PCI DSS 9.5.1.1: An up-to-date list of POI devices is maintained

PCI DSS v4.0.1 control 9.5.1.1: the requirement in full, the 3 testing procedures an assessor uses to verify it, and the related controls in section 9.5.

Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.5

An up-to-date list of POI devices is maintained, including:

  • Make and model of the device.
  • Location of device.
  • Device serial number or other methods of unique identification.

Summary

Keep an accurate list of every card-reading device: make, model, location and serial number.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
9.5.1.1.a Examine the list of POI devices to verify it includes all elements specified in this requirement.
9.5.1.1.b Observe POI devices and device locations and compare to devices in the list to verify that the list is accurate and up to date.
9.5.1.1.c Interview personnel to verify the list of POI devices is updated when devices are added, relocated, decommissioned, etc.

The inventory half of 9.5.1, and the reason it needs a serial number is the attack it defends against. A skimmer is often not an attachment but a substitution: an identical-looking terminal swapped for the real one. Make, model and location cannot detect that. The serial number can, which is why it is a named element. Procedure 9.5.1.1.b is the one that decides this control: the assessor observes the devices and compares them to the list, so the list has to be right on the day rather than right when it was written. 9.5.1.1.c then interviews personnel about updating it when devices are added, relocated or decommissioned.

What to prepare

  • The device list with all three elements populated for every device.
  • Physical access to the devices, since the list is compared against them.
  • The process for updating it on add, move and decommission, with a recent example.
  • Coverage of every location, including any device held as a spare.

How to implement it

1. Record the serial number and check it, not just record it. It is the only field that detects a substituted device, and it is useless unless someone compares it during the inspection under 9.5.1.2.

2. Include spares and devices in transit. A terminal in a cupboard is a terminal someone can tamper with before it is deployed.

3. Tie updates to the deployment process. A list maintained separately from the process that moves devices will disagree with reality within a quarter.

4. Make location specific enough to find the device. "Store 14" is weaker than the lane or counter, and the inspection depends on knowing where to look.

Where this commonly fails

  • Serial numbers missing, leaving substitution undetectable.
  • The list accurate at the last audit and wrong now, which 9.5.1.1.b is designed to find.
  • Spare and decommissioned devices excluded.
  • Devices relocated between sites with no update, so both lists are wrong.

Others in section 9.5:

Control What it requires
9.5.1 POI devices that capture payment card data via direct physical interaction with the payment…
9.5.1.2 POI device surfaces are periodically inspected to detect tampering and unauthorized substitution
9.5.1.3 Training is provided for personnel in POI environments to be aware of attempted tampering…

9.5.1 · All controls · 9.5.1.2

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.