Console

PCIComplianceHubLast updated

A screen and keyboard connected directly to a system, so that using it means being physically at the machine. Everything else, from a laptop on the office network to an SSH session from home, is non-console access, and PCI DSS treats the two differently because one of them crosses a network.

Applies to. Every in-scope system component. The distinction decides whether 2.2.7 (encryption of administrative access) and 8.4.1 (MFA for administrative access into the CDE) apply to a given session.
Example. An engineer at the rack with a crash cart plugged into the server is on the console. The same engineer at their desk using a remote desktop tool to the same server is not, and that session must be encrypted with strong cryptography and authenticated with MFA.
Limits. Console access is not exempt from Requirement 8; it is exempt from the two controls that exist because of the network. Physical access to a console is governed by Requirement 9 instead: the console for a CDE system sits in a sensitive area, and 9.2.4 requires consoles in sensitive areas to be locked when not in use.
In PCI DSS v4.0.1. 2.2.7, 8.4.1, 9.2.4