Requirement 9: Restrict physical access to cardholder data
Physical access to systems and media holding cardholder data must be controlled, and payment devices protected from tampering.
Sub-requirements
9.1
Processes and mechanisms are defined and understood
2 defined requirementsDocument physical security policy.
View defined requirements →9.2
Physical access controls manage entry into facilities and systems
5 defined requirementsControl and monitor entry to areas with cardholder data.
View defined requirements →9.3
Physical access for personnel and visitors is authorised and managed
5 defined requirementsAuthorise personnel access and log/escort visitors.
View defined requirements →9.4
Media with cardholder data is securely stored, accessed, distributed and destroyed
10 defined requirementsClassify, secure, track and securely destroy media holding card data.
View defined requirements →9.5
Point-of-interaction (POI) devices are protected
5 defined requirementsInspect payment terminals for tampering/substitution and train staff to spot it.
View defined requirements →Tips
- ›If you are cloud-only, much of req 9 maps to your provider, but office and POI controls still apply.
- ›Keep a POI device inventory with serial numbers and inspection logs.
Evidence to keep
- ✓Physical access logs
- ✓Visitor logs
- ✓Media handling/destruction records
- ✓POI inspection logs
Example
Server areas need badge access with logs, visitors are escorted, and store staff inspect card terminals daily against a serial-number list.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Physical and environmental security policyUse for ISO 27001 A.7.1 to A.7.14, SOC 2 Security, and PCI DSS requirement 9 physical access controls.AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Clear desk and clear screen policyUse for ISO 27001 A.7.7, physical protection of papers and screens, printing controls, and office and visitor area practices.Cloud services and outsourcing policyUse for ISO 27001 A.5.19 to A.5.23, SOC 2 vendor management, and oversight of cloud and outsourced service providers.
Open the control-to-policy map