PCI DSS 4.0
Req 5: Anti-Malware

PCI DSS 4.0 5.2.3: 5.2.3 Periodic evaluation of components not at risk from malware

Any system components treated as not at risk from malware must be evaluated on a periodic basis, and the evaluation must include: a documented list of every system component considered not at risk; identification and assessment of evolving malware threats relevant to those components; and confirmation of whether those components still do not need anti-malware protection. Determinations should be supported by vendor resources, best practice and evidence from industry, and malware trends should be fed into the vulnerability identification work under Requirement 6.3.1. Applicability: covers the components on which no anti-malware solution is deployed under Requirement 5.2.1. Objective under the customized approach: the entity stays aware of changing malware threats so that systems left without malware protection are not exposed to infection.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 39 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 6 controls

  • CA-7 Continuous Monitoring
  • CM-7 Least Functionality
  • CM-7(5) Authorized Software Allow-by-Exception
  • CM-8 System Component Inventory
  • RA-3 Risk Assessment
  • SI-3 Malicious Code Protection

FedRAMP Moderate · 6 controls

  • CA-7 Continuous Monitoring
  • CM-7 Least Functionality
  • CM-7(5) Authorized Software Allow-by-Exception
  • CM-8 System Component Inventory
  • RA-3 Risk Assessment
  • SI-3 Malicious Code Protection
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained
  • NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization

ISO 27002:2022 · 4 controls

  • 5.35 Independent review of information security
  • 5.9 Inventory of information and other associated assets
  • 8.7 Protection against malware
  • 8.8 Management of technical vulnerabilities

NIST SP 800-53 Rev 5 · 4 controls

CIS Controls v8 · 2 controls

  • CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory
  • CIS-10.1 Deploy and Maintain Anti-Malware Software

HIPAA Security Rule · 2 controls

ISO 22301:2019 · 2 controls

  • 7.5.3 Control of documented information
  • 8.2.3 Risk assessment

NIST SP 800-66 Rev 2 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies

C5 (Germany) · 1 control

  • C5-OPS-04 Protection Against Malware - Concept
  • CCM-TVM-02 Malware Protection Policy and Procedures

ISO 27001:2022 · 1 control

  • 8.7 Protection against malware

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 5: Anti-Malware

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 5.2.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 39 it maps to, and the evidence behind each claim, over MCP and REST.