PCI DSS 5.3.3: For removable electronic media, the anti-malware solution(s)
PCI DSS v4.0.1 control 5.3.3: the requirement in full, the 3 testing procedures an assessor uses to verify it, and the related controls in section 5.3.
Requirement 5: Protect All Systems and Networks from Malicious Software › Section 5.3
For removable electronic media, the anti-malware solution(s):
- Performs automatic scans of when the media is inserted, connected, or logically mounted, OR
- Performs continuous behavioral analysis of systems or processes when the media is inserted, connected, or logically mounted.
Summary
Removable media is scanned automatically when it is connected, or covered by continuous behavioural analysis.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 5.3.3.a | Examine anti-malware solution(s) configurations to verify that, for removable electronic media, the solution is configured to perform at least one of the elements specified in this requirement. |
| 5.3.3.b | Examine system components with removable electronic media connected to verify that the solution(s) is enabled in accordance with at least one of the elements as specified in this requirement. |
| 5.3.3.c | Examine logs and scan results to verify that the solution(s) is enabled in accordance with at least one of the elements specified in this requirement. |
The one part of Requirement 5 about a threat that walks in through the door. Two alternatives, either of which satisfies it: automatic scans on insertion, connection or logical mount, or continuous behavioural analysis of systems and processes when media is attached. The word doing the work is automatic: a scan a user can decline is not one. Where an entity has concluded some systems are not at risk under 5.2.3, that evaluation should say something about removable media specifically, because a platform rarely targeted by malware can still carry it to one that is.
What to prepare
- The configuration showing scan-on-mount enabled, or the behavioural alternative in place.
- Evidence it cannot be declined by the user.
- The policy on removable media use, and where it is prohibited outright.
How to implement it
1. Prohibit first, scan second. The cheapest way to satisfy this is that removable media cannot be mounted on in-scope systems at all, which is a configuration rather than an ongoing control.
2. Cover every mount type. USB is the obvious one; optical media, SD cards, phones mounting as storage and network-attached removable volumes are all in scope.
3. Verify the scan actually runs. Scan-on-insertion is frequently enabled in policy and disabled by an exclusion added for performance, and the only way to know is to insert something.
4. Do not rely on the user. A prompt offering to scan is not automatic, and it is the configuration an assessor will look for.
Where this commonly fails
- Scan-on-insertion enabled with an exclusion that quietly disables it.
- A user-dismissable prompt treated as an automatic scan.
- Policy prohibiting removable media with nothing enforcing it technically.
- Systems excluded under 5.2.3 without the evaluation considering media-borne malware.
Related controls
Others in section 5.3:
| Control | What it requires |
|---|---|
| 5.3.1 | The anti-malware solution(s) is kept current via automatic updates |
| 5.3.2 | The anti-malware solution(s)… |
| 5.3.2.1 | If periodic malware scans are performed to meet Requirement 5.3.2… |
| 5.3.4 | Audit logs for the anti-malware solution(s) are enabled and retained in accordance… |
| 5.3.5 | Anti-malware mechanisms cannot be disabled or altered by users, unless specifically documented… |
← 5.3.2.1 · All controls · 5.3.4 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.