PCI DSS 9.2.1.1: Individual physical access to sensitive areas within the CDE is monitored with either video

PCI DSS v4.0.1 control 9.2.1.1: the requirement in full, the 3 testing procedures an assessor uses to verify it, and the related controls in section 9.2.

Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.2

Individual physical access to sensitive areas within the CDE is monitored with either video cameras or physical access control mechanisms (or both) as follows:

  • Entry and exit points to/from sensitive areas within the CDE are monitored.
  • Monitoring devices or mechanisms are protected from tampering or disabling.
  • Collected data is reviewed and correlated with other entries.
  • Collected data is stored for at least three months, unless otherwise restricted by law.

Summary

Watch who goes into and out of the sensitive areas, protect the watching from being switched off, review what it records, and keep it three months.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
9.2.1.1.a Observe locations where individual physical access to sensitive areas within the CDE occurs to verify that either video cameras or physical access control mechanisms (or both) are in place to monitor the entry and exit points.
9.2.1.1.b Observe locations where individual physical access to sensitive areas within the CDE occurs to verify that either video cameras or physical access control mechanisms (or both) are protected from tampering or disabling.
9.2.1.1.c Observe the physical access control mechanisms and/or examine video cameras and interview responsible personnel to verify that: • Collected data from video cameras and/or physical access control mechanisms is reviewed and correlated with other entries. • Collected data is stored for at least three months.

Four elements and three observational procedures. Three of the elements are routinely half-met. Entry and exit points means both, and a camera covering the door from inside records arrivals well and departures poorly. Monitoring devices are protected from tampering or disabling is the element with the sharpest logic: a recorder sitting in the same room the camera watches, on the same unlocked rack, is monitoring an attacker can turn off after the fact. And collected data is reviewed and correlated with other entries is an active obligation, so recording without ever looking satisfies the equipment and not the control. Retention is at least three months, the same figure as the visitor log in 9.3.4, which makes correlating the two practical.

What to prepare

  • The sensitive areas, and what monitors each entry and exit point.
  • Where the recording equipment lives and what protects it.
  • Evidence of review and correlation, not just retention.
  • Confirmation the retention period is met, and any legal restriction on it.

How to implement it

1. Cover exits as well as entries. Knowing who went in without knowing who came out cannot tell you who is still inside, which is what an access record is for.

2. Put the recorder somewhere the monitored area cannot reach. Off-site, in a separate secured room, or streamed away. Otherwise the monitoring protects everything except itself.

3. Correlate with the badge and visitor records deliberately. Access control says a badge was used; video says who used it. The control asks for the two together, and it is the pairing that detects a shared or borrowed badge.

4. Record that reviews happen. The element is reviewed and correlated, so a review with no artefact is indistinguishable from no review.

Where this commonly fails

  • Entry monitored and exit not.
  • Recording equipment inside the area it monitors, so it can be disabled by whoever gets in.
  • Footage retained and never reviewed or correlated with anything.
  • Retention shorter than three months by default, which is a common factory setting on small recorders.

Others in section 9.2:

Control What it requires
9.2.1 Appropriate facility entry controls are in place to restrict physical access to systems…
9.2.2 Physical and/or logical controls are implemented to restrict use of publicly accessible network…
9.2.3 Physical access to wireless access points, gateways, networking/communications hardware…
9.2.4 Access to consoles in sensitive areas is restricted via locking when not in use

9.2.1 · All controls · 9.2.2

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.