PCI DSS · Domain 5
Monitoring and Testing
About 15% of the exam
Requirement 10, logging and monitoring
- Coverage
- all access to cardholder data
- Privileged actions
- every administrative action recorded
- Log content
- user, event, time, origin, outcome
- Failed attempts
- invalid access attempts logged too
- Retention
- twelve months, three immediately available
- Review
- daily for the critical logs
- Automation
- automated review mechanisms now required
- Time
- synchronized from approved sources
Version 4.0 requires automated log review mechanisms and prompt detection of any critical security control that fails
Log protection
- Centralized collection away from sources
- Write once or append only storage
- Access to logs strictly limited
- Changes to logs detected and alerted
- Time sources controlled and protected
When a critical control fails
- Detected and alerted promptly
- Cause identified and addressed
- Duration of the failure recorded
- Security impact assessed afterwards
- Controls restored and verified
Requirement 11, testing
- Wireless scan
- quarterly for unauthorized access points
- Internal scan
- quarterly and after significant change
- External scan
- quarterly by an approved vendor
- Internal test
- penetration test at least annually
- External test
- penetration test at least annually
- Segmentation test
- annually, twice yearly for providers
- Intrusion detection
- traffic monitored at the perimeter
- Change detection
- file comparisons at least weekly
Penetration testing must cover the whole CDE perimeter and the critical systems inside it, never a convenient subset
Penetration testing method
- Documented methodology agreed in advance
- Network and application layers both covered
- Segmentation controls tested for isolation
- Tester independent of the systems built
- Findings ranked and then remediated
- Retest confirms the fix worked
- Report states scope, method and limits
A test scoped to part of the environment cannot support a claim about the whole environment
File integrity monitoring
- Critical files and executables watched
- Comparisons at least once weekly
- Alerts investigated, not merely collected
- Baseline updated through change control
- Payment page tamper detection required separately
Incident response duties
- Plan documented and kept current
- Roles, responsibilities and contacts defined
- Tested at least once a year
- Round the clock response availability
- Staff trained for their response duties
- Plan updated from lessons learned
Who to contact
- Acquiring bank
- notified per the merchant agreement
- Card brands
- each has its own rules
- Forensic investigator
- engaged from the approved list
- Legal and regulators
- breach notification obligations apply
- Insurer
- the policy may dictate procedures
PAN found where unexpected
- A documented procedure covers this
- Determine how it got there
- Assess the scope impact immediately
- Delete securely or bring into scope
- Fix the process that leaked it
Monitoring in the cloud
- Control plane events collected too
- Provider logs exported to your store
- Serverless invocations logged with context
- Managed service defaults often log little
- Retention configured, not left to defaults
Detection content that matters
- Privileged use outside normal hours
- Unexpected outbound connections from the CDE
- Large or unusual data transfers
- New accounts created outside process
- Memory scraping behavior on payment systems
- Repeated bursts of failed authentication
Evidence for this goal
- Twelve months of retained logs
- Daily review records or tool output
- Four quarters of passing external scans
- Internal scan reports and remediation
- Penetration test report and retest
- Segmentation test results
- Incident response exercise records
The annual testing calendar
- Quarter one scans
- Quarter two scans
- Quarter three scans
- Quarter four scans
- Annual penetration test
- Segmentation test
- Incident response exercise
- Scope and policy review
- Every significant change inserts extra tests
- Service providers repeat several items twice yearly
- A missed quarter cannot be recovered later
- Plan the calendar rather than reacting
Rapid recall: frequencies
- Log review
- daily for critical systems
- Log retention
- twelve months minimum
- Immediately available
- the most recent three months
- Wireless scan
- at least quarterly
- Vulnerability scans
- quarterly, internal and external
- Penetration test
- at least annually
- Segmentation test
- annually for merchants
- Incident plan test
- at least annually
Testing words to separate
- Vulnerability scan
- automated, finds known weaknesses
- Penetration test
- human, exploits to prove impact
- Segmentation test
- proves the isolation actually holds
- Red team
- broad simulation beyond the standard
- Rescan
- confirms a finding is fixed
Reference strip: log, protect, scan, test, respond
Log
- Access, admin actions, failures
- User, event, time, origin, outcome
- Clocks synchronized centrally
Protect
- Centralized and tamper resistant
- Twelve months retained
- Three months immediately available
Scan
- Internal and external quarterly
- Wireless detection quarterly
- Rescan after significant change
Test
- Penetration testing annually
- Segmentation isolation verified
- File comparisons at least weekly
Respond
- Plan tested every year
- Availability around the clock
- Bank, brands and investigator contacted
Quick exam traps
- Trap: Three months of logs is enough for an assessment
- Trap: A penetration test may cover a representative sample of the CDE
- Trap: Collecting logs satisfies the review requirement
- Trap: Segmentation only needs testing when the network changes
- Trap: A vulnerability scan and a penetration test are interchangeable
- Trap: Service providers follow exactly the same frequencies as merchants
- Trap: Detecting a failed security control is optional if it is fixed quickly
cybercertprep.com · original revision sheet written from the public body of knowledge