PCI Requirement 10.5.2 – Protect Audit Trail Files from Unauthorized Modifications

by Randy Bartels / May 1st, 2018

Unauthorized vs. Authorized Modifications

PCI Requirement 10.5.2 requires organizations to protect audit trail files from unauthorized modifications. What would an unauthorized modification look like? Audit trails contain all the correct information about events and incidents in critical systems, so malicious individuals will often seek to modify audit trails to hide their actions. What would an authorized modification look like? If an approved individual in an organization finds unencrypted cardholder data or Social Security numbers in a log, they may want to modify the log to encrypt this sensitive data.

During an assessment for PCI Requirement 10.5.2, an assessor may look for a situation where an individual would need to modify an audit trail file, examine the access controls, and review the modification approval process. An assessor really wants to verify that those who shouldn’t or don’t have access to audit trail files actually don’t have access to them.

