PCI DSS 9.4.1: All media with cardholder data is physically secured

PCI DSS v4.0.1 control 9.4.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 9.4.

Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.4

All media with cardholder data is physically secured.

Summary

Physically secure anything holding cardholder data: paper, printouts, disks, tapes and anything else that can be picked up.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
9.4.1 Examine documentation to verify that the procedures defined for protecting cardholder data include controls for physically securing all media.

A short requirement with a wide scope, and the one that catches entities who have thought carefully about systems and not at all about paper. Media means every physical form: receipts and reports, backup tapes and disks, and removable drives. The single procedure examines documented policies and procedures for securing media, and the related controls in section 9.4 cover classification, transport, retention and destruction, which are assessed alongside it. Worth pairing with 3.2.1: media you no longer have a retention justification for should not exist to secure, and destroying it is cheaper than protecting it.

What to prepare

  • The media inventory or, where volume makes that impractical, the defined storage locations and their controls.
  • Evidence of physical security for each location: locked, access-controlled, and who holds the key.
  • The policy covering paper as well as electronic media.
  • Destruction records for media past its retention period, per 9.4.6.

How to implement it

1. Find the paper first. Signed receipts in a drawer, printed reconciliation reports and order forms taken over the phone are the media most entities have and least often secure, because none of it is anybody’s system.

2. Secure by location, not by item, where volume is high. A defined, locked, access-controlled area with a rule that card-bearing media lives only there is auditable. An inventory of every receipt is not.

3. Reduce the volume before improving the locks. Media you have no retention justification for is media you can destroy, and this control gets easier in direct proportion.

4. Cover media in transit and at third parties. Backups held offsite and archives at a storage provider are still yours, and the security of the location is still your evidence to produce.

Where this commonly fails

  • Electronic media secured carefully while printouts and receipts sit in an unlocked cabinet.
  • Backup tapes at an offsite provider with no evidence of the controls there.
  • A locked room whose key is held by everyone, which is a lock rather than access control.
  • Media retained indefinitely because nobody applied the retention policy to physical formats.

Others in section 9.4:

Control What it requires
9.4.1.1 Offline media backups with cardholder data are stored in a secure location
9.4.1.2 The security of the offline media backup location(s) with cardholder data is reviewed at least…
9.4.2 All media with cardholder data is classified in accordance with the sensitivity of the data
9.4.3 Media with cardholder data sent outside the facility is secured…
9.4.4 Management approves all media with cardholder data that is moved outside the facility…
9.4.5 Inventory logs of all electronic media with cardholder data are maintained
9.4.5.1 Inventories of electronic media with cardholder data are conducted at least once every 12 months
9.4.6 Hard-copy materials with cardholder data are destroyed when no longer needed for business…
9.4.7 Electronic media with cardholder data is destroyed when no longer needed for business or legal…

9.3.4 · All controls · 9.4.1.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.