Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Malware protection posture: GuardDuty/Inspector coverage, container image scanning, and host-based AV on EC2.
GuardDutyInspectorHost AVImage scan
5.2 / 5.3 — Malware Detection Controls (AWS-native)
| Service | Purpose | Status | Evidence |
|---|
| Amazon GuardDuty | Threat detection incl. malware/crypto-mining signals | Compliant | Detector 3cbe13fb1be275ffab6f883e26df3ae6 status=ENABLED |
| Amazon Inspector v2 | Continuous vuln/malware exposure scanning | Gap | Account state=DISABLED |
ECR registry scan configuration: BASIC. No ECR repositories currently in the account — container workloads not in use.
5.2 — Host-based Anti-malware (EC2 via SSM)
Note: SSM Run Command inspection unavailable in this environment (aws-cli send-command incompatibility; prior attempt returned send-failed) — instance-level checks require manual review.
| Instance | Platform | Inspection Status | AV Result |
|---|
| i-0**** | Linux | send-failed | Needs Review |
Compensating controls: Serverless (Lambda, 56 functions) and managed services run on AWS-maintained, continuously-patched infrastructure where customer-installed AV is not applicable; GuardDuty provides account-wide malware/behavioral detection.
Control Mapping
| Control | Description | Status | Evidence |
|---|
| 5.2.1 | Anti-malware / threat detection deployed | Compliant | GuardDuty ENABLED |
| 5.2.2 | Detection of known & evolving malware (behavioral) | Compliant | GuardDuty behavioral analytics |
| 5.2.3 (Images) | Container image vulnerability scanning | Compliant | ECR scanType=BASIC; no repositories present |
| 5.2.1 (Hosts) | Anti-malware present on in-scope EC2 hosts | Needs Review | 1 managed instance(s); SSM inspection could not complete — manual review required |
| 5.3.4 | Audit logs for anti-malware retained ≥12 months | Gap | 50/74 log groups retain ≥365d; 24 never expire (unset) |
Recommendations
HighEnable Amazon Inspector v2 (EC2 + Lambda) for continuous vulnerability/malware exposure scanning — currently DISABLED.
HighDeploy and verify host-based anti-malware (e.g. ClamAV / CrowdStrike / Wazuh) on EC2 instance(s) and document scan schedules; SSM inspection could not confirm presence.
MediumSet explicit CloudWatch Logs retention ≥365 days on log groups feeding malware/security detection.
ProcessDocument the malware-risk evaluation for system components deemed not at risk (PCI 5.2.3.1).