PCI DSS Security Maturity Model·AWS v1.0.0
Efficient Application Security 🤝 Shared

r5.3 Anti-phishing protection with email and browsing controls

Implement technical mechanisms that detect and protect personnel against phishing attacks, complementing the awareness training of Requirement 12.6.

Quick Wins
Foundational
Efficient
Optimized
Effort: Medium Impact: Medium Applies to CDE: No

AWS services

Amazon SES Amazon Route 53 Resolver DNS Firewall Amazon GuardDuty

Requirement 5

Protect All Systems and Networks from Malicious Software

PCI sub-requirements covered

  • 5.4 Anti-phishing mechanisms protect users against phishing attacks

How to implement on AWS

Configure email authentication (SPF, DKIM, DMARC) on domains managed with Amazon SES/Route 53. Integrate anti-phishing filtering at the email gateway. Use Route 53 Resolver DNS Firewall to block known malicious domains. Correlate signals with GuardDuty.

Practical implementation

How this control is implemented in each reference architecture:

Configure SPF/DKIM/DMARC for your domains (SES/Route 53) and use Route 53 Resolver DNS Firewall to block known-malicious domains from the account's VPC.

Single-account, 3-tier →

Manage email authentication and the DNS Firewall rule groups centrally (network account) and share them to the VPCs of all accounts, so anti-phishing DNS controls are consistent org-wide.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineobserve

Testing procedures

  • Observe implemented processes and examine mechanisms to verify that controls are in place to detect and protect personnel against phishing attacks (5.4.1).

Evidence in AWS

  • SPF/DKIM/DMARC DNS records configured in Route 53.
  • DNS Firewall rules blocking malicious domains.
  • Anti-phishing filtering configuration at the email gateway.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 5.4 — Mechanisms are in place to protect against and mitigate risk posed by phishing attacks.

Learning resources

References

  • PCI DSS v4.0.1 Requirement 5.4