Sensitive Area

PCIComplianceHubLast updated

A physical area that houses systems critical to the CDE: data centres, server rooms, back-office rooms in shops, anywhere cardholder data storage, processing or transmission is concentrated, and rooms holding the systems that secure the CDE, such as network security controls. A cashier's till area or a call-centre floor, where only point-of-sale terminals are present, is not one.

Applies to. Every entity with a physical footprint for its CDE, including a retailer whose only sensitive area is the cupboard with the store's network switch.
Example. The room in a shop where the point-of-sale server and the router live is a sensitive area; the shop floor is not. The room needs monitoring by video or access control, with the records reviewed and kept for at least three months (9.2.1.1), consoles locked when unattended (9.2.4), visitors escorted (9.3.4) and personnel's badges revoked on departure (9.3.1.1).
Limits. The definition is a subset of the CDE and excludes the places most people picture first, which is deliberate: the controls for sensitive areas are heavier than for the rest of the facility, and applying them to every checkout would be neither possible nor useful. An entity decides which areas are sensitive and an assessor checks the reasoning against the definition.
In PCI DSS v4.0.1. 9.2.1.1, 9.2.4, 9.3.1.1, 9.3.4