Back to category

Week 14

Identify Logging & Monitoring Gaps for a Client

Intermediate
GRC Analyst
CIS Controls
PCI DSS 4.0
NIST CSF 2.0
MITRE ATT&CK Detection
Logging Assessment
Monitoring Gap Analysis
Detection Capability Review
Control Prioritization
PCI DSS 4.0
XDR/SOAR
Cloud Telemetry

Client Background

Summit Retail Co. operates an e-commerce platform and 8 physical stores, processing customer payment card data across both channels. The company has a small IT team and no dedicated security monitoring function.

Business Environment

Summit's PCI DSS qualified security assessor flagged 'insufficient logging and monitoring' as a finding during last quarter's compliance assessment, and the company has 90 days to demonstrate improvement before the next review.

Security Incident

No breach; the engagement is a proactive gap analysis. The driver is Summit Retail's PCI DSS QSA flagging 'insufficient logging and monitoring' last quarter, with 90 days to demonstrate improvement before the next compliance review.

Scope

This engagement covers a documentation review of Summit's current logging configuration, log retention settings, and monitoring processes across POS, e-commerce, and network systems. It excludes deploying new logging tools.

Objectives

  • Inventory which systems currently generate security-relevant logs
  • Assess whether logs are centrally collected, retained, and reviewed
  • Identify critical systems with no logging or monitoring coverage
  • Evaluate whether current logging would support incident investigation
  • Produce a gap analysis with prioritized logging and monitoring recommendations
  • Update the gap analysis for PCI DSS 4.0 logging/tamper-evidence (req. 10) and design XDR/SOAR automation and e-commerce cloud telemetry coverage, not just on-prem POS log retention.

Required Deliverables

Logging & Monitoring Gap Report
Prioritized Recommendations
3 hrs estimated