Skip to main content

πŸ’Ό 10.7.1 Failures of critical security control systems are detected, alerted, and addressed promptly.

Description​

Additional requirement for service providers only

Includes the following critical security control systems:

  • Network security controls.
  • IDS/IPS.
  • FIM.
  • Anti-malware solutions.
  • Physical access controls.
  • Logical access controls.
  • Audit logging mechanisms.
  • Segmentation controls (if used).

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/10/08
    • /frameworks/pci-dss-v4.0.1/10/07/01

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 10.8 Implement a process for the timely detection and reporting of failures of critical security control systems.1
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 10.7.1 Failures of critical security control systems are detected, alerted, and addressed promptly.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 10.8 Implement a process for the timely detection and reporting of failures of critical security control systems.1
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 10.7.1 Failures of critical security control systems are detected, alerted, and addressed promptly.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags