What information must each audit log entry contain?
- A.Only the user name and action, which matches v4.0's position that centralized logging is needed only for internet-facing components, with internal systems permitted to keep local logs that are never reviewed
- B.Only the timestamp, as audit logs must be retained for three months in total with no archival obligation for SAQ A merchants
- C.User ID, event type, date/time, success/failure, origination of event, and identity or name of affected data/system/resource
- D.Only the event description, given that the standard permits audit log files to be editable by the administrators they record
Why C is correct
PCI DSS requires comprehensive log entries containing user identification, event type, timestamp, outcome, event origin, and affected component or resource.
Know someone studying for PCI DSS? Send them this one.