PCI DSS 4.0 9.4.3: 9.4.3 Securing media sent outside the facility
Media with cardholder data that is sent outside the facility must be protected as follows: each shipment of media is logged; media travels by secured courier or by another delivery method whose progress can be tracked accurately; and off-site tracking logs record details of where the media is. The guidance explains that a trackable courier lets the organization keep an inventory and location of shipments, whereas ordinary post cannot be tracked. Applicability: all entities that send media off site. Customized approach objective: while in transit beyond the facility, media stays protected and traceable.
This control maps to 41 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 9.4.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.