Under active development Content is continuously updated and improved

SM-24Security Monitoring Alert Criteria: Cardholder System Components

>Control Description

Organization defines security monitoring alert criteria for system components that store, process, transmit, or could impact the security of cardholder data and/or sensitive authentication data.

Theme

Process

Type

Detective

Policy/Standard

Logging & Monitoring Standard

>Implementation Guidance

1. Ensure that Organization's Security Monitoring Standard includes requirements for security monitoring alert criteria for system components that store, process, transmit, or could impact the security of cardholder data and/or sensitive authentication data. 2. Ensure that the security monitoring rules are defined, enabled, and alert applicable personnel on checks for any impact to the CDE. 3. Ensure that alerts are being generated and sent to the SOC team to support remediation.

>Testing Procedure

1. Inspect whether the security logs from various sources are sent to the monitoring tool. 2. Inspect a sample of security monitoring rules, to validate that the rules are defined to look for and alert applicable personnel on checks for any impact to the CDE. 3. Validate that alerts being generated are sent to the SOC team to support remediation.

>Audit Artifacts

E-SM-18
E-SM-19

>Framework Mappings

Cross-framework mappings provided by Adobe CCF Open Source under Creative Commons License.

Ask AI

Configure your API key to use AI features.