Requirement 9 · Restrict physical access to cardholder data

9.2 Physical access controls manage entry into facilities and systems

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAIL9.2 Audit PathPOLICY / CONTROL / EVIDENCE / REVIEW

How to meet it

Control and monitor entry to areas with cardholder data.

Defined requirements

The individual PCI DSS v4.0.1 requirements under 9.2, in plain English.

9.2.1Suitable facility entry controls limit physical access to systems within the CDE.
9.2.1.1Physical access to sensitive areas is monitored by cameras and/or access controls, protected from tampering, and kept at least three months.
9.2.2Physical and/or logical controls restrict use of publicly accessible network jacks.
9.2.3Physical access to wireless access points, gateways, and networking hardware is restricted.
9.2.4Access to consoles in sensitive areas is limited by locking them when not in use.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to Requirement 9, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.