PCI DSS 9.3.2: Procedures are implemented for authorizing and managing visitor access to the CDE

PCI DSS v4.0.1 control 9.3.2: the requirement in full, the 5 testing procedures an assessor uses to verify it, and the related controls in section 9.3.

Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.3

Procedures are implemented for authorizing and managing visitor access to the CDE, including:

  • Visitors are authorized before entering.
  • Visitors are escorted at all times.
  • Visitors are clearly identified and given a badge or other identification that expires.
  • Visitor badges or other identification visibly distinguishes visitors from personnel.

Summary

Visitors are authorised before they come in, escorted the whole time, and wear something that marks them as visitors and expires.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
9.3.2.a Examine documented procedures and interview personnel to verify procedures are defined for authorizing and managing visitor access to the CDE in accordance with all elements specified in this requirement.
9.3.2.b Observe processes when visitors are present in the CDE and interview personnel to verify that visitors are: • Authorized before entering the CDE. • Escorted at all times within the CDE.
9.3.2.c Observe the use of visitor badges or other identification to verify that the badge or other identification does not permit unescorted access to the CDE.
9.3.2.d Observe visitors in the CDE to verify that: • Visitor badges or other identification are being used for all visitors. • Visitor badges or identification easily distinguish visitors from personnel.
9.3.2.e Examine visitor badges or other identification and observe evidence in the badging system to verify visitor badges or other identification expires.

Four elements and five procedures, most of them observational, which makes this one of the hardest controls to pass on paperwork alone. The assessor watches visitors being handled. Two elements are stricter than they look. Escorted at all times is absolute, so leaving a visitor in a room for a moment is a failure of the control rather than a lapse in etiquette. And the badge must visibly distinguish visitors from personnel and must expire, with 9.3.2.e examining evidence of expiry in the badging system and 9.3.2.c checking the badge does not permit unescorted access. A visitor badge that opens a door is not a visitor badge for this purpose.

What to prepare

  • The documented procedure covering all four elements.
  • The visitor badge itself, so its distinguishability and expiry can be examined.
  • Badging system evidence that visitor credentials expire.
  • A period when visitors are present, since three procedures observe the process live.

How to implement it

1. Make the badge obviously different at a glance. Colour and shape, not a small word. Personnel have to recognise an unescorted visitor without reading anything.

2. Give visitor credentials a hard expiry in the system. Physical expiry on a printed badge is good; system expiry is what 9.3.2.e examines.

3. Make sure a visitor badge opens nothing. If it does, the escort requirement is enforced only by goodwill.

4. Brief the escorts. "Escorted at all times" is performed by ordinary staff who may not know the standard is absolute about it, and the observation procedures are watching them rather than the policy.

Where this commonly fails

  • A visitor left alone briefly, which the observation is likely to catch and which the control does not tolerate.
  • Visitor badges that open doors, so escorting depends on convention.
  • Badges that look like staff badges from a distance.
  • Authorisation given at the door rather than before entry, which is a different element.

Others in section 9.3:

Control What it requires
9.3.1 Procedures are implemented for authorizing and managing physical access of personnel…
9.3.1.1 Physical access to sensitive areas within the CDE for personnel is controlled…
9.3.3 Visitor badges or identification are surrendered or deactivated before visitors leave…
9.3.4 Visitor logs are used to maintain a physical record of visitor activity both within…

9.3.1.1 · All controls · 9.3.3

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.