May I know what is User Activity as per PCI requirement 10 ?
On going SSAE 18 audit, there is one question - please provide the Daily Group and User activity report evidence of their review and evidence of investigation and follow-up (if applicable).
Please share me if anyone have an idea regarding this!
Thanks in advance.
PCI Requirement 10: Track and monitor all access to network resources and cardholder data
Logging mechanisms and the ability to track user activities are critical in preventing, detecting and minimizing the impact of a data compromise. The presence of logs in all environments allows thorough tracking, alerting and analysis when something does go wrong. Determining the cause of a compromise is very difficult, if not impossible, without system activity logs.