MUST-DO Logging for PCI?
...critters :-) will tell you whether "yours is OK" or "OMG, no!", but will not write your logging policy for you. With them, the best approach is: define your logging policy, then show to auditor, if they are happy - now you know what you MUST do
As a final word: still, I dislike the above compliance-induced daze as much as the next guy. I much...





