Procedure 11  TECHNICAL

Logging & Monitoring Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 11  ·  PCI DSS Req 10  ·  3 of 7 policy statements fully met  ·  AWS facts collected read-only 2026-08-13
← All 21 procedures 📘← Back to Policy 11 — Logging & Monitoring PolicyThe rule this procedure implements

How Revique implements this today

Production audit logging is provided by a CloudTrail trail named after the audit-log function (alias begins aud****), configured as a multi-region trail with log-file validation enabled and encrypted with a customer-managed KMS key. It has been logging continuously since 2021-06-24, with the most recent log delivery on the day of collection. Beyond management events it also captures S3 object-level data events across all buckets (read and write), which is what makes access to stored PHI visible in the trail. The dev account has its own multi-region trail with log-file validation, logging since 2026-07-15. CloudWatch Logs holds application logs: production us-e****-2 retains 50 log groups for 1827 days (5 years), and production us-e****-1 retains 6 groups for 180 days. System clocks are synchronised by the Amazon Time Sync Service, which is AWS-managed and applies to Fargate and EC2 alike.

The rule against the current state

Each row takes a statement from Policy 11 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.

The ruleCurrent stateVerdict
Audit logs capture access to systems and CHD/PHI with user, action, timestampCloudTrail captures every API call with identity and timestamp; S3 object-level data events extend this to stored objects in production.Meets
Audit logs protected from unauthorised modificationLog-file validation is enabled on both the production and dev trails; the production trail is additionally KMS-encrypted.Meets
Logs retained for at least [X] months, recent logs readily availableProduction us-e****-2: 5 years. Production us-e****-1: 180 days. CloudTrail's own S3 destination retention is governed by bucket lifecycle — see Procedure 17.Partial
Logging covers all environmentsThe UAT account has no CloudTrail trail at all.Gap
Security-relevant events trigger alerts for timely reviewNo security-event alarms exist. All 56 production alarms are operational.Gap
System clocks synchronised to a reliable sourceAmazon Time Sync Service, AWS-managed, used by ECS Fargate and EC2.Meets
Logs reviewed regularly for anomaliesGuardDuty performs continuous automated analysis in production. No evidenced human review cadence.Partial

🔍 Auditor verification — where to log in and what you will see

The production trail exists and is correctly configuredConsole → CloudTrail → production account → Trails → the aud**** trail. Confirm Multi-region trail: Yes, Log file validation: Enabled, SSE-KMS encryption: Enabled. Home region is us-e****-2, so the trail appears in both region views.
It is actually loggingSame trail → the status panel shows Logging: ON, last log file delivered within the hour, logging started 2021-06-24.
Object-level access is capturedSame trail → Data events → an S3 selector with read and write both included, applied to all buckets.
Log retentionConsole → CloudWatch → Log groups, production us-e****-2 → the Retention column shows 1827 days on 50 groups. In us-e****-1, 6 groups show 180 days.
UAT has no trailConsole → CloudTrail → UAT account (559****) → Trails — the list is empty in both regions.
Clock syncAWS-managed. Confirm via AWS Artifact / the Amazon Time Sync Service documentation; no per-instance NTP configuration is required.

Team process

DevOps owns trail and log-group configuration. The Security Officer is responsible for reviewing security-relevant events; today that review is driven by GuardDuty findings and operational alarms rather than by a scheduled log review.

⚠️ Where reality does not meet the policy

Evidence location. All evidence is in AWS (CloudTrail, CloudWatch Logs). Log review records, if any, would be held by the Security Officer.
📘Back to the PolicyPolicy 11 — Logging & Monitoring Policy (PCI DSS Req 10)←
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.