PCIDSS.COM - PCI DSS Security Solutions Directory

Category: PCI DSS Requirement 5

Protect all systems against malware and regularly update anti-virus software or programs.
PCI DSS Requirement 5 relates to Anti-Virus programs, which have been available for many years and are a well established server or workstation protection mechanism. Anti-virus applications typically protect systems from virus, worms, trojan horses and these are typically known collectively as malware. From a PCI DSS perspective, systems within the Cardholder Data Environment must utilize anti-virus. This includes, servers, workstations, laptops, virtual servers through any access vector such as network shares, USB, e-mail, instant messaging etc. to name but a few. There is an evolving need for anti-malware programs, detecting anomalous activities or Indicators of Compromise (IoC) but these solutions should be carefully reviewed to ensure they provide adequate anti-virus capability otherwise they should be utilised in conjunction with each other.

