PCI DSS 9.2.2: Physical and/or logical controls are implemented to restrict use of publicly accessible network
PCI DSS v4.0.1 control 9.2.2: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 9.2.
Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.2
Physical and/or logical controls are implemented to restrict use of publicly accessible network jacks within the facility.
Summary
Network jacks in places the public can reach must not simply work when something is plugged into them.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 9.2.2 | Interview responsible personnel and observe locations of publicly accessible network jacks to verify that physical and/or logical controls are in place to restrict access to publicly accessible network jacks within the facility. |
Sits between 9.2.1, which controls who gets into the facility, and 9.2.3, which protects the network hardware itself. This one covers the case where someone is legitimately in the building and near a live socket: a reception area, a meeting room, a lobby, a retail floor. The requirement allows physical and/or logical controls, so disabling the port, requiring authentication on it, or physically preventing access are all acceptable, and you may mix them. The procedure has the assessor observe the locations, which means this is walked rather than read, and it is worth walking it yourself first.
What to prepare
- A list of the areas the public can reach, agreed with facilities rather than assumed.
- The jacks in each, with what restricts them and how.
- Switch configuration showing the ports disabled, or the NAC policy applied to them.
- A recent test result: something plugged in, and what happened.
How to implement it
1. Walk the building. This control is failed in meeting rooms more than anywhere else, and a port list from the patch panel will not tell you which sockets sit where the public can sit.
2. Default the unused ports to shut. Disabling by default and enabling on request is far easier to evidence than tracking which of the live ports are safe.
3. Use 802.1X where jacks have to stay live. A port that authenticates before it grants access satisfies the logical half of the requirement without arguments about which room counts as public.
4. Test it rather than describing it. Plug a laptop into a reception jack and see what you get. That result is the evidence, and it is also how you find the one port that was re-enabled and forgotten.
Where this commonly fails
- Meeting room jacks live on the corporate VLAN, because someone might need them.
- Ports disabled at the switch and re-enabled for a visitor, with nothing to turn them off again.
- The list built from documentation rather than from a walk, so the jack behind the reception desk is missing.
- Wireless treated as the only public access path, when a socket in the lobby needs no credentials at all.
Related controls
Others in section 9.2:
| Control | What it requires |
|---|---|
| 9.2.1 | Appropriate facility entry controls are in place to restrict physical access to systems… |
| 9.2.1.1 | Individual physical access to sensitive areas within the CDE is monitored with either video… |
| 9.2.3 | Physical access to wireless access points, gateways, networking/communications hardware… |
| 9.2.4 | Access to consoles in sensitive areas is restricted via locking when not in use |
← 9.2.1.1 · All controls · 9.2.3 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.