ℹ️
Reference Content: This is a copy of content from the PCI Security Standards Council FAQ database, preserved for tracking changes over time.
View Original →
FAQ #1081 Published

Does the logging required at PCI DSS Requirements 10.2 and 10.3 mean we have to enable database logging as well?

The intent of the logging requirement is to provide a full record of who did what, when, and how, so that it can be used for investigation in the event of unexpected or unauthorized activities. In addition to operating system logging, either database logging or application logging (or a combination of both) should be implemented to show access to cardholder data. Requirement 10.2.1 specifically says to log ?all individual access to cardholder data.? If your applications log all individuals? access to the database, full database logging in addition to application logging may not be necessary. We suggest you contact a Qualified Security Assessor (QSA) for help with logging as they will be able to make recommendations based on an understanding of your actual environment. Our list of QSAs can be found at: https://www.pcisecuritystandards.org/pdfs/pci_qsa_list.pdf

Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.