r5.1 Enable malware detection with Amazon GuardDuty
Turn on managed threat and malware detection in the environment, including Malware Protection for EC2 and ECS workloads, as a cost-efficient baseline against malicious software.
AWS services
Requirement 5
Protect All Systems and Networks from Malicious Software
PCI sub-requirements covered
- 5.2 Malicious software is prevented, or detected and addressed
- 5.3 Anti-malware mechanisms and processes are active, maintained, and monitored
How to implement on AWS
Enable Amazon GuardDuty across all accounts and Regions via the organization's delegated administrator account. Turn on GuardDuty Malware Protection. Send findings to Security Hub and alert with EventBridge. GuardDuty runs continuously and agentlessly for threat analysis.
Practical implementation
How this control is implemented in each reference architecture:
Enable Amazon GuardDuty (with Malware Protection) in the account and send findings to Security Hub with EventBridge alerts. Agentless, so it protects the app/data tiers immediately.
Single-account, 3-tier →Enable GuardDuty organization-wide from the delegated administrator in the security tooling account, so every current and future CDE account is auto-enrolled and findings aggregate centrally.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine system components to verify that an anti-malware solution is deployed on all components except those a periodic evaluation determined not at risk (5.2.1.a).
- Examine vendor documentation and configurations to verify the solution detects and removes/blocks/contains all known types of malware (5.2.2).
- Examine the periodic-evaluation process for components deemed not at risk (5.2.3.a, 5.2.3.c).
Evidence in AWS
- GuardDuty enabled across all accounts/Regions (organization status).
- GuardDuty Malware Protection active and findings in Security Hub.
- EventBridge rules that route and alert on malware findings.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 5.2 — Automated mechanisms are implemented to prevent systems from becoming an attack vector for malware.
- 5.3 — Anti-malware mechanisms can detect and address the latest malware threats.
Learning resources
References
- AWS Security Maturity Model: Detect common threats
PCI DSS Security Maturity Model