|
1 | 1 | ---
|
2 | 2 | title: PCI DSS Compliance
|
3 |
| -disable_toc: false |
4 | 3 | further_reading:
|
5 |
| -- link: "https://www.datadoghq.com/blog/datadog-pci-compliance-log-management-apm/" |
6 |
| - tag: "Blog" |
7 |
| - text: "Announcing PCI-Compliant Log Management and APM from Datadog" |
8 |
| -- link: "coterm" |
9 |
| - tag: "Documentation" |
10 |
| - text: "CoTerm: Monitor terminal sessions and sensitive activities on local and remote systems" |
| 4 | +- link: "https://trust.datadoghq.com/" |
| 5 | + tag: "Datadog Trust Center" |
| 6 | + text: "Learn about Datadog's security posture and review security documentation" |
11 | 7 | ---
|
12 | 8 |
|
13 |
| -{{% site-region region="us3,us5,eu,ap1,gov,ap2" %}} |
14 |
| -<div class="alert alert-warning"> |
15 |
| -PCI DSS compliance for APM and Log Management is only available for Datadog organizations in the <a href="/getting_started/site/">US1 site</a>. |
16 |
| -</div> |
17 |
| -{{% /site-region %}} |
18 |
| - |
19 |
| -{{% site-region region="us" %}} |
20 |
| -<div class="alert alert-warning"> |
21 |
| -PCI DSS compliance for APM and Log Management is only available for Datadog organizations in the <a href="/getting_started/site/">US1 site</a>. |
22 |
| -</div> |
23 |
| - |
24 | 9 | ## Overview
|
25 | 10 |
|
26 |
| -The Payment Card Industry (PCI) Data Security Standard (DSS) has rigorous monitoring and data security requirements for all merchants, service providers, and financial institutions. To meet these requirements, organizations have had to separate out PCI-regulated data and non-regulated data to different applications for monitoring. |
27 |
| - |
28 |
| -Datadog offers PCI-compliant Log Management and Application Performance Monitoring (APM) within the [US1 site][1] so that you can collect all of your logs, whether they are PCI-regulated or not, in one place. See [Set up a PCI-compliant Datadog organization](#set-up-a-pci-compliant-datadog-organization) on how to get started. |
29 |
| - |
30 |
| -## Set up a PCI-compliant Datadog organization |
31 |
| - |
32 |
| -{{< tabs >}} |
33 |
| - |
34 |
| -{{% tab "Log Management" %}} |
35 |
| - |
36 |
| -{{% pci-logs %}} |
37 |
| - |
38 |
| -{{% /tab %}} |
39 |
| - |
40 |
| -{{% tab "APM" %}} |
41 |
| - |
42 |
| -{{% pci-apm %}} |
43 |
| - |
44 |
| -{{% /tab %}} |
45 |
| - |
46 |
| -{{< /tabs >}} |
47 |
| - |
48 |
| -[1]: /getting_started/site/ |
49 |
| - |
50 |
| -{{% /site-region %}} |
51 |
| - |
52 |
| -## View your PCI Compliance status |
53 |
| - |
54 |
| -See the [Configuration Page][2] inside Safety Center. |
| 11 | +The Payment Card Industry (PCI) Data Security Standard (DSS) has rigorous monitoring and data security requirements for all merchants, service providers, and financial institutions. To meet these requirements, organizations often separate PCI-regulated data (such as cardholder data) and non-regulated data into different applications for monitoring and compliance purposes. |
55 | 12 |
|
56 |
| -Example of a fully onboarded customer: |
| 13 | +**Datadog's tools and policies comply with PCI v4.0**. To understand the full scope of Datadog's environment and how it relates to customer responsibilities under the relevant PCI-DSS controls, download the Customer Responsibility Matrix and the Attestation of Compliance (AoC) from the [Datadog Trust Center][1]. |
57 | 14 |
|
58 |
| -{{< img src="/data_security/pci_compliant.png" alt="View of PCI compliance in the Configuration Page" style="width:75%;" >}} |
| 15 | +Datadog's Attestation of Compliance (AoC) reflects the tools and policies we have in place to maintain a Connected PCI environment as a service provider. The Datadog platform supports connections to cardholder data environments (CDE) as a Connected PCI environment, but does not serve as a CDE itself for storing, processing, or transmitting cardholder data (CHD). |
| 16 | +It is your responsibility to prevent any CHD from entering the Datadog platform. |
59 | 17 |
|
60 |
| -Example of an onboarding customer: |
| 18 | +## Recommended tools for PCI compliance |
61 | 19 |
|
62 |
| -{{< img src="/data_security/pci_onboarding.png" alt="View of PCI onboarding in the Configuration Page" style="width:75%;" >}} |
| 20 | +To help maintain PCI compliance, **Datadog strongly recommends** the use of the following tools and process: |
| 21 | +- [**Sensitive Data Scanner**][2]: discover, classify, and redact sensitive cardholder data |
| 22 | +- [**Audit Trail**][3]: search and analyze detailed audit events for up to 90 days for long-term retention and archiving |
| 23 | +- [**File Integrity Monitoring**][4]: watch for changes to key files and directories |
| 24 | +- [**Cloud Security Management**][5]: track conformance to requirements of industry benchmarks and other controls |
63 | 25 |
|
64 | 26 | ## Further Reading
|
65 | 27 |
|
66 | 28 | {{< partial name="whats-next/whats-next.html" >}}
|
67 | 29 |
|
68 |
| -[2]: https://app.datadoghq.com/organization-settings/safety-center/configuration |
| 30 | +[1]: https://trust.datadoghq.com/?itemUid=53e1508c-665e-45a8-9ce0-03fdf9ae1efb&source=click |
| 31 | +[2]: /security/sensitive_data_scanner/ |
| 32 | +[3]: /account_management/audit_trail/ |
| 33 | +[4]: /security/workload_protection/ |
| 34 | +[5]: /security/cloud_security_management/#track-your-organizations-health |
0 commit comments