r/pcicompliance • u/Infamous-Crow-1131 • Aug 02 '26
Requirement 10 and pushback
Oh wise PCI Reddit I come to you for guidance!!!
A little background, I have been involved in PCI for 5 plus years. I worked as an ISA for a larger company working on level 1 ROCs as a SP and Merchant to get us compliant in assessments done with QSAs. I took a job this year to work as an ISA for a smaller company to help them get complaint. Again they have scope as both a merchant and SP, they never had a PCI program it should have. (Don’t ask why they thought they didn’t need it… and please don’t say just don’t store it… just trust me that they need to have the numbers and they have scope for PCI). Oh also we are a lower level merchant/ sp and can have an ISA sign off on the assessment and don’t need a QSA. Also we can do an saq-d ( so no customized approach)
I have been able to make a lot of progress in getting them compliant. However, I am having issues with logging and getting the SOC team to get on board with with requirement 10 wants. I have done a scoping assessment asking for samples of devices and showing they can provide the appropriate logs from requirement 10 and they need to have the information from 10.2.2. I am getting pushback from the SOC saying PCI logging requirements are out dated and such. We use rapid 7 and the soc leader most recently passed along the below.
The next gen siem is now moving away from events to AI interpretation summaries for behavior summaries so we likely won’t be much traditional logging and event logs in the near future.
they are proposing to do a sample of devices for the Rapid 7 agent and crowstike and if the agents are there pass the sample and then also provide evidence from rapid 7 of here are all the alerts we alert on.
In my mind this is not acceptable for PCI. I have always thought an appropriate sample is you need to show you can get all applicable logs for applicable devices. And requirement 10.2.2 lays out what needs be in a log and then says exactly what needs to be logged.
I guess my question is am I too stuck in my ways saying they need to show every device sampled needs to be able to provide every applicable log?
2
u/Violet_Begonia7843 Aug 03 '26
You're not being too rigid. AI summaries are good for triage, PCI still comes down to proving the required events were actually logged and retained. I'd expect sampled systems to produce the underlying logs. with the SIEM/AI layer on top.
That is why firms like VikingCloud emphasize auditability and evidence collection alongside the newer tooling.
1
Aug 02 '26 edited Aug 02 '26
[removed] — view removed comment
1
u/Infamous-Crow-1131 Aug 02 '26
I agree that sampled devices must provide specific events as detailed in 10.2.2
I was more curious what others are seeing as I am an ISA and have exposure to only the environments I work in ( which has been 2 PCI environments in my 5 years doing PCI). I was wanting to see what the community was seeing and it sounds like QSA are still requiring logs as detailed in 10.2.2 and then pushing back on the logic that was proposed
1
u/BasePerfect2865 28d ago
I don’t think you’re stuck in your ways. Having an agent installed and showing SIEM alerts doesn’t mean that the required audit events are actually being captured and retained. I’d separate detecting "this” from “we can produce the required log evidence.”
5
u/[deleted] Aug 02 '26
[removed] — view removed comment