PCI DSS v4.0.1 — Requirement 10

Log and Monitor All Access to System Components and Cardholder Data
Environment: hptprod | us-east-2  |  Account: 501****  |  Generated: 2026-07-07 05:52 UTC
Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Audit logging (CloudTrail), security-event alerting, flow logs, retention and time-sync posture.
0
Critical
3
Gap
1
Needs Review
5
Compliant
0
AWS-Managed
0
N/A
CloudTrailCWL alarmsFlow logsRetention

10.2 — CloudTrail Audit Logging

CheckValueStatus
Logging activeYesCompliant
Multi-regionYesCompliant
Log file validationYesCompliant
KMS-encryptedYesCompliant
CloudWatch Logs integrationNOGap

10.4 — Security Event Alerting (CIS metric-filter alarms)

CloudTrail→CloudWatch Logs metric filters: 0. CloudTrail-metric alarms: 0. CloudTrail CloudWatch Logs integration: NOT enabled — without it, metric-filter alarms on API activity cannot fire.
Recommended security alarmStatus
Unauthorized API callsGap
Console sign-in without MFAGap
Root account usageGap
IAM policy changesGap
CloudTrail config changesGap
Console auth failuresGap
CMK disable/schedule deletionGap
S3 bucket policy changesGap
Config changesGap
Security group changesGap
NACL changesGap
Network gateway changesGap

10.2 — VPC Flow Logs

VPCFlow LogStatus
vpc-3****MISSINGGap
vpc-0****ActiveCompliant
Note: SSM Run Command inspection unavailable in this environment (aws-cli send-command incompatibility; prior attempt returned send-failed) — instance-level checks require manual review.

Control Mapping

ControlDescriptionStatusEvidence
10.2.1Audit trail enabled for all system componentsCompliantTrail 'auditlog-hipaa' logging=True
10.3.2Log file integrity protection (validation)CompliantLogFileValidation=True
10.5.1 (Coverage)Multi-region trail coverageCompliantMultiRegion=True
10.4.1Security events reviewed / alerted (12 alarm matrix)Gap0/12 CloudTrail security-event alarms configured
10.5.1 (Retention)Audit history retained ≥12 monthsGap50/74 groups ≥365d; 24 never-expire (unset)
10.2.1 (Network)Network flow logging enabled per VPCGap1/2 VPCs with active flow logs
10.2.1 (DB)Database audit logs exportedCompliant2/2 DBs export logs to CloudWatch
10.7.1 (Detection)Failures of critical security controls detectedCompliantGuardDuty ENABLED
10.6.1 (Time)Time synchronization on hosts (NTP/chrony)Needs ReviewSSM inspection unavailable — verify chronyd/NTP per instance manually

Recommendations

HighEnable CloudTrail → CloudWatch Logs integration and create the 12 CIS security metric-filter alarms (unauthorized API calls, root usage, IAM/policy changes, etc.) — currently 0/12 (PCI 10.4.1).
MediumEnable VPC Flow Logs for: vpc-3****.
MediumSet CloudWatch Logs retention to ≥365 days on audit-relevant log groups (many are unset/never-expire).
ProcessDefine and evidence daily log-review procedures (PCI 10.4.1) and 12-month retention with 3 months immediately available (10.5.1).