← PCI DSS 4.0.1 · Req 5 — Malicious software
5.4.1 — Protection against phishing
Requirement
Processes and automated mechanisms are in place to detect and protect personnel against phishing attacks — for example email link scanning, attachment sandboxing, and anti-spoofing controls such as SPF, DKIM and DMARC.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| SOC 2 | CC6.8 | Prevention and detection of unauthorised software | malware |
| ISO 27001 | A.6.3 | Information security awareness, education and training | awareness |
| ISO 27001 | A.6.8 | Information security event reporting | awareness |
| ISO 27001 | A.8.7 | Protection against malware | malware |
| HIPAA | 164.308(a)(5)(ii)(A-D) | Security awareness and training (A) | awareness malware |
| GLBA | 314.4(e) | Security awareness training and qualified security personnel | awareness |
| NIST CSF 2.0 | PR.AT-01 | Personnel are provided awareness and training | awareness |
| NDPA 2023 | GAID Art.30 | Privacy training and internal sensitisation (GAID 2025) | awareness |