Join our Newsletter — 33% off our NHI Course

PCI DSS 4.0 evidence gaps for infrastructure access and account reviews

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20631
Topic starter  

TL;DR: PCI DSS 4.0 shifts assessments from informal security practice to documented evidence, with Teleport arguing that assessors now expect clear ties between access, ownership, remediation, and closure across requirements 7, 8, and 10. For practitioners, the real challenge is proving that least privilege, account lifecycle control, and log review are operational, not just written down.

NHIMG editorial — based on content published by Teleport: What PCI DSS 4.0 Requires for Infrastructure Identity and Access Evidence

By the numbers:

Questions worth separating out

Q: What breaks when PCI DSS 4.0 access evidence is incomplete?

A: The control itself may still exist, but the assessor cannot verify ownership, review, or remediation.

Q: Why do service accounts create PCI DSS 4.0 evidence gaps?

A: Service accounts often sit outside the review cadence used for human users, so their privileges persist without a clear lifecycle record.

Q: How do organisations know whether access reviews are working?

A: Access reviews are working when they lead to timely removals, reduced exception volume, and role definitions that stop accumulating unused rights.

Practitioner guidance

  • Document access as an evidence chain Capture the full path from grant to review to remediation for in-scope infrastructure access, including approvals, tickets, and closure records that an assessor can sample.
  • Separate service account ownership from human review cadence Assign named ownership to every service and system account, then retain justification and lifecycle records that show why each permission still exists.
  • Tie log review to documented follow-up Pair automated review of privilege elevation, administrative action, and denied access events with incident tickets or remediation records that prove action followed detection.

What's in the full article

Teleport's full article covers the operational detail this post intentionally leaves for the source:

  • The specific artifact sets assessors expect for Requirements 7, 8, and 10 across cloud, Kubernetes, and database environments.
  • Examples of access-review records, remediation tickets, and audit logs that can support a PCI DSS evidence trail.
  • The checklist for tracing one access exception from detection through closure in a production environment.
  • Practical examples of service account, SSH, and RBAC evidence that can withstand audit sampling.

👉 Read Teleport's analysis of PCI DSS 4.0 infrastructure identity evidence →

PCI DSS 4.0 evidence gaps for infrastructure access and account reviews?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20222
 

PCI DSS 4.0 is forcing identity teams to become evidence teams. The standard no longer rewards organisations for having access controls in place if they cannot prove who reviewed them, why they remained, and what changed after exceptions were found. That shifts identity governance from configuration management to defensible accountability, especially in infrastructure environments where access is distributed across cloud, cluster, and database layers. Practitioners need to treat the evidence chain as part of the control, not a report generated after the fact.

A few things that frame the scale:

  • 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time, according to Ultimate Guide to NHIs.
  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, which mirrors the lifecycle evidence gaps PCI assessors often surface.

A question worth separating out:

Q: What is the difference between logging access and proving accountability?

A: Logging shows that an event happened. Accountability requires a linked record showing who reviewed the event, what decision was made, and what action followed. PCI DSS 4.0 cares about both, because telemetry without follow-through does not demonstrate control.

👉 Read our full editorial: PCI DSS 4.0 raises the bar for infrastructure identity evidence



   
ReplyQuote
Share: