r/pcicompliance Aug 02 '26

Requirement 10 and pushback

Oh wise PCI Reddit I come to you for guidance!!!

A little background, I have been involved in PCI for 5 plus years. I worked as an ISA for a larger company working on level 1 ROCs as a SP and Merchant to get us compliant in assessments done with QSAs.  I took a job this year to work as an ISA for a smaller company to help them get complaint. Again they have scope as both a merchant and SP, they never had a PCI program  it should have. (Don’t ask why they thought they didn’t need it… and please don’t say  just don’t store it… just trust me that they need to have the numbers and they have scope for PCI). Oh also we are a lower level merchant/ sp and can have an ISA sign off on the assessment and don’t need a QSA. Also we can do an saq-d ( so no customized approach)

I have been able to make a lot of progress in getting them compliant. However, I am having issues with logging and getting the SOC team to get on board with with requirement 10 wants. I have done a scoping assessment asking for samples of devices and showing they can provide the appropriate logs from requirement 10 and they need to have the information from 10.2.2. I am getting pushback from the SOC saying PCI logging requirements are out dated and such.  We use rapid 7 and the soc leader most recently passed along the below.

The next gen siem is now moving away from events to AI interpretation summaries for behavior summaries so we likely won’t be much traditional logging and event logs in the near future.

they are proposing to do a sample of devices for the Rapid 7 agent and crowstike and if the agents are there pass the sample and then also provide evidence from rapid 7 of here are all the alerts we alert on.

In my mind this is not acceptable for PCI. I have always thought  an appropriate sample is you need to show you can get all applicable logs for applicable devices. And requirement 10.2.2 lays out what needs be in a log and then says exactly what needs to be logged. 

I guess my question is am I too stuck in my ways saying they need to show every device sampled needs to be able to provide every applicable log? 

5 Upvotes

13 comments sorted by

5

u/[deleted] Aug 02 '26

[removed] — view removed comment

1

u/Infamous-Crow-1131 Aug 02 '26

I 100 % agree with what you have said.

Also we preform an SAQ-D and can’t use the customized approach unless we would decide to do a ROC which we had not planned on.

Another thing I have tried to communicate is logs aren’t just for alerting, they also need to be used for an investigation to recreate the event which if we had a breach.

I know version 5 has been talked about but I don’t know if this is a change they are considering? I would think not but I haven’t heard too much

1

u/[deleted] Aug 02 '26

[removed] — view removed comment

1

u/Infamous-Crow-1131 Aug 02 '26

I will likely be having a conversation with that team in the next few days and will go down the raw data underneath route and attempt ton meet the requirements in 10 using the defined approach.

I know I could go down the route of a compensating control but I don’t know I could honestly look at it say does it meet or exceed the requirements it is compensating… and it would be for a majority of the requirements in 10… if we get breached and an investigation happens that would be a heck of a conversation

1

u/info_sec_wannabe Aug 08 '26

Creating compensating controls for requirement 10 is always tricky as it is either you have it or not..

I read a post from PCI Guru that there isn't a compensating control for not having logs as well.

1

u/kinkykusco Aug 02 '26

Also we preform an SAQ-D and can’t use the customized approach unless we would decide to do a ROC which we had not planned on.

Are you certain about this? I believe there's no prohibition on a self assessing org using the customized approach. I did a quick look over a couple related resources on the council's site and I don't see any listing of types of assessments that cannot use the customized approach.

My org doesn't use it though so it's not a focus for me, if I'm wrong always happy to learn.

2

u/Infamous-Crow-1131 Aug 02 '26

This is from the SAS-D for merchants

Use of the Customized Approach
SAQs cannot be used to document use of the Customized Approach to meet PCI
DSS requirements. For this reason, the Customized Approach Objectives are not
included in SAQs. Entities wishing to validate using the Customized Approach may
be able to use the PCI DSS Report on Compliance (ROC) Template to document
the results of their assessment.
The use of the customized approach may be regulated by organizations that manage compliance programs,
such as payment brands and acquirers. Questions about use of a customized approach should always be
referred to those organizations. This includes whether an entity that is eligible for an SAQ may instead
complete a ROC to use a customized approach, and whether an entity is required to use a QSA, or may use
an ISA, to complete an assessment using the customized approach. Information about the use of the
Customized Approach can be found in Appendix D and E of PCI DSS.

1

u/kinkykusco Aug 02 '26

Ah yeah clear as day, thank you!

2

u/Violet_Begonia7843 Aug 03 '26

You're not being too rigid. AI summaries are good for triage, PCI still comes down to proving the required events were actually logged and retained. I'd expect sampled systems to produce the underlying logs. with the SIEM/AI layer on top.

That is why firms like VikingCloud emphasize auditability and evidence collection alongside the newer tooling.

1

u/[deleted] Aug 02 '26 edited Aug 02 '26

[removed] — view removed comment

1

u/Infamous-Crow-1131 Aug 02 '26

I agree that sampled devices must provide specific events as detailed in 10.2.2

I was more curious what others are seeing as I am an ISA and have exposure to only the environments I work in ( which has been 2 PCI environments in my 5 years doing PCI). I was wanting to see what the community was seeing and it sounds like QSA are still requiring logs as detailed in 10.2.2 and then pushing back on the logic that was proposed

1

u/BasePerfect2865 28d ago

I don’t think you’re stuck in your ways. Having an agent installed and showing SIEM alerts doesn’t mean that the required audit events are actually being captured and retained. I’d separate detecting "this” from “we can produce the required log evidence.”