PCI安全标准委员会在PCI DSS v4.0.1中规定,组织必须部署自动化反钓鱼机制来保护员工。[1]该要求的具体表述为"采取流程和自动化机制检测和防护人员免受钓鱼攻击",[1]并自2025年3月31日起从最佳实践升级为强制性要求。[1]
标准将DMARC、SPF和DKIM列为示例控制措施,[1]但并未强制指定某一特定协议。组织在选择反钓鱼解决方案时具有灵活性,但建议部署的DMARC政策级别应设置为p=reject或p=quarantine而非p=none。[1]
邮件认证的采纳率仍显不足。扫描数据表明,仅30.4%的域名发布了DMARC记录,而40.8%的域名完全缺乏邮件认证机制。[1]这种保护缺口在业界造成了严重损失——美国联邦调查局数据显示,2024年商业邮件泄露(BEC)事件造成的损失达27.7亿美元。[1]
第5.4.1条款的邮件安全要求需与Requirement 4.2.2相结合落实。后者规定,邮件中传输的卡号(PAN)必须采用强密码学加密。[1]PCI DSS合规违规的罚款范围约为每月5000至100000美元。[1]
The PCI Security Standards Council has activated a new mandatory requirement for anti-phishing defenses as part of PCI DSS v4.0.1, effective March 31, 2025 [1]. Section 5.4.1 mandates that "processes and automated mechanisms are in place to detect and protect personnel against phishing attacks" [1].
While the regulation does not explicitly require DMARC, it identifies Domain-based Message Authentication, Reporting and Conformance (DMARC), Sender Policy Framework (SPF), and DomainKeys Identified Mail (DKIM) as example controls [1]. Organizations must implement email authentication technologies to satisfy the requirement [1].
The timing of this enforcement reflects growing security threats. FBI data indicates that Business Email Compromise (BEC) attacks caused $2.77 billion in losses during 2024 [1]. Current vulnerability surveys reveal that only 30.4% of domains publish DMARC records, while 40.8% lack any email authentication mechanism entirely [1].
For organizations deploying DMARC, experts recommend setting policy levels to either "p=reject" or "p=quarantine" rather than "p=none" [1]. This stricter configuration provides stronger protection against unauthorized email use. Implementation must also align with PCI DSS Requirement 4.2.2, which mandates strong cryptographic encryption of Primary Account Numbers (PAN) in email communications [1].
Organizations should note that PCI DSS non-compliance carries significant financial consequences, with penalties estimated between $5,000 and $100,000 per month, though these figures are not officially published by the council [1].