welcome to the cyber ery demystifying P. C. I. D. S s compliance course.
This model focused on the goals of the P C I. D ss and the requirements associate it with them.
This video introduces you to requirement 10.
We will talk about the requirements and nuances associated with how do you handle the monitoring of access to re sources within the CD?
The learning objective of this video is to discuss how to monitor your CD E to determine if a potential breach is occurring or has occurred.
Were karma tennis all about tracking access in your environment?
You need to be able to tell who is doing what in your environment to facilitate any forensic activity that may be needed to take place in the event of a breach,
you need to be able to see what individuals are doing, what to which systems and how to protect your audit trails so that an adversary is not able to cover their tracks after an attack.
This all begins with requirement 10 1
As a merchant, you need tohave in place, audit trails that are tied to each user.
If an account is accessing a system, it needs to be locked.
The 10 2 requirements note all of the activities that need to be on it.
It's not just the failures but also the successful access of information.
So open account access is cardholder data. You should be able to know about it.
Have access. Attempts fail. You should be able to know about it.
If new processes or system level objects are created,
you should be able to know about it.
The 10 3 Requirement Group tells you all of the information that needs to be tracked in your audit logs.
Most current operating systems are able to support collecting this information natively and shouldn't be difficult required A requirement to me.
You just need to remember to collect all of these items when it comes to applications you are developing in house as well.
Time is a key component of auditing.
If you need to develop a timeline of activities users are engaged in over long periods or across systems, it will be difficult to develop a narrative of what happened if time sources don't match or could be tampered with.
So it's important that critical systems have their time sync to buy an authoritative source
for an industry accepted time source. There's a lot of ambiguity there and industry, except that can change.
I typically suggest time sources published by NOUS. They're good, but there are a number of solutions out there that can satisfy this requirement.
This has just met so that you aren't using some random time source that can be entrusted.
10 5 requirements are used to make sure you put in place controls to protect your audit logs from tampering.
10 51 is in line with previous requirements.
If it's not a part of your job function, you should not have access to it.
10 53 is the best practice. All of your audit logs and need to be shipped from the local systems toe a centralized source.
This allows you to be able to do some correlation across systems and aid in the ability to detect malicious activity.
It also adds a layer of protection for your audit locks by separating, separating what's happening on the system from the system itself.
It should be placed in a location where only a handful of personal have access to them.
10 54 is the same concept. Just apply to externally facing systems.
10 55 is that you need to be alerted. If anyone is tampering with log data,
there shouldn't be any legitimate reasons for audit data to be changed, other than adding more data to it.
If this is occurring, it should be an immediate cause for alarm.
Requirement 10 6 is that you need to have in place a process to review logs and security events for all system components to identify anomalies or other suspicious activity.
So what's the point of collecting all these logs if you aren't going to regularly review them?
So here's the required for requirement for regularly reviewing your logs.
The requirement is for daily review
Right now. The practical way to meet this requirement is with the implementation of a seam type solution,
something that is able to collect all these logs and generates alerts.
It is impractical for most environments to try to do this in any way other than with automated tools.
You can have an environment that generates millions of logs, so it's best to try to automate this work and have someone review the alerts and potential suspicious activity.
So requirement 10 62 can be a confusing one.
What are all other system components?
PC I defines this as systems that are considered in scope
but which are not critical systems, and neither store process or transmit cardholder data nor provide security service is to the CD.
Some possible examples could be a stock control or inventory control systems. Maybe some prints servers, assuming there's no printing of cardholder data or certain types of work stations.
So you have to have a risk management strategy in place that addresses all these types of devices that states How often these logs should be reviewed.
10 63 is just stating that if you see an alarm or bad behavior that you follow up on it
and track the incident until its closure or completion.
If you have a ticketing system in place, it's best to leverage this to provide proof to the auditor of this activity.
Here's an easy one in concept,
you have to be able to maintain logs for three months for immediate recall and up to a year for logs that are maintained on backups.
So this means three months on disks essentially and the other nine months worth could be archived
if you have enough this space for a year, that's fine, too.
For service providers, The PC I counsel has implemented additional requirements around security controls
they explicitly defined which controls need to be notifying.
But the ambiguous nous of timely leads this up to interpretation.
Whatever your notification mechanism in timeline, just be able to explain it to your auditor. Why the time you have set is effective for your needs and it shouldn't be an issue for the audit.
10 81 s stating that service providers just need to be able to respond toe alerts that are generated in tinny.
This is another control that would benefit from school production.
Limit what you consider critical controls outside of what is explicitly stated if you can.
And here's the final requirement of the group
document document document.
All of your policies and procedures need to be put in writing and deliver to all those that are impact.
So in summary, we went over the requirements necessary for logging.
These logs are integral to your ability to detect, attack
and track down each of the things that happened during an attack.
All right, quick quiz
Audit trails need to be Altera ble by administrators when they're in cohesive.
Audit trails should never be altered