PCI DSS 4.0
Req 9: Restrict Physical Access

PCI DSS 4.0 9.4.3: 9.4.3 Securing media sent outside the facility

Media with cardholder data that is sent outside the facility must be protected as follows: each shipment of media is logged; media travels by secured courier or by another delivery method whose progress can be tracked accurately; and off-site tracking logs record details of where the media is. The guidance explains that a trackable courier lets the organization keep an inventory and location of shipments, whereas ordinary post cannot be tracked. Applicability: all entities that send media off site. Customized approach objective: while in transit beyond the facility, media stays protected and traceable.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 41 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CMMC 2.0 · 4 controls

FedRAMP High · 4 controls

  • AC-20(2) Portable Storage Devices Restricted Use
  • MP-5 Media Transport
  • PE-16 Delivery and Removal
  • PE-5 Access Control for Output Devices (PE-5)

FedRAMP Moderate · 4 controls

  • AC-20(2) Portable Storage Devices Restricted Use
  • MP-5 Media Transport
  • PE-16 Delivery and Removal
  • PE-5 Access Control for Output Devices (PE-5)

ISO 27701:2019 · 4 controls

  • 6.10.2 Information transfer
  • 6.5.3 Media handling
  • 7.4.9 PII transmission controls
  • 8.4.3 PII transmission controls

CIS Controls v8 · 3 controls

  • CIS-14.4 Train Workforce on Data Handling Best Practices
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-3.9 Encrypt Data on Removable Media

ISO 27001:2022 · 3 controls

  • 5.14 Information transfer
  • 7.10 Storage media
  • 7.9 Security of assets off-premises

ISO 27002:2022 · 3 controls

  • 5.14 Information transfer
  • 7.10 Storage media
  • 7.9 Security of assets off-premises

SOC 2 · 3 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • CCM-DCS-02 Off-Site Transfer Authorization Policy and Procedures
  • CCM-DCS-04 Secure Media Transportation Policy and Procedures

HIPAA Security Rule · 2 controls

  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected

NIST SP 800-53 Rev 5 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

C5 (Germany) · 1 control

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 9: Restrict Physical Access

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 9.4.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 41 it maps to, and the evidence behind each claim, over MCP and REST.