PCI DSS 9.2.3: Physical access to wireless access points, gateways, networking/communications hardware
PCI DSS v4.0.1 control 9.2.3: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 9.2.
Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.2
Physical access to wireless access points, gateways, networking/communications hardware, and telecommunication lines within the facility is restricted.
Summary
Restrict physical access to the network hardware itself: access points, switches, gateways and the cabling.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 9.2.3 | Interview responsible personnel and observe locations of hardware and lines to verify that physical access to wireless access points, gateways, networking/communications hardware, and telecommunication lines within the facility is restricted. |
The part of Requirement 9 about the network rather than the systems, and it is the one an office-based entity most often has no answer for. An unlocked comms cupboard means anyone can plug into a switch carrying CDE traffic, mirror a port, or attach a device to a wireless access point: none of which the controls in Requirement 1 can see, because the attacker is inside the boundary those controls define. Pairs with 9.2.1: facility entry is the outer control, this is the one that matters once someone is through the front door, whether they belong there or not.
What to prepare
- The locations of network and communications hardware, including risers and cupboards.
- The access restriction at each, and who holds keys or codes.
- Evidence for wireless access points, which are often mounted in open areas.
How to implement it
1. Lock the cupboard and know who has the key. It is a small control and it is usually the whole finding.
2. Secure access points physically where they are mounted in the open. Mounting brackets with tamper screws and above-ceiling placement are the usual answers; a reachable access point can be reset to defaults.
3. Include the cabling and patch panels. The requirement names telecommunication lines, and a patch panel in a shared corridor is an access point to every segment it carries.
4. Do not rely on the building. A shared office building means the facility entry control at 9.2.1 is somebody else's, so the hardware restriction is the one you own.
Where this commonly fails
- Servers secured while the comms cupboard is unlocked or propped open.
- Wireless access points mounted within reach and resettable.
- Patch panels and risers in shared or common areas.
- Key holders unknown, so the restriction cannot be described let alone evidenced.
Related controls
Others in section 9.2:
| Control | What it requires |
|---|---|
| 9.2.1 | Appropriate facility entry controls are in place to restrict physical access to systems… |
| 9.2.1.1 | Individual physical access to sensitive areas within the CDE is monitored with either video… |
| 9.2.2 | Physical and/or logical controls are implemented to restrict use of publicly accessible network… |
| 9.2.4 | Access to consoles in sensitive areas is restricted via locking when not in use |
← 9.2.2 · All controls · 9.2.4 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.