File integrity and change detection
None of the held texts sets a fixed period on this consumer; every row below reads no period set by the text. Paste one job that feeds this consumer, for example fim_integrity_check, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.
Matched on the job name or the consumer column by these words: fim, file integrity, integrity check, change detection, integrity monitor, FIM report.
The clock each rule sets
| Regime | Clock | Clause |
|---|---|---|
| PCI DSS | no clock | PCI DSS 10.3.4 File integrity or change detection on logsalerts on change to log data |
| ISO 27001 | no clock | ISO 27001 8.16 Monitoring activities |
| no clock | ISO 27001 8.32 Change management |
Questions this page answers
How often does PCI DSS v4.0 require file integrity and change detection?
The held text of PCI DSS 10.3.4 (File integrity or change detection on logs) sets no fixed period: alerts on change to log data. File integrity monitoring or change-detection mechanisms are used on audit logs to ensure that existing log data cannot be changed without generating alerts.
How often does ISO/IEC 27001:2022 require file integrity and change detection?
The held text of ISO 27001 8.16 (Monitoring activities) sets no fixed period: no period set by the text. The held text of ISO 27001 8.32 (Change management) sets no fixed period: no period set by the text. Monitor networks, systems and applications for anomalies and act on potential incidents. Put changes to facilities and systems through change management procedures.
What does the register ask the owner of a file integrity and change detection job?
A log altered between runs raises no alert until the next run. Is that interval inside what the owner accepts?
The clauses in full
File integrity monitoring or change-detection mechanisms are used on audit logs to ensure that existing log data cannot be changed without generating alerts.
What an assessor asks to see: FIM tool configuration covering log paths; Sample FIM alerts on log modification tests; Coverage list across systems; Procedure for FIM alert triage. Where it usually falls short: FIM not deployed on logs
Monitor networks, systems and applications for anomalies and act on potential incidents.
Guidance beside it, ISO 27002 8.16: Requires networks, systems and applications to be monitored for anomalous behaviour, with appropriate action taken to evaluate whether what is observed constitutes an information security incident. Secondary commentary notes the deliberate shift to anomalous behaviour as the trigger, responding to cloud era risk.
What an assessor asks to see: network_anomaly_detection_logs; system_integrity_monitoring_reports; application_behavior_alerts; incident_response_records. Where it usually falls short: alerts not correlated across sources
Put changes to facilities and systems through change management procedures.
Guidance beside it, ISO 27002 8.32: Requires change management procedures to govern changes made to information systems and to the facilities that process information. Older source material adds that changes should be controlled by formal, documented and enforced procedures, with risk assessed as part of the process.
What an assessor asks to see: change_requests; change_approvals; implementation_testing; post_implementation_reviews. Where it usually falls short: missing formal approval
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register