control
PCI-Req9 — Restrict physical access to cardholder data
Restrict physical access to cardholder data
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- framework
- pci-dss
- type
- preventive
- category
- physical
Details
- control_id
- PCI-Req9
- framework
- pci-dss
- group
- PCI DSS v4.0.1
- domains
- Network & Communications Security
- Secure Configuration & Change Management
- Data Protection & Privacy
- Cryptography & Key Management
- Vulnerability & Patch Management
- Secure Development (SDLC) & Application Security
- Access Control & Identity Management
- Physical & Environmental Security
- Logging, Monitoring & Detection
- Governance, Policy & Oversight
- risk_count
- 3
- control_type
- preventive
- control_category
- physical
- automation
- hybrid
- key_control
- False
- requirement_status
- Not provided
- requirement_frequency
- Not provided
- source_url
- Not provided
- source_pages
- Not provided
Source
No record-specific source URL is provided.
Connections
- PCI-Req9 — Restrict physical access to cardholder data belongs_to PCI DSS v4.0.1
- UC-ASSET-04 — Control storage media through use, storage, and destruction maps_to PCI-Req9 — Restrict physical access to cardholder data
- framework
- pci-dss
- control_id
- PCI-Req9
- coverage
- partial
- delta
- media lifecycle (9.4) is covered; facility entry controls and personnel/visitor access management (9.2-9.3) satisfied by physical-access companion controls; POI terminal anti-tampering and periodic inspection (9.5) not covered by this control
- relationship
- intersects_with
- source_version
- v4.0.1
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.