r9.1 Inherit AWS physical controls through the compliance reports
On AWS, the physical security of the data centers is AWS's responsibility under the shared responsibility model. The customer inherits these controls and evidences them with the AWS PCI DSS AOC obtained via AWS Artifact.
AWS services
Requirement 9
Restrict Physical Access to Cardholder Data
PCI sub-requirements covered
- 9.2 Physical access controls manage entry into facilities and systems
- 9.3 Physical access for personnel and visitors is authorized and managed
How to implement on AWS
Download the AWS PCI DSS Attestation of Compliance (AOC) and the customer responsibilities from AWS Artifact. Document in the shared responsibility matrix which physical sub-requirements AWS covers. Keep these documents current as evidence for the assessor.
Practical implementation
How this control is implemented in each reference architecture:
Physical security of the AWS facilities is AWS's responsibility. Download the AWS PCI DSS AOC from AWS Artifact and record in your shared responsibility matrix that Requirement 9.2/9.3 is inherited from AWS.
Single-account, 3-tier →Same inheritance applies; capture it once at the organization level. Use AWS Artifact (organization agreements) and keep a single shared responsibility matrix covering all CDE accounts under the PCI OU.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Observe entry controls and physical access controls to verify that access to systems in the CDE is restricted, and that entry/exit points of sensitive areas are monitored and the recordings retained (9.2.1, 9.2.1.1.a, 9.2.1.1.c).
- Examine procedures for authorizing and managing physical access of personnel and visitors to the CDE (9.3.1.a, 9.3.2.a). On AWS, these controls are inherited from AWS under the shared responsibility model and evidenced via the AWS PCI DSS AOC.
Evidence in AWS
- AWS PCI DSS AOC downloaded from AWS Artifact (current).
- Shared responsibility matrix documenting the physical controls covered by AWS.
- AWS customer responsibilities guide for PCI DSS.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 9.2 — System components in the CDE cannot be physically accessed by unauthorized personnel.
- 9.3 — Requirements for access to the physical CDE are defined and enforced to identify and authorize personnel.
Learning resources
- AWS Artifact (doc)
- Shared Responsibility Model (doc)
References
- PCI DSS v4.0.1 Requirement 9.2, 9.3 (AWS responsibility)
PCI DSS Security Maturity Model