Skip to main content

💼 9.5.1 POI devices that capture payment card data via direct physical interaction with the payment card form factor are protected from tampering and unauthorized substitution.

  • ID: /frameworks/pci-dss-v4.0/09/05/01

Description

Including the following:

  • Maintaining a list of POI devices.
  • Periodically inspecting POI devices to look for tampering or unauthorized substitution.
  • Training personnel to be aware of suspicious behavior and to report tampering or unauthorized substitution of devices.

Similar

  • Sections
    • /frameworks/pci-dss-v3.2.1/09/09
    • /frameworks/pci-dss-v4.0.1/09/05/01
  • Internal
    • ID: dec-c-5b1269ea

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 PCI DSS v3.2.1 → 💼 9.9 Protect devices that capture payment card data via direct physical interaction with the card from tampering and substitution.31no data
💼 PCI DSS v4.0.1 → 💼 9.5.1 POI devices that capture payment card data via direct physical interaction with the payment card form factor are protected from tampering and unauthorized substitution.31no data

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 PCI DSS v3.2.1 → 💼 9.9 Protect devices that capture payment card data via direct physical interaction with the card from tampering and substitution.31no data
💼 PCI DSS v4.0.1 → 💼 9.5.1 POI devices that capture payment card data via direct physical interaction with the payment card form factor are protected from tampering and unauthorized substitution.31no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 9.5.1.1 An up-to-date list of POI devices is maintained.1no data
💼 9.5.1.2 POI device surfaces are periodically inspected to detect tampering and unauthorized substitution.1no data
 💼 9.5.1.2.1 The frequency of periodic POI device inspections and the type of inspections performed is defined in the entity's targeted risk analysis.no data
💼 9.5.1.3 Training is provided for personnel in POI environments to be aware of attempted tampering or replacement of POI devices.no data

Policies (1)

PolicyLogic CountFlagsCompliance
🛡️ Google Cloud Asset Inventory API is not enabled🟢1🟢 x6no data