PCI DSS Requirement 5 – Explained 

PCI DSS stands for Payment Card Industry Data Security Standard. It’s a set of globally recognised security requirements designed to ensure that businesses protect payment card data. This article focuses on Requirement 5 of PCI DSS v4.0.1 – what it means, how it’s evolved from version 3.2.1, and what your organisation needs to do to stay compliant. 

For more on PCI DSS, see our Ultimate Guide. 

What is PCI DSS Requirement 5?

Requirement 5: Protect all systems and networks from malicious software 

This requirement focuses on protecting all systems and networks from malware threats. This includes both traditional viruses and more advanced malicious software that can compromise the confidentiality, integrity, or availability of cardholder data. The requirement applies to all system components that are commonly affected by malicious software. 

The aim is to ensure that anti-malware solutions are implemented where applicable, regularly updated, actively running, and capable of generating audit logs. In environments where traditional anti-malware is not applicable, organisations must document and implement alternative risk mitigation controls to address malware threats. 

By proactively managing the risk of malware, organisations can reduce the likelihood of compromise and maintain a more resilient security posture. 

Why is Requirement 5 important? 

Malware remains one of the most common ways attackers gain access to sensitive systems and extract cardholder data. It can be introduced through: 

  • Phishing emails 
  • Compromised websites 
  • Infected USB drives 
  • Software vulnerabilities 

Once inside, malware can steal data, log keystrokes, or create backdoors for attackers. Effective anti-malware solutions help prevent these outcomes – reducing the risk of breach, loss, and financial penalties. 

What’s changed in PCI DSS v4.0.1? 

In PCI DSS v3.2.1, Requirement 5 was focused mainly on antivirus software. Version 4.0.1 updates this to reflect a broader, more complex threat landscape. Key updates include: 

  • Anti-malware solutions now replace “antivirus” – covering behaviour-based detection, machine learning, and other modern approaches 
  • Risk-based justification is required for systems where malware protection is not installed 
  • Remote access protections have been added to prevent copying or relocating cardholder data during remote sessions 
  • Customised implementation is available for organisations with strong risk management processes, allowing flexibility in how compliance is achieved 

A breakdown of Requirement 5 

5.1 – Processes and mechanisms for protecting all systems and networks from malicious software are defined and understood.

Organisations must define, document, and communicate the processes used to manage and mitigate malware threats. This includes assigning roles and responsibilities for anti-malware management, identifying systems that require protection, and ensuring relevant teams understand how controls are applied. These processes must be clearly established and consistently followed to support effective malware protection. 

5.2 – Malicious software (malware) is prevented, or detected and addressed.

Organisations must implement anti-malware solutions that are capable of detecting, blocking, and removing known types of malicious code. These solutions must be kept current, configured to actively run, and must  be configured so that end users cannot alter or disable the anti-malware protection.  Where users are permitted to disable mechanisms for legitimate reasons, strict controls must govern this access. These tools must be monitored and capable of generating audit logs. If anti-malware is not applicable to a system component, this must be supported by documented risk analysis and compensated for with alternative controls. 

5.3 – Anti-malware mechanisms and processes are active, maintained, and monitored.

Anti-malware mechanisms must be actively running on all systems commonly affected by malicious software, with configuration settings that ensure the software cannot be disabled or altered by users. These solutions must be continuously maintained, receiving regular updates and being monitored to confirm that they are functioning effectively. Audit logs generated by these tools must be retained and reviewed to detect and respond to potential incidents. 

5.4 – Anti-phishing mechanisms protect users against phishing attacks.

Organisations must implement anti-phishing controls to protect personnel against phishing attacks that could compromise credentials or enable unauthorised access. These controls may include email filtering, user education, and alert mechanisms. The goal is to ensure users can identify and avoid phishing attempts, supported by technology that helps detect and block malicious messages before they reach end users. 

Common challenges with Requirement 5 

Some of the most frequent problems we see include: 

  • Using outdated antivirus tools without modern threat detection 
  • Failing to document the rationale for excluding systems from protection 
  • Allowing users to disable or modify malware tools 
  • Infrequent scans or missed updates 
  • Assuming servers don’t need protection based on vendor claims

You should configure, manage, and review malware protection in line with your risk profile. 

How Securious Can Help 

Securious has been a PCI QSAC since 2016, with a team of qualified, highly experienced PCI DSS QSA and 3DS assessors ready to assist you in achieving and maintaining compliance with the latest PCI DSS standards. 

Based in Exeter, Devon, we undertake PCI QSA work both nationally and internationally. We are the only PCI DSS QSA company in our region, so organisations in Devon, Cornwall, or Somerset can benefit from cost efficiencies with on-site assessments. 

Our mission is to build cyber security confidence. When it comes to PCI DSS compliance, we collaborate with you to make the process as efficient as possible, helping you understand what needs to be done and why. 

We offer three options to assist our clients with PCI DSS compliance: 

  1. PCI DSS QSA Gap Analysis & Assessment (one-off fee)
    Read more about our PCI DSS QSA Gap Analysis & Assessment by clicking here.
  1. Managed PCI DSS Compliance Service (fixed monthly fee)
    Read more about our Managed PCI DSS Compliance Service by clicking here.
  1. Assisted PCI DSS SAQ Compliance Service (one-off fee)
    Read more about our Assisted PCI DSS SAQ Compliance Service by clicking here. 

Get in Touch to Get Started 

To learn more, visit our PCI services page, call us on 01392 247 110, email info@securious.co.uk, or send us a message using the form below. 

Find out whether you’re ready for PCI DSS v4.0.1 in minutes.