PCI ASV external FAQ
PCI ASV
-
What is PCI ASV?
-
PCI ASV refers to requirement 11.2.2 of the Payment Card Industry (PCI) Data Security Standard (DSS) Requirements and Security Assessment Procedures that requires quarterly external vulnerability scans, which must be performed (or attested to) by an Approved Scanning Vendor (ASV). An ASV is an organization with a set of services and tools (“ASV Scanning Solution”) to validate adherence to the external scanning requirement of PCI DSS Requirement 11.2.2.
-
What systems are in scope for ASV Scanning?
-
The PCI DSS requires vulnerability scanning of all externally accessible (internet-facing) system components owned or utilized by the scan customer that are part of the cardholder data environment, as well as any externally facing system component that provides a path to the cardholder data environment.
-
What is the ASV process?
-
The main phases of ASV scanning consist of:
- Scoping: performed by the customer to include all internet-facing system components that are part of the cardholder data environment.
- Scanning: using the specified Tenable One Vulnerability Management PCI and WAS templates. Multiple Cardholder Data Environment (CDE) sections can be scanned individually.
- Merge multiple scans into a single attestation.
- Reporting/remediation: results from interim reports are remediated.
- Dispute resolution: Customer and ASV (Tenable) work together to document and resolve disputed scan results.
- Rescan (as needed): until a passing scan that resolves disputes and exceptions is generated.
- Final reporting: submitted and delivered in a secure fashion.
-
How often are ASV vulnerability scans required?
-
ASV Vulnerability scans are required at least quarterly and after any significant change in the network, such as new system component installations, changes in network topology, firewall-rule modifications, or product upgrades.
-
How is an Approved Scanning Vendor (ASV) different from a Qualified Security Assessor (QSA)?
-
An ASV specifically performs only the external vulnerability scans described in PCI DSS 11.2. A QSA refers to an assessor company that has been qualified and trained by PCI Security Standards Council (SSC) to perform general PCI DSS on-site assessments.
-
Is Tenable One a certified PCI ASV?
-
Yes. Tenable is qualified as an Approved Scanning Vendor (ASV) to validate external vulnerability scans of internet facing environments (used to store, process, or transmit cardholder data) of merchants and service providers. The ASV qualification process consists of three parts: the first involves the qualification of Tenable Network Security as a vendor. The second relates to the qualification of Tenable’s employees responsible for the remote PCI Scanning Services. The third consists of the security testing of Tenable’s remote scanning solution (Tenable One Vulnerability Management and Tenable PCI ASV).
-
As an Approved Scanning Vendor (ASV), does Tenable One actually perform the scans?
-
ASVs may perform the scans. However, Tenable relies on customers to conduct their own scans using the PCI Quarterly External Scan template. This template prevents customers from changing configuration settings, such as disabling vulnerability checks, assigning severity levels, altering scan parameters, etc. Customers use Tenable One Vulnerability Management cloud-based scanners to scan their internet facing environments and then submit compliant scan reports to Tenable for attestation. Tenable attests the scan reports, and then the customer submits them to their acquirers or payment brands as directed by the payment brands.
Data sovereignty
-
Does Tenable PCI ASV comply with EU data sovereignty requirements?
-
Vulnerability data is not EU DPD 95/46/EC data, so any data residency requirements would be customer, not regulatory driven. EU state governmental organizations could have their own data residency requirements, but those would have to be assessed on a case-by-case basis and probably not an issue for PCI-ASV scans.
- Tenable One Vulnerability Management
Tenable One
Request a demo
The world’s leading AI-powered exposure management platform.
Thank You
Thank you for your interest in Tenable One.
A representative will be in touch soon.
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success