Individual physical entry into sensitive areas within the CDE must be monitored by video cameras, physical access control mechanisms, or both, such that: all points of entry to and exit from these sensitive areas are covered; the cameras or access mechanisms are shielded against tampering or being disabled; the collected data is reviewed and matched against other entry records; and the data is kept for at least three months where the law permits. The guidance suggests, for example, placing cameras out of reach or monitoring them to detect tampering, and says the chosen mechanism should cover every entry and exit point. Applicability: all entities with sensitive areas inside the CDE. Objective under the customized approach: trustworthy, verifiable records exist of each person entering and leaving sensitive areas.
This control maps to 42 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
PCI DSS 4.0 9.2.1.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.
The graph holds this control, the 42 it maps to, and the evidence behind each claim, over MCP and REST.