← PCI DSS 4.0.1 · Req 5 — Malicious software

5.4.1 — Protection against phishing

high awarenessmalware

Requirement

Processes and automated mechanisms are in place to detect and protect personnel against phishing attacks — for example email link scanning, attachment sandboxing, and anti-spoofing controls such as SPF, DKIM and DMARC.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
phishingspoofingspoof…
Required element 2 — any one of
dmarcdkimspflink scanningsandbox…email filteringemail securityfilterfiltersautomateddetectblock
Supporting terms — specificity signals
5.4.1quarantinebannerexternal sender

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
SOC 2 CC6.8 Prevention and detection of unauthorised software malware
ISO 27001 A.6.3 Information security awareness, education and training awareness
ISO 27001 A.6.8 Information security event reporting awareness
ISO 27001 A.8.7 Protection against malware malware
HIPAA 164.308(a)(5)(ii)(A-D) Security awareness and training (A) awareness malware
GLBA 314.4(e) Security awareness training and qualified security personnel awareness
NIST CSF 2.0 PR.AT-01 Personnel are provided awareness and training awareness
NDPA 2023 GAID Art.30 Privacy training and internal sensitisation (GAID 2025) awareness