PCI DSS 9.4.1.2: The security of the offline media backup location(s) with cardholder data is reviewed at least

PCI DSS v4.0.1 control 9.4.1.2: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 9.4.

Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.4

The security of the offline media backup location(s) with cardholder data is reviewed at least once every 12 months.

Summary

Check at least once a year that the place your offline backups are stored is still secure.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
9.4.1.2.a Examine documentation to verify that procedures are defined for reviewing the security of the offline media backup location(s) with cardholder data at least once every 12 months.
9.4.1.2.b Examine documented procedures, logs, or other documentation, and interview responsible personnel at the storage location(s) to verify that the storage location’s security is reviewed at least once every 12 months.

The obligation that entities most often assume the contract discharges. Storing media with a vendor does not transfer this: 9.4.1.1 asks that the location is secure, and this asks that you reviewed it, annually, and can show the review. 9.4.1.2.b examines procedures, logs and other documentation and interviews responsible personnel at the storage location, so a review conducted entirely from your own desk with no contact at the site is thin. What a review looks like varies reasonably: a site visit, an examination of the vendor's current certification or audit report, or a documented assessment against your own criteria. What it cannot be is nothing, and the most common finding is a location reviewed once at onboarding and never since.

What to prepare

  • The documented review procedure, stating the annual frequency.
  • The last review for each storage location, dated.
  • What the review examined, and against what criteria.
  • Vendor evidence relied on, with its date, since a certificate expires.

How to implement it

1. Schedule it with a fixed date. Annual reviews triggered by an approaching assessment are visible as such from the dates.

2. Decide in advance what evidence satisfies you. A current third-party audit report is usually proportionate for a commercial vault; a cupboard at a branch office needs someone to go and look.

3. Check the vendor evidence is current. Relying on a certification that lapsed is a review that concluded nothing.

4. Give it an owner in the 9.1.2 matrix. It is an annual task with no natural home, which is exactly the kind that goes unperformed.

Where this commonly fails

  • Reviewed at onboarding and never again, on the assumption the contract covers it.
  • A vendor certificate accepted without checking whether it is still in date.
  • Only the primary vault reviewed, while secondary or interim locations are not.
  • The review performed and not documented, leaving 9.4.1.2.b nothing to examine.

Others in section 9.4:

Control What it requires
9.4.1 All media with cardholder data is physically secured
9.4.1.1 Offline media backups with cardholder data are stored in a secure location
9.4.2 All media with cardholder data is classified in accordance with the sensitivity of the data
9.4.3 Media with cardholder data sent outside the facility is secured…
9.4.4 Management approves all media with cardholder data that is moved outside the facility…
9.4.5 Inventory logs of all electronic media with cardholder data are maintained
9.4.5.1 Inventories of electronic media with cardholder data are conducted at least once every 12 months
9.4.6 Hard-copy materials with cardholder data are destroyed when no longer needed for business…
9.4.7 Electronic media with cardholder data is destroyed when no longer needed for business or legal…

9.4.1.1 · All controls · 9.4.2

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.