9.5 Point-of-interaction (POI) devices are protected
How to meet it
Inspect payment terminals for tampering/substitution and train staff to spot it.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 9.5, in plain English.
9.5.1POI devices that capture card data are protected from tampering and substitution, with a device list, inspections, and staff training.
9.5.1.1An up-to-date list of POI devices is kept with make, model, location, and serial number.
9.5.1.2POI device surfaces are periodically inspected for tampering and substitution.
9.5.1.2.1The inspection frequency and type are defined in the targeted risk analysis.
9.5.1.3POI personnel are trained to spot tampering, verify maintenance personnel, and report suspicious behaviour.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Security awareness and training policyUse for ISO 27001 A.6.3, SOC 2 Security awareness criteria, and PCI DSS requirement 12.6 training obligations.Acceptable use policyUse for ISO 27001 A.5.10, A.6.3, A.6.4, endpoint controls, remote work, and SOC 2 Security awareness.Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.
Open the control-to-policy mapBack to Requirement 9, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.