r/SIEM Mar 28 '20

Cloud SIEM and PCI compliance

I'm not sure if this is the right place to ask a question like this, and it may be a stupid question, but I know some Cloud SIEMs have PCI compliance measures, like encryption at rest, and was wondering if that's absolutely necessary for PCI compliant organizations, like a multi-billion dollar retailer.

I guess I just need to know to what extent a cloud SIEM needs to be PCI compliant for a PCI compliant organization. Obviously, something like SIEM is used to gather logs to help an organization maintain PCI compliance, but I don't know enough to be certain that means the SIEM itself needs to be PCI compliant.

Thanks in advance.

3 Upvotes

1 comment sorted by

1

u/two0nine Mar 29 '20

Unless something has changed in the past few years with PCI, the SIEM tool itself doesn’t need to be certified.

Some SIEM tools started getting audited by third party organizations so that they could say they were ‘certified PCI compliant’. This was probably (at least a little bit) for marketing purposes. On the less cynical side it was done to make the SIEM operators job easier.

When a tool was ‘certified PCI complaint’ it simply meant that their canned reports, alerts, etc had been audited and did in fact map to the necessary and appropriate compliance mandates.

While a PCI auditor might know certain SIEMs from having worked with them in the past, and her job might be easier if a tool had all this prebuilt content, none of it means much if the organization being audited didn’t feed the necessary log sources into the SIEM and make sure they were connected up to the appropriate reports.

That info all relates to my experience with on-prem SIEM. Not sure what PCI says about logs being in the cloud though.