PCI DSS 9.1.2: Roles and responsibilities for performing activities in Requirement 9 are documented, assigned

PCI DSS v4.0.1 control 9.1.2: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 9.1.

Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.1

Roles and responsibilities for performing activities in Requirement 9 are documented, assigned, and understood.

Summary

Someone is named for each Requirement 9 activity, they know it, and the assessor will interview them wherever they work.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
9.1.2.a Examine documentation to verify that descriptions of roles and responsibilities for performing activities in Requirement 9 are documented and assigned.
9.1.2.b Interview personnel with responsibility for performing activities in Requirement 9 to verify that roles and responsibilities are assigned as documented and are understood.

The split between 9.1.2.a and 9.1.2.b is the point in every requirement: the first examines documentation, the second interviews the people named. What is specific here is who those people turn out to be. Requirement 9 responsibilities land on reception, facilities, retail management, a contracted security firm, and often an offsite media storage vendor, so 9.1.2.b can mean the assessor interviewing a guard employed by another company or calling the storage facility. A responsibility matrix that assigns physical security to "the security team" survives 9.1.2.a and not the interview, because the person who actually escorts visitors does not report to it. Two responsibilities are easy to leave unowned entirely: administering the badge system, which 9.3.1 treats as a control in its own right, and the annual review of the backup storage location under 9.4.1.2.

What to prepare

  • A responsibility matrix by role for each Requirement 9 activity.
  • The contracted parties performing any of them, and what their contract says.
  • Evidence each assignment reached its holder, including the ones outside the organisation.
  • People available for interview at each site, not only at head office.

How to implement it

1. Assign to the role that does the work, not the function that owns the policy. Reception issues badges; facilities holds keys; the store manager inspects terminals.

2. Put third-party responsibilities in the contract. Where a guard or a storage vendor performs the activity, the assignment has to exist somewhere they will see it, which is the agreement rather than your matrix.

3. Name an owner for the badge system and for the storage-location review. Both are activities without an obvious home, and both are separately required elsewhere in the requirement.

4. Cover every site. Requirement 9 is performed wherever you have premises, and a matrix written for head office leaves the branches unassigned.

Where this commonly fails

  • Everything assigned to a security function that does not perform any of it.
  • Contracted staff performing activities with no documented assignment.
  • Badge system administration unowned, so nobody governs who can grant physical access.
  • A matrix covering the main site while stores or warehouses have none.

Others in section 9.1:

Control What it requires
9.1.1 All security policies and operational procedures that are identified in Requirement 9…

9.1.1 · All controls · 9.2.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.