← PCI DSS 4.0.1 · Req 10 — Log and monitor

10.7 — Failures of critical security controls are detected and addressed

medium monitoringincident-response

Requirement

Failures of critical security control systems — such as network security controls, IDS/IPS, anti-malware, change-detection, audit logging and access controls — are detected, alerted and addressed promptly, including restoring the control, identifying the cause and documenting remediation.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
control failurecontrol failuresfailure offailures offailsstops workingstops logginghealth monitoring
Required element 2 — any one of
alertalertsalerteddetectedrestoredaddressedremediat…investigat…
Supporting terms — specificity signals
10.7.110.7.210.7.3heartbeat

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
NIST CSF 2.0 DE.AE-02 Potentially adverse events are analysed monitoring incident-response
NIST CSF 2.0 DE.AE-06 Information on adverse events is provided to authorised staff monitoring incident-response
GDPR Art.33 Notification of a breach to the supervisory authority incident-response
SOC 2 CC4.1 Ongoing and separate evaluations monitoring
SOC 2 CC7.3 Evaluation of security events incident-response
SOC 2 CC7.4 Incident response programme incident-response
SOC 2 CC7.5 Recovery from identified incidents incident-response
ISO 27001 A.5.7 Threat intelligence monitoring