5.3 Anti-malware mechanisms are active and monitored
How to meet it
Keep engines current, run periodic scans, and prevent users from disabling them.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 5.3, in plain English.
5.3.1The anti-malware solution is kept current through automatic updates.
5.3.2The solution runs periodic/active or real-time scans, or performs continuous behavioural analysis.
5.3.2.1When periodic scans are used, their frequency is defined in the targeted risk analysis.
5.3.3For removable electronic media, the solution scans on insertion/connection or performs continuous behavioural analysis.
5.3.4Audit logs for the anti-malware solution are enabled and retained.
5.3.5Anti-malware mechanisms cannot be disabled or altered by users unless documented and authorized by management for a limited time.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.Logging and monitoring policyUse for ISO 27001 A.8.15, A.8.16, A.8.17, SOC 2 Security, and PCI DSS requirements 10 and 11.Malware protection policyUse for ISO 27001 A.8.7, SOC 2 Security, and PCI DSS requirement 5 anti-malware controls.Vulnerability and patch management policyUse for ISO 27001 A.8.8, A.8.19, A.8.32, SOC 2 Security, and PCI DSS requirements 6 and 11.
Open the control-to-policy mapBack to Requirement 5, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.