PCI DSS 9.5.1.2: POI device surfaces are periodically inspected to detect tampering and unauthorized substitution
PCI DSS v4.0.1 control 9.5.1.2: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 9.5.
Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.5
POI device surfaces are periodically inspected to detect tampering and unauthorized substitution.
Summary
Look at the card readers regularly for signs that one has been tampered with or swapped.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 9.5.1.2.a | Examine documented procedures to verify processes are defined for periodic inspections of POI device surfaces to detect tampering and unauthorized substitution. |
| 9.5.1.2.b | Interview responsible personnel and observe inspection processes to verify: • Personnel are aware of procedures for inspecting devices. • All devices are periodically inspected for evidence of tampering and unauthorized substitution. |
The inspection half of 9.5.1. Note what the requirement does not say: it does not set a frequency, only "periodically", which the entity defines. Procedure 9.5.1.2.b interviews personnel and observes the inspection process, checking both that personnel are aware of the procedures and that all devices are inspected, so the two failures are inspecting some devices well and inspecting all of them nominally. The inspection is only as good as its reference: it depends on the list in 9.5.1.1, and specifically on comparing the serial number, since a substituted terminal looks correct in every other respect.
What to prepare
- The documented inspection procedure, including what to look for and how often.
- Inspection records covering every device, not a sample.
- The device list used as the reference during inspection.
- The people who perform it, available to be interviewed and observed.
How to implement it
1. Check the serial against the list every time. Attachments are visible; substitution is not, and the serial is the only thing that catches it.
2. Give inspectors a photograph of the correct device. Comparing against a known-good image finds an altered casing far more reliably than remembering what it looked like.
3. Set a frequency you can evidence for every device. The standard leaves the interval to you, so the number matters less than covering all devices at it.
4. Record the negative results. "Inspected, no anomalies" per device per cycle is the evidence; an inspection that only produces records when something is wrong looks identical to no inspection.
Where this commonly fails
- Inspections performed and not recorded, so there is nothing for the procedure to examine.
- Serial numbers never compared, so the inspection detects attachments and misses substitutions.
- A sample of devices inspected rather than all of them.
- Inspection by staff who were never told what tampering looks like, which the interview surfaces.
Related controls
Others in section 9.5:
| Control | What it requires |
|---|---|
| 9.5.1 | POI devices that capture payment card data via direct physical interaction with the payment… |
| 9.5.1.1 | An up-to-date list of POI devices is maintained… |
| 9.5.1.3 | Training is provided for personnel in POI environments to be aware of attempted tampering… |
← 9.5.1.1 · All controls · 9.5.1.3 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.