesConfidence
M10471. Audit processes, including regular review of logs, are essential for detecting anomalies as mandated by PCI DSS v4 Requirement 10.
90%
M10481. Account Use Policies define expected user behavior. Requirement 10's logging tracks adherence to these policies, identifying deviations.
80%
M10391. Privilege Account Management ensures that actions performed by privileged accounts are meticulously logged, a key aspect of PCI DSS v4 Requirement 10.
80%
M10511. Software Configuration ensures logging mechanisms are correctly implemented and maintained, supporting PCI DSS v4 Requirement 10's objectives.
70%
M10181. User Account Management practices are critical for tracking individual user activities, directly supporting the goals of PCI DSS v4 Requirement 10.
80%

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-7781. Insufficient Logging directly undermines PCI DSS v4 Requirement 10, as it prevents effective tracking and detection of security incidents.
90%
CWE-2841. Improper Access Control allows unauthorized users to disable or tamper with logging mechanisms, directly violating PCI DSS v4 Requirement 10's intent.
80%
CWE-2001. Exposure of Sensitive Information to an Unauthorized Actor can occur if logs themselves are not adequately protected, compromising the integrity of evidence required by PCI DSS v4 Requirement 10.
70%
CWE-5321. Inclusion of Sensitive Information in Log Files makes logs a target for attackers, potentially leading to data compromise despite PCI DSS v4 Requirement 10's logging mandate.
70%
CWE-7981. Use of Hard-coded Credentials can compromise systems responsible for logging, allowing attackers to disable or manipulate logs, contrary to PCI DSS v4 Requirement 10.
60%
CWE-8631. Incorrect Authorization allows unauthorized actions to occur without proper logging, directly conflicting with the tracking requirements of PCI DSS v4 Requirement 10.
80%
CWE-9221. Insecure Storage of Sensitive Information, including log data, compromises the integrity and availability of audit trails, undermining PCI DSS v4 Requirement 10.
70%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0179 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation