Organization should implement change detection mechanisms
Medium
Cross-cloud
General
manual-pci-change-detection
How to fix it
Deploy a change detection mechanism (e.g., file integrity monitoring) to alert personnel to unauthorized modification of critical system files, configuration files, and content files. Perform comparisons at least weekly.
How to verify
- Verify FIM tool deployment on critical systems
- Confirm weekly comparison schedule
- Verify alert review process
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related Cross-cloud rules
- Block storage volumes must be encrypted
- Cache service security hardening
- Cache services must enforce TLS encryption in transit
- Container registry security hardening
- Database authentication must use managed identities
- Databases must not be publicly accessible
- IAM password policy must require minimum length of 14
- Key management service security hardening