PCI DSS 4.0
Req 9: Restrict Physical Access

PCI DSS 4.0 9.4.1.1: 9.4.1.1 Secure storage location for offline backups

Offline media backups that contain cardholder data must be kept in a secure location. The guidance describes off-site storage, for instance at a commercial storage provider or an alternate or backup site, as good practice, and notes that backups in a non-secured facility could be lost, stolen or copied. Applicability: entities keeping offline backups with cardholder data. Customized approach objective: unauthorized personnel cannot reach offline backups by unauthorized personnel.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 47 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 6 controls

ISO 27001:2022 · 5 controls

  • 5.35 Independent review of information security
  • 7.10 Storage media
  • 7.8 Equipment siting and protection
  • 7.9 Security of assets off-premises
  • 8.13 Information backup

SOC 2 · 5 controls

  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets

ISO 27701:2019 · 4 controls

FedRAMP High · 3 controls

  • CP-6 Alternate Storage Site
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • MP-4 Media Storage

FedRAMP Moderate · 3 controls

  • CP-6 Alternate Storage Site
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • MP-4 Media Storage

ISO 27002:2022 · 3 controls

  • 7.10 Storage media
  • 7.9 Security of assets off-premises
  • 8.13 Information backup

CIS Controls v8 · 2 controls

  • CIS-11.3 Protect Recovery Data
  • CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data

CMMC 2.0 · 2 controls

HIPAA Security Rule · 2 controls

ISO 22301:2019 · 2 controls

  • 7.5.3 Control of documented information
  • 8.3.5 Implementation of solutions

NIST SP 800-66 Rev 2 · 2 controls

  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components

C5 (Germany) · 1 control

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 9: Restrict Physical Access

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 9.4.1.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 47 it maps to, and the evidence behind each claim, over MCP and REST.