Diff: FAQ #1304
What devices does PCI DSS Requirement 10.6.2 apply to?
Earlier Version
2015-05-28 00:00:00 UTC
2015-05-28 00:00:00 UTC
Later Version
2018-08-14 17:43:00 UTC
2018-08-14 17:43:00 UTC
Removed
Added
For some environments, it is possible that all in-scope systems fall under the system categories defined in Requirement 10.6.1, meaning that daily log reviews are required for all in-scope systems. In other environments, there may be many different types of system that are considered in scope, but which are not critical systems and neither store, process or transmit CHD nor provide security services to the CDE. Some possible examples could be stock-control or inventory-control systems, print servers (assuming there is no printing of CHD) or certain types of workstations. For these events or systems, the entity, as part of its annual risk assessment process, is expected to define the frequency for log reviews based on the risk to its specific environment.