Implement strong access control measures

Requirement 9: Restrict physical access to cardholder data

Physical access to systems and media holding cardholder data must be controlled, and payment devices protected from tampering.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILPCI Req 9 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Sub-requirements

Tips

  • If you are cloud-only, much of req 9 maps to your provider, but office and POI controls still apply.
  • Keep a POI device inventory with serial numbers and inspection logs.

Evidence to keep

  • Physical access logs
  • Visitor logs
  • Media handling/destruction records
  • POI inspection logs

Example

Server areas need badge access with logs, visitors are escorted, and store staff inspect card terminals daily against a serial-number list.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map