Auditen
Home / Frameworks / PCI DSS / Restrict physical access to cardholder data
PCI DSS · Req 9

Restrict physical access to cardholder data

Requirement 9 mandates that organizations implement physical security controls to prevent unauthorized individuals from gaining direct access to systems, networks, and media containing cardholder data. The goal is to ensure that only authorized personnel can physically reach the hardware or paper records where payment data resides.

What it means

While most security focuses on digital firewalls, Requirement 9 addresses "physical" vulnerabilities. If an attacker has physical access to a server, a network switch, or a point-of-sale (POS) terminal, they can often bypass software security entirely by installing hardware keyloggers, stealing hard drives, or manipulating cabling.

The scope extends beyond the data center. It includes any area where cardholder data is processed or stored, such as retail storefronts with payment terminals, office spaces containing paper records, and remote sites hosting networking equipment.

In practice, this means creating a layered defense—using barriers to keep people out, monitoring systems to detect intruders, and strict protocols for managing those who are permitted entry.

How to meet it

Evidence an auditor asks for

  • Physical access logs (electronic badge reports or manual sign-in sheets) showing who entered secure areas.
  • A current inventory list of all hardware devices that process payment data, including their physical locations.
  • CCTV footage samples and a documented policy on how long video recordings are retained.
  • Completed inspection checklists proving that POS terminals were checked for tampering.
  • Visitor logs demonstrating that guests were signed in and assigned an escort.

Common pitfalls

  • Tailgating, where unauthorized individuals follow authorized staff through secure doors without scanning their own badges.
  • Failure to maintain the visitor log consistently or allowing vendors (like HVAC or internet technicians) to work unescorted in secure areas.
  • Neglecting "forgotten" hardware, such as old POS terminals kept in an unlocked storage closet rather than being securely decommissioned.
  • Having security cameras that are improperly positioned or fail to capture clear images of faces at entry points.