PCI DSS 9.4.3: Media with cardholder data sent outside the facility is secured

PCI DSS v4.0.1 control 9.4.3: the requirement in full, the 3 testing procedures an assessor uses to verify it, and the related controls in section 9.4.

Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.4

Media with cardholder data sent outside the facility is secured as follows:

  • Media sent outside the facility is logged.
  • Media is sent by secured courier or other delivery method that can be accurately tracked.
  • Offsite tracking logs include details about media location.

Summary

Media leaving the building is logged, sent by a trackable method, and its location recorded.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
9.4.3.a Examine documentation to verify that procedures are defined for securing media sent outside the facility in accordance with all elements specified in this requirement.
9.4.3.b Interview personnel and examine records to verify that all media sent outside the facility is logged and sent via secured courier or other delivery method that can be tracked.
9.4.3.c Examine offsite tracking logs for all media to verify tracking details are documented.

The transport half of section 9.4, and the one with the most specific evidence: three elements, each producing an artefact. Media sent outside is logged, sent by secured courier or another accurately trackable method, and the offsite tracking logs include details about location. Pairs with 9.4.4, which requires management approval before it moves, and with 9.4.2, since knowing an item is sensitive is what triggers this treatment. The commonest scope surprise is that backup tapes going to an offsite store are media leaving the facility, and so is a laptop or a document carried by an employee.

What to prepare

  • The transport log, showing what left, when, by what method and where it went.
  • Courier or carrier records that make tracking demonstrable.
  • The current location of anything held offsite.

How to implement it

1. Log at the point of departure. A log reconstructed later is not a log; the requirement is about knowing where media is, which is only useful in real time.

2. Include employee-carried media. A person taking documents or a drive to another site is media sent outside the facility, and it rarely goes through whatever process covers the courier.

3. Keep the offsite location current. The third element is about location details, so a log recording despatch and never arrival leaves the item untracked from the moment it left.

4. Reconcile periodically. What the log says is offsite should match what the offsite store says it holds; the difference is the interesting part.

Where this commonly fails

  • Backup tapes going offsite outside the media transport process.
  • Ordinary post used where the method must be trackable.
  • Despatch logged and arrival not, so location is unknown after the first hop.
  • Employee-carried media excluded because no courier was involved.

Others in section 9.4:

Control What it requires
9.4.1 All media with cardholder data is physically secured
9.4.1.1 Offline media backups with cardholder data are stored in a secure location
9.4.1.2 The security of the offline media backup location(s) with cardholder data is reviewed at least…
9.4.2 All media with cardholder data is classified in accordance with the sensitivity of the data
9.4.4 Management approves all media with cardholder data that is moved outside the facility…
9.4.5 Inventory logs of all electronic media with cardholder data are maintained
9.4.5.1 Inventories of electronic media with cardholder data are conducted at least once every 12 months
9.4.6 Hard-copy materials with cardholder data are destroyed when no longer needed for business…
9.4.7 Electronic media with cardholder data is destroyed when no longer needed for business or legal…

9.4.2 · All controls · 9.4.4

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.