PCI DSS 9.4.5.1: Inventories of electronic media with cardholder data are conducted at least once every 12 months
PCI DSS v4.0.1 control 9.4.5.1: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 9.4.
Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.4
Inventories of electronic media with cardholder data are conducted at least once every 12 months.
Summary
Once a year, actually count the electronic media against the register.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 9.4.5.1.a | Examine documentation to verify that procedures are defined to conduct inventories of electronic media with cardholder data at least once every 12 months. |
| 9.4.5.1.b | Examine electronic media inventory logs and interview personnel to verify that electronic media inventories are performed at least once every 12 months. |
The distinction from 9.4.5 is the whole control, and it is the difference between a list and a stocktake. 9.4.5 asks that an inventory is maintained; this asks that an inventory is conducted at least once every 12 months, meaning the recorded items are checked against the ones that physically exist. A register can be diligently maintained and still be wrong, because it records what people remembered to tell it. The annual count is what finds the tape that was never returned and the drive that left in a decommissioning box. Both procedures matter: 9.4.5.1.a examines that the procedure is defined, and 9.4.5.1.b examines the logs and interviews personnel to verify it was performed.
What to prepare
- The documented procedure defining the annual inventory.
- Results of the last count, with the date and who performed it.
- Discrepancies found and what was done about them.
- The register itself, which the count is performed against.
How to implement it
1. Count against the register, and record the exceptions. A count that reports no discrepancies every year without listing what was checked is the pattern an assessor probes.
2. Include media held offsite. It is the population most likely to have drifted, and counting it usually requires the storage vendor, so it needs arranging rather than doing.
3. Treat a missing item as an incident. Electronic media with cardholder data that cannot be located is a potential exposure, not a bookkeeping error, and 12.10.7 is the procedure for account data turning up where it should not be.
4. Do it at a fixed point in the year. Annual controls with no date attached are the ones that quietly become eighteen-monthly.
Where this commonly fails
- The register maintained and never verified, so errors accumulate unseen.
- Offsite media excluded from the count because reaching it is inconvenient.
- Discrepancies found and resolved informally with no record.
- A defined procedure with no evidence it was performed, or a count performed with no procedure behind it.
Related controls
Others in section 9.4:
| Control | What it requires |
|---|---|
| 9.4.1 | All media with cardholder data is physically secured |
| 9.4.1.1 | Offline media backups with cardholder data are stored in a secure location |
| 9.4.1.2 | The security of the offline media backup location(s) with cardholder data is reviewed at least… |
| 9.4.2 | All media with cardholder data is classified in accordance with the sensitivity of the data |
| 9.4.3 | Media with cardholder data sent outside the facility is secured… |
| 9.4.4 | Management approves all media with cardholder data that is moved outside the facility… |
| 9.4.5 | Inventory logs of all electronic media with cardholder data are maintained |
| 9.4.6 | Hard-copy materials with cardholder data are destroyed when no longer needed for business… |
| 9.4.7 | Electronic media with cardholder data is destroyed when no longer needed for business or legal… |
← 9.4.5 · All controls · 9.4.6 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.