PCI_DSS_v4Requirement 9voice-validated
PCI_DSS_v4 R9: Requirement 9
PCI_DSS_v4
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Any physical access to data or systems that store, process, or transmit cardholder data provides the opportunity for individuals to access devices or data, and to remove systems or hardcopies, and should be appropriately restricted. Includes media handling, visitor controls, and destruction procedures.
ATT&CK techniques this article tests · 0
| Technique | Why it maps | Confidence |
|---|
Defending mitigations · 0
| Mitigation | What it does | Confidence |
|---|
Underlying weaknesses · 6
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-284 | 9.1.1, 9.1.2. Insufficient authorization for physical access allows unauthorized individuals to enter restricted areas, directly compromising the security of cardholder data. | 90% |
| CWE-287 | 9.1.3. Improper authentication of visitors or personnel at physical access points can lead to unauthorized entry, bypassing established security protocols. | 80% |
| CWE-532 | 9.1.4. Inadequate logging of physical access events (e.g., visitor logs, entry/exit records) hinders forensic analysis and accountability in the event of a physical breach. | 80% |
| CWE-732 | 9.1.1, 9.1.2. Incorrect permission assignment for physical access controls (e.g., access cards, keys) can grant access to individuals who should not have it, creating security gaps. | 80% |
| CWE-200 | 9.1.4. Exposure of sensitive information through improper media handling or inadequate destruction procedures allows unauthorized disclosure of cardholder data. | 70% |
| CWE-306 | 9.1.1, 9.1.2. Missing authentication for critical physical access points (e.g., server rooms, data centers) creates a direct vulnerability for unauthorized entry and data compromise. | 70% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0185 compute · voice-rubric self-validated