PCI DSS 4.0 5.4.1: 5.4.1 Mechanisms detect and protect against phishing
The entity must have processes and automated mechanisms that detect phishing attacks and protect personnel from them. A combination of approaches is encouraged, for example anti-spoofing controls (DMARC, SPF, DKIM), link scrubbing and server-side anti-malware that block phishing messages before delivery, and training personnel to spot and report phishing; applying the controls across the whole organisation is recommended but not required. Applicability: the emphasis is on protecting staff who can access in-scope PCI DSS system components. Technical anti-phishing controls under this requirement are separate from security awareness training under Requirement 12.6.3.1; meeting one does not satisfy the other. This was advisory only up to 31 March 2025 and is now required and fully assessed. Objective under the customized approach: mechanisms exist that protect against, and reduce the risk from, phishing attacks. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.
This control maps to 47 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 5.4.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.