
Week 14
Identify Logging & Monitoring Gaps for a Client
Client Background
Summit Retail Co. operates an e-commerce platform and 8 physical stores, processing customer payment card data across both channels. The company has a small IT team and no dedicated security monitoring function.
Business Environment
Summit's PCI DSS qualified security assessor flagged 'insufficient logging and monitoring' as a finding during last quarter's compliance assessment, and the company has 90 days to demonstrate improvement before the next review.
Security Incident
No breach; the engagement is a proactive gap analysis. The driver is Summit Retail's PCI DSS QSA flagging 'insufficient logging and monitoring' last quarter, with 90 days to demonstrate improvement before the next compliance review.
Scope
This engagement covers a documentation review of Summit's current logging configuration, log retention settings, and monitoring processes across POS, e-commerce, and network systems. It excludes deploying new logging tools.
Objectives
- Inventory which systems currently generate security-relevant logs
- Assess whether logs are centrally collected, retained, and reviewed
- Identify critical systems with no logging or monitoring coverage
- Evaluate whether current logging would support incident investigation
- Produce a gap analysis with prioritized logging and monitoring recommendations
- Update the gap analysis for PCI DSS 4.0 logging/tamper-evidence (req. 10) and design XDR/SOAR automation and e-commerce cloud telemetry coverage, not just on-prem POS log retention.
Required Deliverables