Requirement 5: Protect All Systems and Networks from Malicious Software
Malicious software (malware) is software or firmware designed to infiltrate or damage a computer system without the owner's knowledge or consent. Examples include viruses, worms, Trojans, spyware, ransomware, keyloggers, and rootkits, malicious code, scripts, and links.
Anti-malware protection must be deployed on all system components, except for any component covered by a documented periodic evaluation concluding that component is not at risk from malware (Requirement 5.2.3) — being a Linux system is not itself an exemption. This includes both Windows and Linux systems. Anti-malware software must be capable of detecting, protecting against, and removing all types of malicious software, using either traditional signature-based scanning or continuous behavioral analysis (Requirement 5.3.2). Signatures must be updated regularly, and scans must be performed periodically. Logs from anti-malware software must be collected and stored according to requirement 10. Removable media (such as USB drives) must be scanned for malware when inserted or connected, or covered by continuous behavioral analysis (Requirement 5.3.3). Anti-phishing processes and technical mechanisms must also be in place to protect personnel against phishing attacks (Requirement 5.4.1).
Only administrative users should be able to disable or change the configuration of antivirus software.
Go on to Requirement 6 - Secure Systems.
Go back to Requirement 4 - Data Encryption.