Protect against malicious software
Requirement 5 requires the deployment and maintenance of anti-malware solutions across all applicable system components to detect, prevent, and remove malicious software. Organizations must ensure these tools are actively running, kept up to date, and configured to alert security personnel when threats are identified.
What it means
The primary intent is to protect the Cardholder Data Environment (CDE) from malware—such as viruses, worms, trojans, and ransomware—that could be used to steal cardholder data or compromise system integrity. This applies to all systems that can store, process, or transmit account data, provided they are capable of running anti-malware software.
In practice, this is not a "set it and forget it" installation. It requires continuous operational oversight to ensure the software remains active and signatures are current. The focus in v4.0 is on ensuring that protection is persistent rather than relying solely on periodic manual scans.
For systems where anti-malware cannot be installed due to technical constraints (such as certain legacy systems or specialized appliances), the organization must document these exceptions and implement alternative security controls to mitigate the risk of malware infection.
How to meet it
- Deploy an industry-standard anti-malware solution (e.g., AV, EDR, or XDR) on all applicable system components within the CDE.
- Configure the software to perform continuous or real-time scanning and detection rather than relying only on scheduled scans.
- Enable automatic updates for malware signatures and engine definitions to ensure protection against the latest threats.
- Restrict administrative access to anti-malware settings so that unauthorized users or malicious processes cannot disable the software.
- Implement a centralized alerting mechanism that notifies security administrators immediately when a threat is detected or if a system stops reporting.
- Create a formal inventory of systems where anti-malware is not installed, including a technical justification and a description of compensating controls for each.
Evidence an auditor asks for
- A complete asset inventory showing that all CDE components are covered by the active anti-malware solution.
- Configuration screenshots or policy exports proving that real-time scanning and automatic updates are enabled globally.
- Sample logs or reports demonstrating that malware scans have been performed and any detected threats were remediated.
- An access control list (ACL) showing who has administrative permissions to modify the security software.
- Documented justifications for any systems exempt from anti-malware installation, including a risk analysis of those exemptions.
Common pitfalls
- Installing the agent but failing to configure "active" or "real-time" protection, which is a common cause of failure during audits.
- Neglecting to monitor update failures, leading to endpoints with severely outdated signatures.
- Failing to document why certain systems do not run anti-malware, treating them as "invisible" rather than documented exceptions.
- Overlooking the need to protect the security software itself from being disabled by a local administrator account.