Procedure 11 TECHNICAL
Logging & Monitoring Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 11 · PCI DSS Req 10 · 3 of 7 policy statements fully met · AWS facts collected read-only 2026-08-13
← All 21 procedures
📘← Back to Policy 11 — Logging & Monitoring PolicyThe rule this procedure implements
How Revique implements this today
Production audit logging is provided by a CloudTrail trail named after the audit-log function (alias begins aud****), configured as a multi-region trail with log-file validation enabled and encrypted with a customer-managed KMS key. It has been logging continuously since 2021-06-24, with the most recent log delivery on the day of collection. Beyond management events it also captures S3 object-level data events across all buckets (read and write), which is what makes access to stored PHI visible in the trail. The dev account has its own multi-region trail with log-file validation, logging since 2026-07-15. CloudWatch Logs holds application logs: production us-e****-2 retains 50 log groups for 1827 days (5 years), and production us-e****-1 retains 6 groups for 180 days. System clocks are synchronised by the Amazon Time Sync Service, which is AWS-managed and applies to Fargate and EC2 alike.
The rule against the current state
Each row takes a statement from Policy 11 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.
| The rule | Current state | Verdict |
|---|
| Audit logs capture access to systems and CHD/PHI with user, action, timestamp | CloudTrail captures every API call with identity and timestamp; S3 object-level data events extend this to stored objects in production. | Meets |
| Audit logs protected from unauthorised modification | Log-file validation is enabled on both the production and dev trails; the production trail is additionally KMS-encrypted. | Meets |
| Logs retained for at least [X] months, recent logs readily available | Production us-e****-2: 5 years. Production us-e****-1: 180 days. CloudTrail's own S3 destination retention is governed by bucket lifecycle — see Procedure 17. | Partial |
| Logging covers all environments | The UAT account has no CloudTrail trail at all. | Gap |
| Security-relevant events trigger alerts for timely review | No security-event alarms exist. All 56 production alarms are operational. | Gap |
| System clocks synchronised to a reliable source | Amazon Time Sync Service, AWS-managed, used by ECS Fargate and EC2. | Meets |
| Logs reviewed regularly for anomalies | GuardDuty performs continuous automated analysis in production. No evidenced human review cadence. | Partial |
🔍 Auditor verification — where to log in and what you will see
The production trail exists and is correctly configuredConsole → CloudTrail → production account → Trails → the aud**** trail. Confirm Multi-region trail: Yes, Log file validation: Enabled, SSE-KMS encryption: Enabled. Home region is us-e****-2, so the trail appears in both region views.
It is actually loggingSame trail → the status panel shows Logging: ON, last log file delivered within the hour, logging started 2021-06-24.
Object-level access is capturedSame trail → Data events → an S3 selector with read and write both included, applied to all buckets.
Log retentionConsole → CloudWatch → Log groups, production us-e****-2 → the Retention column shows 1827 days on 50 groups. In us-e****-1, 6 groups show 180 days.
UAT has no trailConsole → CloudTrail → UAT account (559****) → Trails — the list is empty in both regions.
Clock syncAWS-managed. Confirm via AWS Artifact / the Amazon Time Sync Service documentation; no per-instance NTP configuration is required.
Team process
DevOps owns trail and log-group configuration. The Security Officer is responsible for reviewing security-relevant events; today that review is driven by GuardDuty findings and operational alarms rather than by a scheduled log review.
⚠️ Where reality does not meet the policy
- The UAT account has no CloudTrail trail. UAT holds CHD/PHI, so API activity against in-scope data there is not logged at all — there is no audit record to review, and no forensic record if an incident occurred.
- No security-event alerting. The policy requires security-relevant events to trigger alerts. There is no alarm on root account usage, IAM policy change, failed authentication or unauthorised API calls anywhere in the estate.
- Retention is inconsistent and partly unbounded. 25 production log groups in us-e****-2, 1 in us-e****-1, 58 in UAT and 92 in dev have no retention set (never expire) — the opposite problem to under-retention, but still an undefined retention period, which Policy 17 prohibits. Meanwhile production us-e****-1 retains only 180 days, below a 12-month audit-history expectation.
- No evidenced periodic log review. Automated analysis exists in production; a documented human review cadence does not.
- The trail's own encryption key does not rotate (see Procedure 09).
Evidence location. All evidence is in AWS (CloudTrail, CloudWatch Logs). Log review records, if any, would be held by the Security Officer.
📘Back to the PolicyPolicy 11 — Logging & Monitoring Policy (PCI DSS Req 10)←