PCI DSS 9.4.5: Inventory logs of all electronic media with cardholder data are maintained

PCI DSS v4.0.1 control 9.4.5: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 9.4.

Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.4

Inventory logs of all electronic media with cardholder data are maintained.

Summary

Keep a register of the electronic media that holds cardholder data: what exists, and where it is.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
9.4.5.a Examine documentation to verify that procedures are defined to maintain electronic media inventory logs.
9.4.5.b Examine electronic media inventory logs and interview responsible personnel to verify that logs are maintained.

The electronic counterpart to the paper controls around it. 9.4.1 secures media, 9.4.2 classifies it, 9.4.3 and 9.4.4 govern it leaving the building, and 9.4.5 is the list that makes any of that checkable. Without it you cannot tell whether a tape that left has come back, and you cannot show under 9.4.7 that a disk was destroyed, because nothing recorded that it existed. Note that both procedures are needed: 9.4.5.a examines the defined procedure and 9.4.5.b examines the logs themselves and interviews the people who keep them, so a register with no procedure behind it fails half of this.

What to prepare

  • The documented procedure for maintaining the inventory, naming who maintains it and when.
  • The inventory itself, with enough identity per item to tell two similar tapes apart.
  • The person who keeps it, available for interview.

How to implement it

1. Decide what counts as electronic media before building the list. Backup tapes and removable drives are obvious. Decommissioned disks awaiting destruction, and USB media used for transfers, are the ones that are held somewhere and recorded nowhere.

2. Give every item a unique identifier and record where it is. An inventory that says how many tapes you have cannot answer the question the control exists to answer.

3. Reconcile it against 9.4.3. Media leaving is already logged, so the movement log and the inventory should agree. Where they do not, one of them is wrong and it is usually worth knowing which.

4. Keep it where the custodian works. A register maintained by someone who never handles the media goes stale between assessments.

Where this commonly fails

  • Counted rather than itemised, so no individual item can be tracked.
  • Drives pulled from decommissioned servers sitting in a cupboard and never entered, which is the population most likely to go missing.
  • An inventory maintained by the backup software only, so media it does not know about is invisible.
  • The register kept and the procedure never written, which fails 9.4.5.a while satisfying 9.4.5.b.

Others in section 9.4:

Control What it requires
9.4.1 All media with cardholder data is physically secured
9.4.1.1 Offline media backups with cardholder data are stored in a secure location
9.4.1.2 The security of the offline media backup location(s) with cardholder data is reviewed at least…
9.4.2 All media with cardholder data is classified in accordance with the sensitivity of the data
9.4.3 Media with cardholder data sent outside the facility is secured…
9.4.4 Management approves all media with cardholder data that is moved outside the facility…
9.4.5.1 Inventories of electronic media with cardholder data are conducted at least once every 12 months
9.4.6 Hard-copy materials with cardholder data are destroyed when no longer needed for business…
9.4.7 Electronic media with cardholder data is destroyed when no longer needed for business or legal…

9.4.4 · All controls · 9.4.5.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.