← PCI DSS 4.0.1 · Req 9 — Physical access
9.5 — Point-of-interaction devices are protected from tampering
Requirement
Point-of-interaction devices that capture card data by direct physical interaction are listed, periodically inspected for tampering or substitution, and personnel are trained to recognise attempted tampering and to verify the identity of anyone claiming to service the devices.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| GDPR | Art.5(1)(d) | Accuracy | integrity |
| GDPR | Art.16 | Right to rectification | integrity |
| CCPA/CPRA | 1798.106 | Right to correct | integrity |
| SOC 2 | CC6.4 | Physical access to facilities | physical-security |
| SOC 2 | PI1.1 | Quality information about processing objectives and specifications | integrity |
| ISO 27001 | A.7.1 | Physical security perimeters | physical-security |
| ISO 27001 | A.7.4 | Physical security monitoring | physical-security |
| ISO 27001 | A.7.9 | Security of assets off-premises | physical-security |