PCI DSS 4.0
Req 5: Anti-Malware

PCI DSS 4.0 5.4.1: 5.4.1 Mechanisms detect and protect against phishing

The entity must have processes and automated mechanisms that detect phishing attacks and protect personnel from them. A combination of approaches is encouraged, for example anti-spoofing controls (DMARC, SPF, DKIM), link scrubbing and server-side anti-malware that block phishing messages before delivery, and training personnel to spot and report phishing; applying the controls across the whole organisation is recommended but not required. Applicability: the emphasis is on protecting staff who can access in-scope PCI DSS system components. Technical anti-phishing controls under this requirement are separate from security awareness training under Requirement 12.6.3.1; meeting one does not satisfy the other. This was advisory only up to 31 March 2025 and is now required and fully assessed. Objective under the customized approach: mechanisms exist that protect against, and reduce the risk from, phishing attacks. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 47 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 5 controls

  • CIS-14.2 Train Workforce Members to Recognize Social Engineering Attacks
  • CIS-9.2 Use DNS Filtering Services
  • CIS-9.3 Maintain and Enforce Network-Based URL Filters
  • CIS-9.5 Implement DMARC
  • CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections

ISO 27002:2022 · 5 controls

  • 5.7 Threat intelligence
  • 6.3 Information security awareness, education and training
  • 6.7 Remote working
  • 8.23 Web filtering
  • 8.7 Protection against malware
  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-RS.MA-02 Incident reports are triaged and validated
  • ASD37-05 Automated dynamic analysis of email and web content (Excellent)
  • ASD37-06 Email content filtering (Excellent)
  • ASD37-14 Block spoofed emails (Very Good)
  • ASD37-15 User education (Limited)

CMMC 2.0 · 4 controls

ISO 27001:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation 
  • 6.3 Information security awareness, education and training
  • 8.23 Web filtering
  • 8.7 Protection against malware

NIST SP 800-53 Rev 5 · 4 controls

SOC 2 · 4 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies

FedRAMP High · 2 controls

  • AT-2(3) Social Engineering and Mining
  • SI-8 Spam Protection

FedRAMP Moderate · 2 controls

  • AT-2(3) Social Engineering and Mining
  • SI-8 Spam Protection
  • E8-MACRO-ML1 Configure Microsoft Office Macro Settings (ML1)
  • AUCDR-IS-5 Limit, prevent, detect and remove malware
  • IM-6 Use strong authentication controls

ISO 27701:2019 · 1 control

  • 6.9.2 Protection from malware
  • 03.02.01 Literacy Training and Awareness

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 5: Anti-Malware

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 5.4.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 47 it maps to, and the evidence behind each claim, over MCP and REST.