Get Demo
↑

PCI DSS Requirement 10: Logging, Monitoring, Log Retention (10.5.1), and Automated Review (10.4.1.1)

PCI DSS v4.0.1 Requirement 10 - audit logs, daily review with automation (10.4.1.1), 12-month retention (10.5.1), time sync (10.

Published: September 2026 Compliance · PCI DSS 8-12 min read

PCI DSS Requirement 10 in v4.0.1 is titled Log and Monitor All Access to System Components and Cardholder Data. It covers capture (10.2), protect (10.3), review (10.4), retain (10.5), time synchronization (10.6), and detection of failures of critical security control systems (10.7).

Related: Requirement 8 · Requirement 11 · 12 requirements hub.

ID gotcha: Daily review of security / CHD / critical / security-function logs is 10.4.1 (with automated mechanisms under 10.4.1.1). 10.4.2.1 is the targeted risk analysis that sets how often you review other system components - it is not time synchronization. Time sync is 10.6. 10.7 is failure detection and response for critical security control systems - not daily log review.

Requirement Structure

Clause
Focus
10.1
Processes and roles for logging and monitoring
10.2
Audit logs implemented (what to capture + event fields)
10.3
Protect audit logs (access, integrity, central backup, FIM)
10.4
Review audit logs (daily set, automation, TRA frequency, exceptions)
10.5
Retain history (12 months / 3 months immediately available)
10.6
Time-synchronization mechanisms
10.7
Detect, alert, and respond to failures of critical security control systems

Deep Dives

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across the 12 requirements.

Frequently Asked Questions

Is daily log review Requirement 10.7?

No. Daily review of the 10.4.1 log set is Requirement 10.4.1, with automated mechanisms under 10.4.1.1. Requirement 10.7 covers detection and response when critical security control systems fail.

What does 10.5.1 require for retention?

Retain audit log history for at least 12 months, with at least the most recent three months immediately available for analysis.

What is 10.4.2.1?

10.4.2.1 is the targeted risk analysis (per 12.3.1) that defines how often you review logs for system components not covered by the daily 10.4.1 set. It is not the time-synchronization control - that is 10.6.

PCI DSS hub · 12 requirements explained · PCI DSS v4.0.1: What Changed · USA v4.0.1 services

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!