5.4 Anti-phishing mechanisms protect users
How to meet it
Deploy technical anti-phishing controls (e.g. email filtering) alongside awareness training.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 5.4, in plain English.
5.4.1Processes and automated mechanisms detect and protect personnel against phishing attacks.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Security awareness and training policyUse for ISO 27001 A.6.3, SOC 2 Security awareness criteria, and PCI DSS requirement 12.6 training obligations.Acceptable use policyUse for ISO 27001 A.5.10, A.6.3, A.6.4, endpoint controls, remote work, and SOC 2 Security awareness.Email and communications security policyUse for ISO 27001 A.5.14 and A.8.24, information transfer, encryption in transit, phishing response, and SOC 2 communication controls.Malware protection policyUse for ISO 27001 A.8.7, SOC 2 Security, and PCI DSS requirement 5 anti-malware controls.
Open the control-to-policy mapBack to Requirement 5, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.