r5.3 Anti-phishing protection with email and browsing controls
Implement technical mechanisms that detect and protect personnel against phishing attacks, complementing the awareness training of Requirement 12.6.
AWS services
Requirement 5
Protect All Systems and Networks from Malicious Software
PCI sub-requirements covered
- 5.4 Anti-phishing mechanisms protect users against phishing attacks
How to implement on AWS
Configure email authentication (SPF, DKIM, DMARC) on domains managed with Amazon SES/Route 53. Integrate anti-phishing filtering at the email gateway. Use Route 53 Resolver DNS Firewall to block known malicious domains. Correlate signals with GuardDuty.
Practical implementation
How this control is implemented in each reference architecture:
Configure SPF/DKIM/DMARC for your domains (SES/Route 53) and use Route 53 Resolver DNS Firewall to block known-malicious domains from the account's VPC.
Single-account, 3-tier →Manage email authentication and the DNS Firewall rule groups centrally (network account) and share them to the VPCs of all accounts, so anti-phishing DNS controls are consistent org-wide.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Observe implemented processes and examine mechanisms to verify that controls are in place to detect and protect personnel against phishing attacks (5.4.1).
Evidence in AWS
- SPF/DKIM/DMARC DNS records configured in Route 53.
- DNS Firewall rules blocking malicious domains.
- Anti-phishing filtering configuration at the email gateway.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 5.4 — Mechanisms are in place to protect against and mitigate risk posed by phishing attacks.
Learning resources
References
- PCI DSS v4.0.1 Requirement 5.4
PCI DSS Security Maturity Model