PCI DSS Security Maturity Model·AWS v1.0.0
Quick Wins Threat Detection 🤝 Shared

r5.1 Enable malware detection with Amazon GuardDuty

Turn on managed threat and malware detection in the environment, including Malware Protection for EC2 and ECS workloads, as a cost-efficient baseline against malicious software.

Quick Wins
Foundational
Efficient
Optimized
Effort: Low Impact: High Applies to CDE: Yes

AWS services

Amazon GuardDuty AWS Security Hub Amazon EventBridge

Requirement 5

Protect All Systems and Networks from Malicious Software

PCI sub-requirements covered

  • 5.2 Malicious software is prevented, or detected and addressed
  • 5.3 Anti-malware mechanisms and processes are active, maintained, and monitored

How to implement on AWS

Enable Amazon GuardDuty across all accounts and Regions via the organization's delegated administrator account. Turn on GuardDuty Malware Protection. Send findings to Security Hub and alert with EventBridge. GuardDuty runs continuously and agentlessly for threat analysis.

Practical implementation

How this control is implemented in each reference architecture:

Enable Amazon GuardDuty (with Malware Protection) in the account and send findings to Security Hub with EventBridge alerts. Agentless, so it protects the app/data tiers immediately.

Single-account, 3-tier →

Enable GuardDuty organization-wide from the delegated administrator in the security tooling account, so every current and future CDE account is auto-enrolled and findings aggregate centrally.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineobserve

Testing procedures

  • Examine system components to verify that an anti-malware solution is deployed on all components except those a periodic evaluation determined not at risk (5.2.1.a).
  • Examine vendor documentation and configurations to verify the solution detects and removes/blocks/contains all known types of malware (5.2.2).
  • Examine the periodic-evaluation process for components deemed not at risk (5.2.3.a, 5.2.3.c).

Evidence in AWS

  • GuardDuty enabled across all accounts/Regions (organization status).
  • GuardDuty Malware Protection active and findings in Security Hub.
  • EventBridge rules that route and alert on malware findings.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 5.2 — Automated mechanisms are implemented to prevent systems from becoming an attack vector for malware.
  • 5.3 — Anti-malware mechanisms can detect and address the latest malware threats.

Learning resources

References

  • AWS Security Maturity Model: Detect common threats