Skip to content

Commit c9e4be1

Browse files
estherk15jinatdatadogdrichards-87
authored
Deprecate PCI DSS for Logs and APM (#30919)
* Deprecate PCI DSS docs * Remove references to PCI * Re-add PCI Compliance docs with updated links * Update content/en/data_security/pci_compliance.md Co-authored-by: Esther Kim <[email protected]> * Update content/en/data_security/pci_compliance.md * Readd the further reading links * Remove PCI config shortcodes * Apply suggestions from code review Co-authored-by: DeForest Richards <[email protected]> * Restore shortcode to fix build issue --------- Co-authored-by: jinatdatadog <[email protected]> Co-authored-by: DeForest Richards <[email protected]>
1 parent 8d55f06 commit c9e4be1

File tree

12 files changed

+32
-149
lines changed

12 files changed

+32
-149
lines changed

config/_default/menus/main.en.yaml

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -5752,13 +5752,6 @@ menu:
57525752
url: logs/log_configuration/forwarding_custom_destinations/
57535753
parent: log_configuration
57545754
weight: 211
5755-
- name: PCI Compliance
5756-
identifier: log_pci_compliance
5757-
url: data_security/pci_compliance/
5758-
parent: log_management
5759-
weight: 3
5760-
params:
5761-
skip: true
57625755
- name: Log Explorer
57635756
url: logs/explorer/
57645757
parent: log_management

content/en/account_management/audit_trail/_index.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ further_reading:
1111
text: "Learn about organization settings"
1212
- link: "/data_security/pci_compliance/"
1313
tag: "Documentation"
14-
text: "Set up a PCI-compliant Datadog organization"
14+
text: "PCI DSS Compliance"
1515
- link: "https://www.datadoghq.com/blog/compliance-governance-transparency-with-datadog-audit-trail/"
1616
tag: "Blog"
1717
text: "Build compliance, governance, and transparency across your teams with Datadog Audit Trail"
@@ -44,7 +44,7 @@ For security admins or InfoSec teams, audit trail events help with compliance ch
4444

4545
You can also analyze Audit Trail events with [Cloud SIEM][15] to detect threats and generate security signals. See [Getting Started with Cloud SIEM][16] for more information.
4646

47-
**Note**: See [PCI DSS Compliance][2] for information on setting up a PCI-compliant Datadog organization.
47+
**Note**: Datadog's tools and policies comply with PCI v4.0. For more information, see [PCI DSS Compliance][2].
4848

4949
## Setup
5050

content/en/data_security/logs.md

Lines changed: 6 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -8,17 +8,16 @@ further_reading:
88
text: "Review the main categories of data submitted to Datadog"
99
- link: "/data_security/pci_compliance/"
1010
tag: "Documentation"
11-
text: "Set up a PCI-compliant Datadog organization"
12-
- link: "https://www.datadoghq.com/blog/datadog-pci-compliance-log-management-apm/"
13-
tag: "Blog"
14-
text: "Announcing PCI-Compliant Log Management and APM from Datadog"
11+
text: "PCI DSS Compliance"
1512
---
1613

1714
<div class="alert alert-info">This page is about the security of data sent to Datadog. If you're looking for cloud and application security products and features, see the <a href="/security/" target="_blank">Security</a> section.</div>
1815

1916
The Log Management product supports multiple [environments and formats][1], allowing you to submit to Datadog nearly any data you choose. This article describes the main security guarantees and filtering controls available to you when submitting logs to Datadog.
2017

21-
**Note**: Logs can be viewed in various Datadog products. All logs viewed in the Datadog UI, including logs viewed in APM trace pages, are part of the Log Management product.
18+
**Notes**:
19+
- Logs can be viewed in various Datadog products. All logs viewed in the Datadog UI, including logs viewed in APM trace pages, are part of the Log Management product.
20+
- Datadog's tools and policies comply with PCI v4.0. For more information, see [PCI DSS Compliance][10].
2221

2322
## Information security
2423

@@ -42,31 +41,6 @@ Sensitive Data Scanner is also available as a [processor][8] in [Observability P
4241

4342
{{% hipaa-customers %}}
4443

45-
## PCI DSS compliance for Log Management
46-
47-
{{< site-region region="us" >}}
48-
49-
<div class="alert alert-warning">
50-
PCI DSS compliance for Log Management is only available for Datadog organizations in the <a href="/getting_started/site/">US1 site</a>.
51-
</div>
52-
53-
Datadog allows customers to send logs to PCI DSS compliant Datadog organizations upon request. To set up a PCI-compliant Datadog org, follow these steps:
54-
55-
{{% pci-logs %}}
56-
57-
See [PCI DSS Compliance][1] for more information. To enable PCI compliance for APM, see [PCI DSS compliance for APM][1].
58-
59-
[1]: /data_security/pci_compliance/
60-
[2]: /data_security/pci_compliance/?tab=apm
61-
62-
{{< /site-region >}}
63-
64-
{{< site-region region="us3,us5,eu,gov,ap1,ap2" >}}
65-
66-
PCI DSS compliance for Log Management is not available for the {{< region-param key="dd_site_name" >}} site.
67-
68-
{{< /site-region >}}
69-
7044
## Endpoint encryption
7145

7246
All log submission endpoints are encrypted. These legacy endpoints are still supported:
@@ -88,4 +62,5 @@ All log submission endpoints are encrypted. These legacy endpoints are still sup
8862
[6]: https://www.datadoghq.com/legal/hipaa-eligible-services/
8963
[7]: /security/sensitive_data_scanner/
9064
[8]: /observability_pipelines/processors/sensitive_data_scanner
91-
[9]: /observability_pipelines/
65+
[9]: /observability_pipelines/
66+
[10]: /data_security/pci_compliance/
Lines changed: 18 additions & 52 deletions
Original file line numberDiff line numberDiff line change
@@ -1,68 +1,34 @@
11
---
22
title: PCI DSS Compliance
3-
disable_toc: false
43
further_reading:
5-
- link: "https://www.datadoghq.com/blog/datadog-pci-compliance-log-management-apm/"
6-
tag: "Blog"
7-
text: "Announcing PCI-Compliant Log Management and APM from Datadog"
8-
- link: "coterm"
9-
tag: "Documentation"
10-
text: "CoTerm: Monitor terminal sessions and sensitive activities on local and remote systems"
4+
- link: "https://trust.datadoghq.com/"
5+
tag: "Datadog Trust Center"
6+
text: "Learn about Datadog's security posture and review security documentation"
117
---
128

13-
{{% site-region region="us3,us5,eu,ap1,gov,ap2" %}}
14-
<div class="alert alert-warning">
15-
PCI DSS compliance for APM and Log Management is only available for Datadog organizations in the <a href="/getting_started/site/">US1 site</a>.
16-
</div>
17-
{{% /site-region %}}
18-
19-
{{% site-region region="us" %}}
20-
<div class="alert alert-warning">
21-
PCI DSS compliance for APM and Log Management is only available for Datadog organizations in the <a href="/getting_started/site/">US1 site</a>.
22-
</div>
23-
249
## Overview
2510

26-
The Payment Card Industry (PCI) Data Security Standard (DSS) has rigorous monitoring and data security requirements for all merchants, service providers, and financial institutions. To meet these requirements, organizations have had to separate out PCI-regulated data and non-regulated data to different applications for monitoring.
27-
28-
Datadog offers PCI-compliant Log Management and Application Performance Monitoring (APM) within the [US1 site][1] so that you can collect all of your logs, whether they are PCI-regulated or not, in one place. See [Set up a PCI-compliant Datadog organization](#set-up-a-pci-compliant-datadog-organization) on how to get started.
29-
30-
## Set up a PCI-compliant Datadog organization
31-
32-
{{< tabs >}}
33-
34-
{{% tab "Log Management" %}}
35-
36-
{{% pci-logs %}}
37-
38-
{{% /tab %}}
39-
40-
{{% tab "APM" %}}
41-
42-
{{% pci-apm %}}
43-
44-
{{% /tab %}}
45-
46-
{{< /tabs >}}
47-
48-
[1]: /getting_started/site/
49-
50-
{{% /site-region %}}
51-
52-
## View your PCI Compliance status
53-
54-
See the [Configuration Page][2] inside Safety Center.
11+
The Payment Card Industry (PCI) Data Security Standard (DSS) has rigorous monitoring and data security requirements for all merchants, service providers, and financial institutions. To meet these requirements, organizations often separate PCI-regulated data (such as cardholder data) and non-regulated data into different applications for monitoring and compliance purposes.
5512

56-
Example of a fully onboarded customer:
13+
**Datadog's tools and policies comply with PCI v4.0**. To understand the full scope of Datadog's environment and how it relates to customer responsibilities under the relevant PCI-DSS controls, download the Customer Responsibility Matrix and the Attestation of Compliance (AoC) from the [Datadog Trust Center][1].
5714

58-
{{< img src="/data_security/pci_compliant.png" alt="View of PCI compliance in the Configuration Page" style="width:75%;" >}}
15+
Datadog's Attestation of Compliance (AoC) reflects the tools and policies we have in place to maintain a Connected PCI environment as a service provider. The Datadog platform supports connections to cardholder data environments (CDE) as a Connected PCI environment, but does not serve as a CDE itself for storing, processing, or transmitting cardholder data (CHD).
16+
It is your responsibility to prevent any CHD from entering the Datadog platform.
5917

60-
Example of an onboarding customer:
18+
## Recommended tools for PCI compliance
6119

62-
{{< img src="/data_security/pci_onboarding.png" alt="View of PCI onboarding in the Configuration Page" style="width:75%;" >}}
20+
To help maintain PCI compliance, **Datadog strongly recommends** the use of the following tools and process:
21+
- [**Sensitive Data Scanner**][2]: discover, classify, and redact sensitive cardholder data
22+
- [**Audit Trail**][3]: search and analyze detailed audit events for up to 90 days for long-term retention and archiving
23+
- [**File Integrity Monitoring**][4]: watch for changes to key files and directories
24+
- [**Cloud Security Management**][5]: track conformance to requirements of industry benchmarks and other controls
6325

6426
## Further Reading
6527

6628
{{< partial name="whats-next/whats-next.html" >}}
6729

68-
[2]: https://app.datadoghq.com/organization-settings/safety-center/configuration
30+
[1]: https://trust.datadoghq.com/?itemUid=53e1508c-665e-45a8-9ce0-03fdf9ae1efb&source=click
31+
[2]: /security/sensitive_data_scanner/
32+
[3]: /account_management/audit_trail/
33+
[4]: /security/workload_protection/
34+
[5]: /security/cloud_security_management/#track-your-organizations-health

content/en/logs/_index.md

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -65,8 +65,6 @@ Datadog Log Management, also referred to as Datadog logs or logging, removes the
6565

6666
Logging without Limits\* enables a streamlined troubleshooting experience in the [Log Explorer][1], which empowers you and your teams to quickly assess and fix your infrastructure issues. It provides intuitive archiving to support your security and IT teams during audits and assessments. Logging without Limits* also powers [Datadog Cloud SIEM][2], which detects security threats in your environment, without requiring you to index logs.
6767

68-
**Note**: See [PCI DSS Compliance][3] for information on setting up a PCI-compliant Datadog organization.
69-
7068
{{< vimeo url="https://player.vimeo.com/progressive_redirect/playback/293195142/rendition/1080p/file.mp4?loc=external&signature=8a45230b500688315ef9c8991ce462f20ed1660f3edff3d2904832e681bd6000" poster="/images/poster/logs.png" >}}
7169

7270
</br>
@@ -117,7 +115,6 @@ Start exploring your ingested logs in the [Log Explorer][1].
117115

118116
[1]: /logs/explorer/
119117
[2]: /security/cloud_siem/
120-
[3]: /data_security/pci_compliance/
121118
[4]: /logs/log_collection/
122119
[5]: /logs/log_configuration/
123120
[6]: /tracing/other_telemetry/connect_logs_and_traces/

content/en/logs/guide/azure-logging-guide.md

Lines changed: 0 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -136,21 +136,6 @@ See [Getting started with Azure Functions][307] for more information.
136136
{{% /tab %}}
137137
{{< /tabs >}}
138138

139-
## Advanced configuration
140-
Refer to the following topics to configure your installation according to your monitoring needs.
141-
142-
### PCI compliance
143-
144-
<div class="alert alert-warning">
145-
PCI DSS compliance for APM and Log Management is only available for Datadog organizations in the <a href="/getting_started/site/">US1 site</a>.
146-
</div>
147-
148-
To set up PCI-compliant Log Management, you must meet the requirements outlined in [PCI DSS Compliance][6]. Send your logs to the dedicated PCI compliant endpoint:
149-
150-
Under **Settings > Environment variables**, click **Add** to set the following environment variable:
151-
- Name: `DD_URL`
152-
- Value: `http-intake-pci.logs.datadoghq.com`
153-
154139
## Log Archiving
155140

156141
Archiving logs to Azure Blob Storage requires an App Registration even if you are using the Azure Native integration. To archive logs to Azure Blob Storage, follow the [automatic][7] or [manual][8] setup instructions to configure the integration using an App Registration. App Registrations created for archiving purposes do not need the `Monitoring Reader` role assigned.
@@ -168,7 +153,6 @@ After configuring an App Registration, you can [create a log archive][3] that wr
168153
[3]: /logs/log_configuration/archives/?tab=azurestorage#configure-an-archive
169154
[4]: /logs/guide/azure-native-logging-guide/
170155
[5]: https://learn.microsoft.com/en-us/azure/partner-solutions/datadog/overview
171-
[6]: /data_security/pci_compliance/?tab=logmanagement
172156
[7]: /integrations/guide/azure-programmatic-management/#datadog-azure-integration
173157
[8]: /integrations/guide/azure-manual-setup/#setup
174158
[9]: /logs/guide/azure-automated-log-forwarding/

content/en/logs/log_collection/_index.md

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -142,7 +142,6 @@ Use the [site][13] selector dropdown on the right side of the page to see suppor
142142
| Site | Type | Endpoint | Port | Description |
143143
|------|-------------|---------------------------------------------------------------------------|--------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
144144
| US | HTTPS | `http-intake.logs.datadoghq.com` | 443 | Used by custom forwarder to send logs in JSON or plain text format over HTTPS. See the [Logs HTTP API documentation][1]. |
145-
| US | HTTPS | `agent-http-intake-pci.logs.datadoghq.com` | 443 | Used by the Agent to send logs over HTTPS to an org with PCI DSS compliance enabled. See [PCI DSS compliance for Log Management][3] for more information. |
146145
| US | HTTPS | `agent-http-intake.logs.datadoghq.com` | 443 | Used by the Agent to send logs in JSON format over HTTPS. See the [Host Agent Log collection documentation][2]. |
147146
| US | HTTPS | `lambda-http-intake.logs.datadoghq.com` | 443 | Used by Lambda functions to send logs in raw, Syslog, or JSON format over HTTPS. |
148147
| US | HTTPS | `logs.`{{< region-param key="browser_sdk_endpoint_domain" code="true" >}} | 443 | Used by the Browser SDK to send logs in JSON format over HTTPS. |
@@ -154,7 +153,6 @@ Use the [site][13] selector dropdown on the right side of the page to see suppor
154153

155154
[1]: /api/latest/logs/#send-logs
156155
[2]: /agent/logs/#send-logs-over-https
157-
[3]: /data_security/logs/#pci-dss-compliance-for-log-management
158156
{{< /site-region >}}
159157

160158
{{< site-region region="eu" >}}

content/en/logs/log_collection/javascript.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -407,7 +407,6 @@ The following parameters are available to configure the Datadog browser logs SDK
407407
| `trackingConsent` | `"granted"` or `"not-granted"` | No | `"granted"` | Set the initial user tracking consent state. See [User Tracking Consent][15]. |
408408
| `silentMultipleInit` | Boolean | No | | Prevent logging errors while having multiple init. |
409409
| `proxy` | String | No | | Optional proxy URL (ex: `https://www.proxy.com/path`), see the full [proxy setup guide][6] for more information. |
410-
| `usePciIntake` | Boolean | No | `false` | Use PCI-compliant intake. See [PCI DSS Compliance][20] for more information. |
411410
| `telemetrySampleRate` | Number | No | `20` | Telemetry data (error, debug logs) about SDK execution is sent to Datadog in order to detect and solve potential issues. Set this option to `0` to opt out from telemetry collection. |
412411
| `storeContextsAcrossPages` | Boolean | No | | Store global context and user context in `localStorage` to preserve them along the user navigation. See [Contexts life cycle][11] for more details and specific limitations. |
413412
| `allowUntrustedEvents` | Boolean | No | | Allow capture of [untrusted events][13], for example in automated UI tests. |
@@ -424,7 +423,6 @@ Options that must have a matching configuration when using the `RUM` SDK:
424423
| `trackSessionAcrossSubdomains` | Boolean | No | `false` | Preserve the session across subdomains for the same site. |
425424
| `useSecureSessionCookie` | Boolean | No | `false` | Use a secure session cookie. This disables logs sent on insecure (non-HTTPS) connections. |
426425
| `usePartitionedCrossSiteSessionCookie` | Boolean | No | `false` | Use a partitioned secure cross-site session cookie. This allows the logs SDK to run when the site is loaded from another one (iframe). Implies `useSecureSessionCookie`. |
427-
| `usePciIntake` | Boolean | No | `false` | To forward logs to the [PCI-compliant intake][16], set to `true`. The PCI-compliant intake is only available for Datadog organizations in the US1 site. If `usePciIntake` is set to `true` and the site is not US1 (datadoghq.com), logs are sent to the default intake. |
428426

429427
## Usage
430428

@@ -1410,8 +1408,6 @@ window.DD_LOGS && window.DD_LOGS.getInternalContext() // { session_id: "xxxx-xxx
14101408
[13]: https://developer.mozilla.org/en-US/docs/Web/API/Event/isTrusted
14111409
[14]: /integrations/content_security_policy_logs/#use-csp-with-real-user-monitoring-and-session-replay
14121410
[15]: #user-tracking-consent
1413-
[16]: https://docs.datadoghq.com/data_security/logs/#pci-dss-compliance-for-log-management
14141411
[17]: /real_user_monitoring/browser/advanced_configuration/?tab=npm#micro-frontend
14151412
[18]: /real_user_monitoring/browser/advanced_configuration/?tab=npm#enrich-and-control-rum-data
14161413
[19]: /real_user_monitoring/browser/advanced_configuration/?tab=npm#discard-a-rum-event
1417-
[20]: /data_security/pci_compliance/?tab=logmanagement

content/en/logs/log_configuration/_index.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ aliases:
66
further_reading:
77
- link: "/data_security/pci_compliance/"
88
tag: "Documentation"
9-
text: "Set up a PCI-compliant Datadog organization"
9+
text: "PCI DSS Compliance"
1010
- link: "https://www.datadoghq.com/blog/logging-without-limits/"
1111
tag: "Blog"
1212
text: Learn more about Logging without Limits*
@@ -25,8 +25,6 @@ further_reading:
2525

2626
Datadog Logging without Limits* decouples log ingestion and indexing. Choose which logs to index and retain, or archive, and manage settings and controls at a top-level from the log configuration page at [**Logs > Pipelines**][1].
2727

28-
**Note**: See [PCI DSS Compliance][2] for information on setting up a PCI-compliant Datadog organization.
29-
3028
## Configuration options
3129

3230
- Control how your logs are processed with [pipelines][3] and [processors][4].

content/en/observability_pipelines/destinations/datadog_logs.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -34,9 +34,7 @@ To send logs from Observability Pipelines to Datadog using AWS PrivateLink, see
3434
- Logs (User HTTP intake): `http-intake.logs.datadoghq.com`
3535
- Remote Configuration: `config.datadoghq.com`
3636

37-
**Notes**:
38-
- If you are a PCI-compliant organization, the Worker sends logs over `http-intake-pci.logs.datadoghq.com`, which is not available as an AWS PrivateLink endpoint.
39-
- The `obpipeline-intake.datadoghq.com` endpoint is used for Live Capture and is not available as a PrivateLink endpoint.
37+
**Note**: The `obpipeline-intake.datadoghq.com` endpoint is used for Live Capture and is not available as a PrivateLink endpoint.
4038

4139
[1]: https://app.datadoghq.com/observability-pipelines
4240
[2]: /observability_pipelines/destinations/#event-batching

0 commit comments

Comments
 (0)