PCI DSS 9.2.4: Access to consoles in sensitive areas is restricted via locking when not in use

PCI DSS v4.0.1 control 9.2.4: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 9.2.

Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.2

Access to consoles in sensitive areas is restricted via locking when not in use.

Summary

Consoles in sensitive areas are locked when nobody is using them, so being in the room is not the same as being logged in.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
9.2.4 Observe a system administrator’s attempt to log into consoles in sensitive areas and verify that they are “locked” to prevent unauthorized use.

This is about the physical console in a sensitive area, not about remote sessions. It is the last line in a section otherwise about keeping people out: 9.2.4 assumes someone is already in the room, whether because they work there, because they were escorted in, or because a door was propped. The procedure is unusually direct. The assessor observes an administrator attempting to log in and verifies the console was locked, so this control is demonstrated live and cannot be evidenced by a policy statement. A screen-lock timeout is the normal answer, and the timeout has to be shorter than the time consoles are actually left unattended.

What to prepare

  • A list of the consoles in sensitive areas, including jump hosts, KVMs and any permanently displayed dashboard.
  • The lock policy applied to each, with the timeout value.
  • The exception list, if any console cannot lock, with what compensates for it.

How to implement it

1. Set the timeout against how the room is used, not against a default. Fifteen minutes in a data centre where an administrator steps away for ten is a control that never engages.

2. Include the dashboards. A wall display logged into a monitoring console is a console in a sensitive area, and it is the one most likely to have locking disabled deliberately. If it must stay on, give it a read-only account with no privileges rather than an exemption.

3. Cover KVMs and out-of-band consoles. They are consoles, they are usually in the sensitive area, and they are frequently missed because they are not thought of as workstations.

4. Make locking on walking away a habit as well as a timeout. The assessor observes an attempt to log in, and a console that is locked because someone locked it is the same evidence as one locked by policy.

Where this commonly fails

  • A timeout longer than the typical absence, so the screen is almost never locked in practice.
  • A permanently logged-in dashboard exempted informally because switching it off is inconvenient.
  • Locking enforced on laptops by group policy and not on the servers in the room, which are on a different policy.
  • Shared credentials on a console, which makes locking it a formality since everyone can unlock it.

Others in section 9.2:

Control What it requires
9.2.1 Appropriate facility entry controls are in place to restrict physical access to systems…
9.2.1.1 Individual physical access to sensitive areas within the CDE is monitored with either video…
9.2.2 Physical and/or logical controls are implemented to restrict use of publicly accessible network…
9.2.3 Physical access to wireless access points, gateways, networking/communications hardware…

9.2.3 · All controls · 9.3.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.