Skip to main content

💼 9.3.4 A visitor log is used to maintain a physical record of visitor activity within the facility and within sensitive areas.

Description​

Including:

  • The visitor's name and the organization represented.
  • The date and time of the visit.
  • The name of the personnel authorizing physical access.
  • Retaining the log for at least three months, unless otherwise restricted by law.

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/09/04/04
    • /frameworks/pci-dss-v4.0.1/09/03/04
  • Internal
    • ID: dec-c-24f07e6c

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v3.2.1 → 💼 9.4.4 A visitor log is used to maintain a physical audit trail of visitor activity to the facility as well as computer rooms and data centers where cardholder data is stored or transmitted.
💼 PCI DSS v4.0.1 → 💼 9.3.4 A visitor log is used to maintain a physical record of visitor activity within the facility and within sensitive areas.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v3.2.1 → 💼 9.4.4 A visitor log is used to maintain a physical audit trail of visitor activity to the facility as well as computer rooms and data centers where cardholder data is stored or transmitted.
💼 PCI DSS v4.0.1 → 💼 9.3.4 A visitor log is used to maintain a physical record of visitor activity within the facility and within sensitive areas.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags