PCI ASV scans

Approved Scanning Vendor (ASV) network scans are performed by a PCI DSS certified company to detect possible vulnerabilities in systems. When one or more systems that store, process or transmit credit card data are connected to the Internet (or remote access is possible), documented quarterly network scans must be performed.

SC2labs provides PCI ASV scanning services using a qualified PCI ASV organization certified by the PCI Security Standards Council.

Per PCI DSS requirement 11.2 — run internal and external network vulnerability scans at least quarterly and after any significant change in the network:

  • 11.2.1 — quarterly internal vulnerability scans; address findings and rescan to verify all "high risk" vulnerabilities are resolved.
  • 11.2.2 — quarterly external scans via a PCI SSC Approved Scanning Vendor (ASV); rescan until passing.
  • 11.2.3 — internal and external scans, and rescans as needed, after any significant change.

SC2labs offers managed external ASV and internal scanning services to meet PCI DSS requirement 11.2. Audits check external-facing, publicly available IT resources (IPv4/IPv6 addresses, networks, domains, etc.) using over 150,000 non-invasive tests designed for various technologies, platforms and applications. The scan detects deficiencies in the architecture and configuration of the analyzed system.

  • Initial teleconference — determine the range of IP addresses/domains in scope, provide a pre-scan checklist and schedule the first PCI ASV scan.
  • Scanning process — after completion the reports are sent: PCI ASV Attestation of Scan Compliance, PCI ASV Vulnerability Details Report and PCI ASV Executive Summary Report.
  • Overview of reports — vulnerabilities grouped by risk (CVSS) and labelled in popular standards (OVAL, CVE). A "fail" result requires a re-scan in the same quarter; evidence may be provided for False Positive / Acceptable Risk designation.
  • Attestation with PASS status — once achieved, the scan runs automatically every 90 days.

You may also be interested in:

PCI DSS Audit
SAQ Support
Advisory