PCI DSS v4.0.1 — Requirement 5

Protect All Systems and Networks from Malicious Software
Environment: hptprod | us-east-2  |  Account: 501****  |  Generated: 2026-07-07 05:52 UTC
Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Malware protection posture: GuardDuty/Inspector coverage, container image scanning, and host-based AV on EC2.
0
Critical
1
Gap
1
Needs Review
3
Compliant
0
AWS-Managed
0
N/A
GuardDutyInspectorHost AVImage scan

5.2 / 5.3 — Malware Detection Controls (AWS-native)

ServicePurposeStatusEvidence
Amazon GuardDutyThreat detection incl. malware/crypto-mining signalsCompliantDetector 3cbe13fb1be275ffab6f883e26df3ae6 status=ENABLED
Amazon Inspector v2Continuous vuln/malware exposure scanningGapAccount state=DISABLED
ECR registry scan configuration: BASIC. No ECR repositories currently in the account — container workloads not in use.

5.2 — Host-based Anti-malware (EC2 via SSM)

Note: SSM Run Command inspection unavailable in this environment (aws-cli send-command incompatibility; prior attempt returned send-failed) — instance-level checks require manual review.
InstancePlatformInspection StatusAV Result
i-0****Linuxsend-failedNeeds Review
Compensating controls: Serverless (Lambda, 56 functions) and managed services run on AWS-maintained, continuously-patched infrastructure where customer-installed AV is not applicable; GuardDuty provides account-wide malware/behavioral detection.

Control Mapping

ControlDescriptionStatusEvidence
5.2.1Anti-malware / threat detection deployedCompliantGuardDuty ENABLED
5.2.2Detection of known & evolving malware (behavioral)CompliantGuardDuty behavioral analytics
5.2.3 (Images)Container image vulnerability scanningCompliantECR scanType=BASIC; no repositories present
5.2.1 (Hosts)Anti-malware present on in-scope EC2 hostsNeeds Review1 managed instance(s); SSM inspection could not complete — manual review required
5.3.4Audit logs for anti-malware retained ≥12 monthsGap50/74 log groups retain ≥365d; 24 never expire (unset)

Recommendations

HighEnable Amazon Inspector v2 (EC2 + Lambda) for continuous vulnerability/malware exposure scanning — currently DISABLED.
HighDeploy and verify host-based anti-malware (e.g. ClamAV / CrowdStrike / Wazuh) on EC2 instance(s) and document scan schedules; SSM inspection could not confirm presence.
MediumSet explicit CloudWatch Logs retention ≥365 days on log groups feeding malware/security detection.
ProcessDocument the malware-risk evaluation for system components deemed not at risk (PCI 5.2.3.1).