Skip to main content

πŸ’Ό 10.8 Implement a process for the timely detection and reporting of failures of critical security control systems.

Description​

Additional requirement for service providers only.

Including but not limited to failure of:

  • Firewalls.
  • IDS/IPS.
  • FIM.
  • Anti-virus.
  • Physical access controls.
  • Logical access controls.
  • Audit logging mechanisms.
  • Segmentation controls (if used).

Similar​

  • Sections
    • /frameworks/pci-dss-v4.0/10/07/01
  • Internal
    • ID: dec-c-b9f6ceef

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 10.7.1 Failures of critical security control systems are detected, alerted, and addressed promptly.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 10.7.1 Failures of critical security control systems are detected, alerted, and addressed promptly.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό 10.8.1 Respond to failures of any critical security controls in a timely manner.