Policy 11  

Logging & Monitoring Policy
PCI DSS Req 10  ·  the rule Revique must follow
← All 21 policies
This page is the rule, not the implementation. It states what Revique must do, at or above the PCI DSS minimum. How Revique actually does it today — the real AWS configuration, the current values, and where an auditor logs in to verify them — is in Procedure 11. Values shown as [X] are placeholders still to be set.

Purpose

To ensure all access to systems and CHD/PHI is logged, protected from tampering, monitored, and retained for the required period.

Scope

Applies to all Revique systems, applications, and data stores.

Policy statements

Each statement below is mandatory. The bolded must marks the obligation.

1Audit logs must capture access to systems and CHD/PHI, including user, action, and timestamp.
2Audit logs must be protected from unauthorized modification (e.g. log-file validation).
3Logs must be retained for at least [X] months, with recent logs readily available.
4Security-relevant events must trigger alerts for timely review.
5System clocks must be synchronized to a reliable time source.
6Logs must be reviewed regularly for anomalies.

Roles & responsibilities

RoleResponsibility
Security OfficerDefine logging standards and review alerts.
DevOps / ITImplement logging, retention, and time synchronization.

Enforcement

This policy is issued under the authority of Policy 01 — Information Security Policy and is mandatory for everyone in scope. Compliance is verified through the controls and evidence described in the linked procedure. Failure to comply may result in withdrawal of access and disciplinary action. This policy is reviewed at least annually, or sooner on significant change.

⚙️See the Procedure for this policyHow Revique implements this rule today, the current values, the gaps, and the auditor verification path→
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.