ℹ️
Reference Content: This is a copy of content from the PCI Security Standards Council FAQ database, preserved for tracking changes over time.
FAQ #1254 Deleted

What is the intent of PCI DSS requirement 10?

The intent of PCI DSS requirement 10 is to ensure organizations have the necessary logs in place to provide an accurate and unaltered record of what has taken place within the cardholder data environment (e.g. who did what, when, and how). When properly implemented, these logs have provided invaluable information during forensic reviews following a compromise. Without logging, there will be no way to determine what happened, what data was accessed and the length of time that the environment was compromised.

Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.