Skip to main content

๐Ÿ’ผ 9.4 Media with cardholder data is securely stored, accessed, distributed, and destroyed.

Descriptionโ€‹

Empty...

Similarโ€‹

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ 9.4.1 All media with cardholder data is physically secured.2
ย ย ย ย ๐Ÿ’ผ 9.4.1.1 Offline media backups with cardholder data are stored in a secure location.
ย ย ย ย ๐Ÿ’ผ 9.4.1.2 The security of the offline media backup location(s) with cardholder data is reviewed at least once every 12 months.
๐Ÿ’ผ 9.4.2 All media with cardholder data is classified in accordance with the sensitivity of the data.
๐Ÿ’ผ 9.4.3 Media with cardholder data sent outside the facility is secured.
๐Ÿ’ผ 9.4.4 Management approves all media with cardholder data that is moved outside the facility.
๐Ÿ’ผ 9.4.5 Inventory logs of all electronic media with cardholder data are maintained.1
ย ย ย ย ๐Ÿ’ผ 9.4.5.1 Inventories of electronic media with cardholder data are conducted at least once every 12 months.
๐Ÿ’ผ 9.4.6 Hard-copy materials with cardholder data are destroyed when no longer needed for business or legal reasons.
๐Ÿ’ผ 9.4.7 Electronic media with cardholder data is destroyed when no longer needed for business or legal reasons.