Procedure 10 TECHNICAL
Anti-Malware Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 10 · PCI DSS Req 5 · 1 of 5 policy statements fully met · AWS facts collected read-only 2026-08-13
← All 21 procedures
📘← Back to Policy 10 — Anti-Malware PolicyThe rule this procedure implements
How Revique implements this today
Revique's workloads are predominantly serverless and containerised — ECS Fargate tasks in us-e****-1 (4 running tasks across 3 services in production) and Lambda in us-e****-2 — where a traditional anti-malware agent cannot be installed. The policy anticipates this and permits compensating controls. Revique's compensating controls are GuardDuty for runtime threat detection, enabled in both production regions with continuous analysis of CloudTrail, VPC flow and DNS telemetry, and ECR image scanning plus immutable image tags on the build path (Procedure 05). GuardDuty findings are retained and published every six hours.
The rule against the current state
Each row takes a statement from Policy 10 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.
| The rule | Current state | Verdict |
|---|
| Anti-malware or equivalent threat detection on all susceptible systems | GuardDuty covers the production account in both regions. It is not enabled in dev or UAT, and the EC2 instances in the legacy estate have no evidenced endpoint agent. | Partial |
| Compensating controls for serverless/container workloads | GuardDuty runtime detection plus ECR scan-on-push and immutable tags. | Partial |
| Definitions and engines kept current automatically | GuardDuty is fully AWS-managed — detection logic updates without operator action. | Meets |
| Anti-malware logs retained for at least [X] months | GuardDuty retains findings; the underlying CloudTrail record is retained per Procedure 11/17. | Partial |
| Controls not disabled without authorisation | Disabling GuardDuty is an IAM-restricted API call, recorded in CloudTrail — but no alarm fires if it happens (see Procedure 03). | Partial |
🔍 Auditor verification — where to log in and what you will see
GuardDuty coverageConsole → GuardDuty → production account, us-e****-1 and us-e****-2 → Enabled, finding publishing frequency 6 hours. Then check the dev (292****) and UAT (559****) accounts — expect not enabled.
FindingsGuardDuty → Findings → production us-e****-2 shows one open low-severity finding, Discovery:S3/AnomalousBehavior, severity 2.0, last updated 2026-08-07. us-e****-1 shows none.
Image scanning as a compensating controlConsole → ECR → the native application repository → Scan on push: Enabled (see Procedure 05 for the coverage caveat).
Workload typeConsole → ECS → production cluster → 4 running tasks, 3 services, launch type Fargate — confirming no host OS Revique can install an agent on.
Team process
DevOps maintains GuardDuty enablement; the Security Officer reviews findings and decides on action. A finding is triaged in the same flow as any incident (Procedure 03). Because GuardDuty is AWS-managed, there is no signature-update task for the team to perform.
⚠️ Where reality does not meet the policy
- GuardDuty is production-only. The dev and UAT accounts — UAT holds CHD/PHI — have no threat detection whatsoever. The policy applies to all susceptible systems, not just production.
- The EC2 instances in the legacy us-e****-2 estate are traditional hosts where a conventional anti-malware agent would apply, and no such agent is evidenced. The serverless exemption does not cover them.
- The one open GuardDuty finding (low severity, 2026-08-07) has been open for six days at the time of collection with no evidenced triage record.
- No alarm exists on GuardDuty being disabled, so the “must not be disabled without authorisation” rule is enforced only by IAM permissions, not by detection.
Evidence location. All evidence is in AWS (GuardDuty, ECR, ECS). Endpoint agent coverage for legacy EC2 would need to be evidenced separately.
📘Back to the PolicyPolicy 10 — Anti-Malware Policy (PCI DSS Req 5)←