Payments and IT

PCI DSS Requirement 9: visitor controls for offices and server rooms

PCI DSS is usually discussed as a network standard, but Requirement 9 covers the physical side, and it is unusually direct about visitors. If any room at your site stores or processes cardholder data, these controls apply to the door as much as the firewall.

Requirement 9 exists because physical access defeats logical controls. Someone standing in front of a server has options that no amount of network segmentation prevents.

What the visitor log must record

The log needs the visitor's name, the firm they represent, and the onsite personnel authorising physical access. That third field is the one most paper books omit, and it is the one that makes the record useful: it ties every visit to an employee who accepted responsibility for it.

Retention is at least three months, unless another law or your own policy requires longer. The log must be kept for sensitive areas specifically, which for most organisations means the server room rather than the whole building.

How badges must behave

  • Visitor badges must be visually distinguishable from those issued to personnel. An assessor will look at both and expect to tell them apart across a lobby.
  • Badges must have an expiry. A badge that works indefinitely is an access credential, not a visitor pass.
  • Badges must be surrendered or deactivated on departure or expiry. This is where most programmes fail: issuing is controlled, returning is not.
  • Visitors must be authorised before entering and escorted at all times within sensitive areas.

What assessors actually test

Not the policy document. They look for the log covering the assessment period, check it is complete rather than sporadic, and sample entries against other evidence. Gaps are the finding. A visitor book with three weeks missing tells the assessor the control is not operating, which is worse than a short retention window.

The same logic runs through SOC 2 CC6.4 and ISO 27001 Annex A 7.2. Neither prescribes fields, but a Type II report tests whether your stated procedure operated consistently across the whole period. Consistency is the control.

Where BeckonDesk fits

The visit record carries visitor name, company and host, which maps to the three fields Requirement 9 asks for, with check-in and check-out timestamps and a badge number. Retention is configurable per tenant, so three months can be set explicitly. Badges are printed per visitor type with a validity window, so a visitor badge and a contractor badge are distinguishable at a glance.

Escorting within sensitive areas is a procedural control that BeckonDesk does not track today, so if your assessor expects escort records, that part stays with your process.

Related reading

See it on your own site.

A 30-minute walkthrough of sign-in, screening, and the record an auditor asks for. 30-day free trial, no credit card.

Get started Book a demo