What does PCI DSS say about users disabling anti-malware?
- A.Users can disable freely, since the standard exempts virtual machines from the anti-malware requirements for SAQ B-IP merchants during the semi-annual rule review
- B.Only administrators can disable because malware protection may be disabled where the entity documents a performance impact for internally facing system components
- C.Anti-malware solutions must not be disabled or altered by users unless specifically authorized by management on a case-by-case basis with documented justification
- D.Anti-malware can be disabled for performance, because the standard now relies on quarterly vulnerability scans to surface infections, which makes continuously running anti-malware mechanisms an optional defence-in-depth measure
Why C is correct
Anti-malware must not be user-disableable. Only documented, management-approved exceptions for specific cases are permitted.
Know someone studying for PCI DSS? Send them this one.