Skip to main content

πŸ’Ό 9.4 Implement procedures to identify and authorize visitors.

Description​

Empty...

Similar​

  • Sections
    • /frameworks/pci-dss-v4.0/09/03/02
  • Internal
    • ID: dec-c-83d6521c

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 9.3.2 Procedures are implemented for authorizing and managing visitor access to the CDE.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 9.3.2 Procedures are implemented for authorizing and managing visitor access to the CDE.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό 9.4.1 Visitors are authorized before entering, and escorted at all times within, areas where cardholder data is processed or maintained.
πŸ’Ό 9.4.2 Visitors are identified and given a badge or other identification that expires and that visibly distinguishes the visitors from onsite personnel.
πŸ’Ό 9.4.3 Visitors are asked to surrender the badge or identification before leaving the facility or at the date of expiration.
πŸ’Ό 9.4.4 A visitor log is used to maintain a physical audit trail of visitor activity to the facility as well as computer rooms and data centers where cardholder data is stored or transmitted.