Skip to main content

💼 10.7.1 Failures of critical security control systems are detected, alerted, and addressed promptly.

Description​

Additional requirement for service providers only

Includes the following critical security control systems:

  • Network security controls.
  • IDS/IPS.
  • FIM.
  • Anti-malware solutions.
  • Physical access controls.
  • Logical access controls.
  • Audit logging mechanisms.
  • Segmentation controls (if used).

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/10/08
    • /frameworks/pci-dss-v4.0.1/10/07/01
  • Internal
    • ID: dec-c-8fcadaa8

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v3.2.1 → 💼 10.8 Implement a process for the timely detection and reporting of failures of critical security control systems.1
💼 PCI DSS v4.0.1 → 💼 10.7.1 Failures of critical security control systems are detected, alerted, and addressed promptly.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v3.2.1 → 💼 10.8 Implement a process for the timely detection and reporting of failures of critical security control systems.1
💼 PCI DSS v4.0.1 → 💼 10.7.1 Failures of critical security control systems are detected, alerted, and addressed promptly.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags