PCI DSS 5.3.4: Audit logs for the anti-malware solution(s) are enabled and retained in accordance
PCI DSS v4.0.1 control 5.3.4: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 5.3.
Requirement 5: Protect All Systems and Networks from Malicious Software › Section 5.3
Audit logs for the anti-malware solution(s) are enabled and retained in accordance with Requirement 10.5.1.
Summary
Turn on the anti-malware logs and keep them as long as you keep everything else.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 5.3.4 | Examine anti-malware solution(s) configurations to verify logs are enabled and retained in accordance with Requirement 10.5.1. |
A short control that borrows its substance from elsewhere: retention is in accordance with 10.5.1, which means twelve months, with the most recent three immediately available rather than in cold storage. Entities meet 10.5.1 carefully for operating systems and applications and then leave anti-malware logs in the vendor console under whatever the product's default retention is, which is usually far shorter and is not under your control. The reason this matters practically is that anti-malware logs are the record of what was detected and what was done about it, so a compromise investigated four months later is exactly the case where the shortest-retained log is the one you needed.
What to prepare
- The anti-malware logging configuration, showing logs are enabled.
- Where those logs are retained, and for how long.
- Evidence the three-month immediate-availability element is met.
- The default retention of the vendor console, if you rely on it.
How to implement it
1. Forward them into the same pipeline as everything else. It is the simplest way to inherit a retention that already satisfies 10.5.1 rather than managing a second one.
2. Check the console default rather than assuming it. Product defaults of 30 to 90 days are common and are shorter than the twelve months this control inherits.
3. Include detection and remediation events, not just health. The point of the log is what was found and what happened next.
4. Confirm the immediate-availability half. Twelve months in an archive with nothing readily searchable meets one part of 10.5.1 and not the other.
Where this commonly fails
- Logs left in the vendor console at a default retention shorter than twelve months.
- Retention met and immediate availability not, which is half of 10.5.1.
- Logging enabled for administrative actions while detection events are not retained.
- A managed service holding the logs with no agreement about how long.
Related controls
This control refers to 10.5.1.
Others in section 5.3:
| Control | What it requires |
|---|---|
| 5.3.1 | The anti-malware solution(s) is kept current via automatic updates |
| 5.3.2 | The anti-malware solution(s)… |
| 5.3.2.1 | If periodic malware scans are performed to meet Requirement 5.3.2… |
| 5.3.3 | For removable electronic media, the anti-malware solution(s)… |
| 5.3.5 | Anti-malware mechanisms cannot be disabled or altered by users, unless specifically documented… |
← 5.3.3 · All controls · 5.3.5 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.