PCI DSS 9.3.1: Procedures are implemented for authorizing and managing physical access of personnel
PCI DSS v4.0.1 control 9.3.1: the requirement in full, the 3 testing procedures an assessor uses to verify it, and the related controls in section 9.3.
Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.3
Procedures are implemented for authorizing and managing physical access of personnel to the CDE, including:
- Identifying personnel.
- Managing changes to an individual’s physical access requirements.
- Revoking or terminating personnel identification.
- Limiting access to the identification process or system to authorized personnel.
Summary
Have a written process for who gets physical access to the cardholder data environment, how changes are handled, and how access is taken away.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 9.3.1.a | Examine documented procedures to verify that procedures to authorize and manage physical access of personnel to the CDE are defined in accordance with all elements specified in this requirement. |
| 9.3.1.b | Observe identification methods, such as ID badges, and processes to verify that personnel in the CDE are clearly identified. |
| 9.3.1.c | Observe processes to verify that access to the identification process, such as a badge system, is limited to authorized personnel. |
Four elements, and the fourth is the one that gets overlooked because it is not about people at all: limiting access to the identification process or system to authorized personnel. That means the badging system itself. Whoever can issue a badge can grant themselves access to the CDE without appearing on any access list, which makes the badge system a control system rather than an administrative tool. Procedure 9.3.1.c observes exactly that. The other three procedures are observational too: 9.3.1.b watches whether people in the CDE are clearly identified, which is a different question from whether they were authorised.
What to prepare
- The documented procedure, checked against all four elements.
- The current access list for the CDE, and how it is kept current.
- The badge system, and who can issue, modify or delete a badge.
- The joiners, movers and leavers process, showing physical access as a step.
How to implement it
1. Treat the badge system as in scope. Its administrators are effectively granting CDE access, so their access needs approving and reviewing like any other privileged access.
2. Make identification visible. The second procedure observes whether personnel in the CDE are clearly identified, which is about badges being worn rather than badges being issued.
3. Handle movers, not just joiners and leavers. "Managing changes to an individual's physical access requirements" is a named element, and a role change that should have removed access is the usual failure.
4. Connect revocation to the same trigger as 8.2.5. One termination event should remove logical and physical access together, or one of them will be forgotten.
Where this commonly fails
- Badge system administration unrestricted, so access can be granted outside the approval process entirely.
- Badges issued and never worn, which fails the observation in 9.3.1.b however good the list is.
- Role changes that add access and never remove the old.
- Physical revocation handled separately from logical, so a leaver keeps a working badge.
Related controls
Others in section 9.3:
| Control | What it requires |
|---|---|
| 9.3.1.1 | Physical access to sensitive areas within the CDE for personnel is controlled… |
| 9.3.2 | Procedures are implemented for authorizing and managing visitor access to the CDE… |
| 9.3.3 | Visitor badges or identification are surrendered or deactivated before visitors leave… |
| 9.3.4 | Visitor logs are used to maintain a physical record of visitor activity both within… |
← 9.2.4 · All controls · 9.3.1.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.