Batch Register

Other system log review

None of the held texts sets a fixed period on this consumer; every row below reads no period set by the text. Paste one job that feeds this consumer, for example app_server_log_review, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.

Matched on the job name or the consumer column by these words: other log, system log review, non cde log, server log review, app log review, application log review, non-CDE log review.

The clock each rule sets

RegimeClockClause
PCI DSSno clockPCI DSS 10.4.2 Periodic review of other system component logsperiodically
no clockPCI DSS 10.4.2.1 Frequency defined by TRAthe frequency the targeted risk analysis defines
ISO 27001no clockISO 27001 8.15 Logging
SP 800-53no clockSP 800-53 AU-6 Audit record review, analysis, and reportinga defined frequency

Questions this page answers

How often does PCI DSS v4.0 require other system log review?

The held text of PCI DSS 10.4.2 (Periodic review of other system component logs) sets no fixed period: periodically. The held text of PCI DSS 10.4.2.1 (Frequency defined by TRA) sets no fixed period: the frequency the targeted risk analysis defines. Logs of all other system components (those not specified in 10.4.1) are reviewed periodically. The frequency of periodic reviews for all other system components is defined in the entity's targeted risk analysis.

How often does ISO/IEC 27001:2022 require other system log review?

The held text of ISO 27001 8.15 (Logging) sets no fixed period: no period set by the text. Produce, store, protect and analyse logs of activities, exceptions and faults.

How often does NIST SP 800-53 Rev 5 require other system log review?

The held text of SP 800-53 AU-6 (Audit record review, analysis, and reporting) sets no fixed period: a defined frequency. Requires audit records to be reviewed and analysed on a defined frequency for indications of organization-defined inappropriate or unusual activity and its likely impact, findings to be reported to defined personnel, and the depth of review to be increased when credible information changes the risk.

What does the register ask the owner of a other system log review job?

The card rule leaves this period to your targeted risk analysis. Does the analysis name the period this job runs on?

The clauses in full

PCI DSS 10.4.2 Periodic review of other system component logsthe standard's page

Logs of all other system components (those not specified in 10.4.1) are reviewed periodically.

What an assessor asks to see: Review schedule for non-critical systems; Sample of completed reviews; Sign-off records by reviewer; Inventory of systems in scope. Where it usually falls short: Reviews not performed

PCI DSS 10.4.2.1 Frequency defined by TRAthe standard's page

The frequency of periodic reviews for all other system components is defined in the entity's targeted risk analysis.

What an assessor asks to see: TRA document with risk inputs and chosen cadence; Annual TRA review records; Approval by senior leadership; Mapping of cadence to system criticality. Where it usually falls short: No TRA

ISO 27001 8.15 Loggingthe standard's page

Produce, store, protect and analyse logs of activities, exceptions and faults.

Guidance beside it, ISO 27002 8.15: Requires logs to be produced, stored, protected and analysed, covering activities, exceptions, faults and any other event of relevance. Older source material adds that records of user activity, exceptions and security events should be retained for an agreed period to support later investigation and access control monitoring, and that faults should be logged, analysed and acted on.

What an assessor asks to see: log_collection_policy; log_storage_and_protection; log_review_and_analysis; log_retention_and_disposal. Where it usually falls short: Inconsistent log collection across systems

SP 800-53 AU-6 Audit record review, analysis, and reportingthe standard's page

Requires audit records to be reviewed and analysed on a defined frequency for indications of organization-defined inappropriate or unusual activity and its likely impact, findings to be reported to defined personnel, and the depth of review to be increased when credible information changes the risk.

What an assessor asks to see: Defined review frequency and the activity indicators being looked for; Completed review records with reviewer, date and findings; Reports issued to the defined recipients and evidence of follow-up; Record of a review level adjustment made in response to changed risk. Where it usually falls short: Review is automated alerting only, with no periodic analytical review for slow patterns

Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register