PCI DSS 3.4.2: When using remote-access technologies, technical controls prevent copy and/or relocation of PAN
PCI DSS v4.0.1 control 3.4.2: the requirement in full, the 3 testing procedures an assessor uses to verify it, and the related controls in section 3.4.
Requirement 3: Protect Stored Account Data › Section 3.4
When using remote-access technologies, technical controls prevent copy and/or relocation of PAN for all personnel, except for those with documented, explicit authorization and a legitimate, defined business need.
Summary
During remote access, technical controls stop people copying or moving card numbers out, unless they are specifically authorised to.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 3.4.2.a | Examine documented policies and procedures and documented evidence for technical controls that prevent copy and/or relocation of PAN when using remote-access technologies onto local hard drives or removable electronic media to verify the following: • Technical controls prevent all personnel not specifically authorized from copying and/or relocating PAN. • A list of personnel with permission to copy and/or relocate PAN is maintained, together with the documented, explicit authorization and legitimate, defined business need. |
| 3.4.2.b | Examine configurations for remote-access technologies to verify that technical controls to prevent copy and/or relocation of PAN for all personnel, unless explicitly authorized. |
| 3.4.2.c | Observe processes and interview personnel to verify that only personnel with documented, explicit authorization and a legitimate, defined business need have permission to copy and/or relocate PAN when using remote-access technologies. |
The counterpart to 3.4.1: that control limits what is displayed, this one limits what can be taken while working remotely. The word carrying it is technical: a policy telling people not to copy PAN does not satisfy it, and all three procedures look for the mechanism. The exception is narrow and needs both halves: documented explicit authorisation and a legitimate defined business need. This control is why remote administration of CDE systems is usually brokered through a controlled desktop or a session tool rather than a plain VPN and a local machine.
What to prepare
- The list of remote-access methods that can reach PAN.
- The technical control on each: clipboard, drive redirection, file transfer, screenshot and print restrictions.
- The authorised exceptions, with the business need documented for each.
How to implement it
1. Control the session, not the endpoint. A virtual desktop or a session broker with clipboard and drive redirection disabled enforces this centrally; asking every laptop to behave is not a technical control you can evidence.
2. Cover every route out, not just copy and paste. Drive mapping, file transfer, screen capture and printing are all relocation, and a configuration that blocks the clipboard alone leaves the rest open.
3. Keep the exception list short and dated. Both halves are required, and an authorisation with no business need recorded is half a justification.
4. Check what the tooling permits by default. Remote desktop and support tools generally enable clipboard and file transfer out of the box, which is the opposite of what this asks.
Where this commonly fails
- A policy prohibiting copying, offered where a technical control is required.
- Clipboard disabled while drive redirection and file transfer remain available.
- Exceptions granted verbally and never documented.
- Third-party support sessions outside whatever controls staff sessions.
Related controls
Others in section 3.4:
| Control | What it requires |
|---|---|
| 3.4.1 | PAN is masked when displayed… |
← 3.4.1 · All controls · 3.5.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.