Skip to main content

Overview

PCI-DSS (Payment Card Industry Data Security Standard) v4.0 applies to all entities that store, process, or transmit cardholder data. Requirement 10 mandates comprehensive audit logging of all access to system components and cardholder data - and critically, that those logs be protected from modification. The challenge is structural: the systems that administrators use to manage infrastructure are the same systems that house the audit logs. A malicious insider, or an attacker with elevated access, can modify logs to conceal their activity - leaving no evidence of the compromise. ROOTKey anchors log entries to the blockchain at emission, before they reach any mutable storage. This creates a tamper-evident record that is verifiable independently of the cardholder data environment.

Requirement 10 - Log and Monitor All Access

Requirement 10.2 - Audit Log Capture

Requirement 10.3 - Protect Audit Logs from Destruction and Modifications

This is where ROOTKey provides direct, structural compliance:
PCI-DSS Requirement 10.3.2 specifically calls for “change-detection technology” for audit log files. Blockchain anchoring is the strongest available implementation of change-detection: any modification produces a hash mismatch that is verifiable by any party with the transaction ID, including the QSA.

Requirement 10.5 - Retain Audit Logs


QSA Verification

PCI-DSS assessments are conducted by Qualified Security Assessors (QSAs) who must verify that controls are operating effectively. ROOTKey anchors provide QSA-verifiable evidence:

Architecture for CDE Log Protection

Log management systems remain in place for operational use. ROOTKey adds the tamper-evidence layer required by PCI-DSS 10.3.2 without replacing existing logging infrastructure.

Request a PCI-DSS architecture review

We’ll design a ROOTKey log anchoring implementation that satisfies Requirement 10 and produces QSA-verifiable evidence.

Regulatory audit trails use case

Full implementation guide for tamper-evident audit logging.