Procedure 10  TECHNICAL

Anti-Malware Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 10  ·  PCI DSS Req 5  ·  1 of 5 policy statements fully met  ·  AWS facts collected read-only 2026-08-13
← All 21 procedures 📘← Back to Policy 10 — Anti-Malware PolicyThe rule this procedure implements

How Revique implements this today

Revique's workloads are predominantly serverless and containerised — ECS Fargate tasks in us-e****-1 (4 running tasks across 3 services in production) and Lambda in us-e****-2 — where a traditional anti-malware agent cannot be installed. The policy anticipates this and permits compensating controls. Revique's compensating controls are GuardDuty for runtime threat detection, enabled in both production regions with continuous analysis of CloudTrail, VPC flow and DNS telemetry, and ECR image scanning plus immutable image tags on the build path (Procedure 05). GuardDuty findings are retained and published every six hours.

The rule against the current state

Each row takes a statement from Policy 10 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.

The ruleCurrent stateVerdict
Anti-malware or equivalent threat detection on all susceptible systemsGuardDuty covers the production account in both regions. It is not enabled in dev or UAT, and the EC2 instances in the legacy estate have no evidenced endpoint agent.Partial
Compensating controls for serverless/container workloadsGuardDuty runtime detection plus ECR scan-on-push and immutable tags.Partial
Definitions and engines kept current automaticallyGuardDuty is fully AWS-managed — detection logic updates without operator action.Meets
Anti-malware logs retained for at least [X] monthsGuardDuty retains findings; the underlying CloudTrail record is retained per Procedure 11/17.Partial
Controls not disabled without authorisationDisabling GuardDuty is an IAM-restricted API call, recorded in CloudTrail — but no alarm fires if it happens (see Procedure 03).Partial

🔍 Auditor verification — where to log in and what you will see

GuardDuty coverageConsole → GuardDuty → production account, us-e****-1 and us-e****-2 → Enabled, finding publishing frequency 6 hours. Then check the dev (292****) and UAT (559****) accounts — expect not enabled.
FindingsGuardDuty → Findings → production us-e****-2 shows one open low-severity finding, Discovery:S3/AnomalousBehavior, severity 2.0, last updated 2026-08-07. us-e****-1 shows none.
Image scanning as a compensating controlConsole → ECR → the native application repository → Scan on push: Enabled (see Procedure 05 for the coverage caveat).
Workload typeConsole → ECS → production cluster → 4 running tasks, 3 services, launch type Fargate — confirming no host OS Revique can install an agent on.

Team process

DevOps maintains GuardDuty enablement; the Security Officer reviews findings and decides on action. A finding is triaged in the same flow as any incident (Procedure 03). Because GuardDuty is AWS-managed, there is no signature-update task for the team to perform.

⚠️ Where reality does not meet the policy

Evidence location. All evidence is in AWS (GuardDuty, ECR, ECS). Endpoint agent coverage for legacy EC2 would need to be evidenced separately.
📘Back to the PolicyPolicy 10 — Anti-Malware Policy (PCI DSS Req 5)←
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.