PCI DSS 5.3.5: Anti-malware mechanisms cannot be disabled or altered by users, unless specifically documented
PCI DSS v4.0.1 control 5.3.5: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 5.3.
Requirement 5: Protect All Systems and Networks from Malicious Software › Section 5.3
Anti-malware mechanisms cannot be disabled or altered by users, unless specifically documented, and authorized by management on a case-by-case basis for a limited time period.
Summary
Users cannot switch off the anti-malware, and any exception is documented, approved by management, and time-limited.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 5.3.5.a | Examine anti-malware configurations, to verify that the anti-malware mechanisms cannot be disabled or altered by users. |
| 5.3.5.b | Interview responsible personnel and observe processes to verify that any requests to disable or alter anti-malware mechanisms are specifically documented and authorized by management on a case-by-case basis for a limited time period. |
Three qualifiers on the exception and all three are tested: specifically documented, authorized by management, and for a limited time period. A permanent exclusion is not an exception under this control, it is a gap. The technical half usually comes down to one thing: if a user has local administrator rights they can generally stop the agent, so the control is met by the product's tamper protection rather than by permissions alone. 5.3.5.a examines the configuration for that, and 5.3.5.b interviews personnel and observes the process for handling requests. It pairs with 5.1.2, because a management authorisation cannot be evidenced if no role has been named to give it.
What to prepare
- Configuration showing tamper protection is enabled and users cannot disable the agent.
- The request and approval process, with the management role that approves.
- Current exceptions, each with a documented approval and an end date.
- Evidence that expired exceptions were actually removed.
How to implement it
1. Turn on tamper protection and set a password or equivalent. Removing local administrator rights is better practice and is not always achievable, and tamper protection covers the case where it is not.
2. Give every exception an expiry, enforced rather than noted. "Limited time period" is an element, and an exception that outlives its justification is the common finding.
3. Record the reason with the approval. 5.3.5.b observes the process, so the artefact needs to show what was approved and why, not just that something was.
4. Review the exclusion list against the approvals. Exclusions added directly in the console to fix a performance complaint are the ones with no approval behind them.
Where this commonly fails
- Local administrator rights with tamper protection off, so any user can stop the agent.
- Exclusions in the console with no corresponding documented approval.
- Exceptions granted with no end date, which fails the limited-time element.
- Expired exceptions never removed, so the list only ever grows.
Related controls
Others in section 5.3:
| Control | What it requires |
|---|---|
| 5.3.1 | The anti-malware solution(s) is kept current via automatic updates |
| 5.3.2 | The anti-malware solution(s)… |
| 5.3.2.1 | If periodic malware scans are performed to meet Requirement 5.3.2… |
| 5.3.3 | For removable electronic media, the anti-malware solution(s)… |
| 5.3.4 | Audit logs for the anti-malware solution(s) are enabled and retained in accordance… |
← 5.3.4 · All controls · 5.4.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.