
PCI Requirement 10.2.2 – All Actions Taken by Any Individual with Root or Administrative Privileges
Root or Administrative Privileges Accounts that have root or administrative privileges have a greater chance of impacting the security and functionality of a system. This is why PCI Requirement 10.2.2 requires that organizations implement automated audit trails to reconstruct all actions taken by an individual with root or administrative privileges. Without logging mechanisms enabled, how could you trace issues resulting from misuse or root or administrative privileges? To verify…




