PCI DSS 9.4.4: Management approves all media with cardholder data that is moved outside the facility
PCI DSS v4.0.1 control 9.4.4: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 9.4.
Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.4
Management approves all media with cardholder data that is moved outside the facility (including when media is distributed to individuals).
Summary
Someone in management approves media leaving the building, before it goes.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 9.4.4.a | Examine documentation to verify that procedures are defined to ensure that media moved outside the facility is approved by management. |
| 9.4.4.b | Examine offsite media tracking logs and interview responsible personnel to verify that proper management authorization is obtained for all media moved outside the facility (including media distributed to individuals). |
The gate in front of 9.4.3. Short, and its scope is wider than it first reads: it covers all media with cardholder data moved outside the facility including when media is distributed to individuals, so handing a report to a colleague to take away is in scope. The value is not the signature but the decision: approval is the moment somebody asks whether the media needs to leave at all, which is usually where the answer is no. Where movement is routine, such as a scheduled backup rotation, a standing approval covering the arrangement is the practical form, provided it is genuinely a decision and not a formality.
What to prepare
- Approval records tied to the transport log entries from 9.4.3.
- Who is authorised to approve, and evidence they are management.
- Any standing approvals, with their scope and review date.
How to implement it
1. Approve before, not after. A record created at audit time is not an approval, and the sequence is visible from the dates.
2. Use standing approval for routine movement, deliberately. A documented arrangement for scheduled backup rotation is legitimate; a standing approval for "anything the team needs" is not a decision.
3. Ask whether it needs to leave. The control's real value is the moment of scrutiny, which is why approval by the person requesting it defeats the purpose.
4. Cover distribution to individuals. It is named in the requirement and it is the route that bypasses courier-shaped processes entirely.
Where this commonly fails
- Approval recorded retrospectively to match a transport log.
- The requester approving their own movement.
- Standing approval so broad it authorises anything.
- Media handed to individuals treated as outside the control.
Related controls
Others in section 9.4:
| Control | What it requires |
|---|---|
| 9.4.1 | All media with cardholder data is physically secured |
| 9.4.1.1 | Offline media backups with cardholder data are stored in a secure location |
| 9.4.1.2 | The security of the offline media backup location(s) with cardholder data is reviewed at least… |
| 9.4.2 | All media with cardholder data is classified in accordance with the sensitivity of the data |
| 9.4.3 | Media with cardholder data sent outside the facility is secured… |
| 9.4.5 | Inventory logs of all electronic media with cardholder data are maintained |
| 9.4.5.1 | Inventories of electronic media with cardholder data are conducted at least once every 12 months |
| 9.4.6 | Hard-copy materials with cardholder data are destroyed when no longer needed for business… |
| 9.4.7 | Electronic media with cardholder data is destroyed when no longer needed for business or legal… |
← 9.4.3 · All controls · 9.4.5 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.