Hasty Briefsbeta

Bilingual

PCI DSS DMARC Requirement: What Section 5.4.1 Requires

4 hours ago
  • PCI DSS v4.0.1 requires automated anti-phishing mechanisms under Requirement 5.4.1, mandatory since March 31, 2025; DMARC, SPF, and DKIM are cited as examples, not specific mandates.
  • Requirement 5.4.1 focuses on detecting and protecting personnel against phishing attacks; it is distinct from training requirement 12.6.3.1.
  • DMARC enforcement (p=quarantine or p=reject) is recommended by assessors but not required by the standard; p=none indicates monitoring only.
  • Requirement 4.2.2 mandates strong cryptography for PAN transmitted via email and other end-user messaging technologies.
  • Implementation steps include auditing current records, publishing DMARC at p=none with reporting, identifying legitimate senders, fixing SPF/DKIM, ramping to enforcement, setting subdomain policy, and documenting for assessors.
  • Common audit failures include leaving DMARC at p=none, lacking subdomain policy, exceeding SPF 10-lookup limit, and ignoring Requirement 4 for transport security.
  • PCI DSS is a contractual obligation; non-compliance penalties are contractual and non-public, not statutory fines.