Dr Anton Chuvakin Blog (Original)

Security writing since the mid-2000s. New posts are mirrored from Anton on Security on Medium.

OMG, How Naive!

"Designing a PCI-Compliant Log Monitoring System" paper is incredibly naive, since the author thinks "logging in PCI = Requirement 10." Read this instead and learn that logging is actually present (or implied!) in ALL 12 of the PCI DSS Requirements.

Comments

Anonymous said…
Anton, what about the PCI Answers blog? We talk about audit logging:

http://pcianswers.com/2006/07/31/track-and-monitor-all-access-to-network-resources-and-cardholder-data/
http://www.insecuremagazine.com/INSECURE-Mag-8.pdf
Anton Chuvakin said…
Thanks for the link to this insightful post! Really good stuff.