EvidenceSheet

9.2.1.1 Individual physical access to sensitive areas within the CDE is monitored with either video cameras or physical access control mechanisms (or both) as follows: • Entry and exit points to/from sensitive areas within the

Individual physical access to sensitive areas within the CDE is monitored with either video cameras or physical access control mechanisms (or both) as follows: • Entry and exit points to/from sensitive areas within the.

5
artefacts
1
held by a system
3
at each review
hard
to go live
Physical access / facilities
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Evidence the monitoring devices or mechanisms are protected from tampering or disabling · Physical access / facilities

periodic reviewEvidence produced at each review

  • Evidence both entry and exit points are monitored · Physical access / facilities
  • Retention evidence showing collected data is stored for at least three months unless otherwise restricted by law · Physical access / facilities
  • Review evidence showing collected data is correlated with other entries · Physical access / facilities

governing documentDocuments that govern the control

  • Observation of the locations where individual physical access to sensitive areas within the cardholder data environment occurs, showing video cameras or physical access control mechanisms at entry and exit points · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Physical access / facilities on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

9.2.1 Appropriate facility entry controls are in place to restrict physical access to systems in the CDE · 9.2.2 Physical and/or logical controls are implemented to restrict use of publicly accessible network jacks within the facility