Approved Scanning Vendors (ASVs) perform vulnerability scans of Internet facing environments of
merchants and service providers.
PCI Security Standards Council maintains a structured process for security solution providers to become Approved Scanning Vendors (ASVs), as well as to be re-approved each year. The five founding members of the Council recognizes the ASVs certified by the PCI Security Standards Council as being qualified to validate adherence to the PCI DSS by performing vulnerability scans of Internet facing environments of merchants and service providers.
PCI Security Standards Council maintains a structured process for security solution providers to become Approved Scanning Vendors (ASVs), as well as to be re-approved each year. The five founding members of the Council recognizes the ASVs certified by the PCI Security Standards Council as being qualified to validate adherence to the PCI DSS by performing vulnerability scans of Internet facing environments of merchants and service providers.
The major requirement of the process is a rigorous remote test conducted by each vendor on the PCI Security Standards Council's test infrastructure, which simulates the network of a typical security scan customer. The Council has set up the test infrastructure in such a way as to deliberately introduce vulnerabilities and misconfigurations for the vendor to identify and report as part of the compliance testing process.
The testing primarily addresses these areas:
- Scan administration - how the vendor collects and manages scan requests from its customers;
- Scan performance - the ability of each vendor to identify vulnerabilities and misconfigurations in the network and Web application; and
- Scan report - how the vendor presents the scan results to its customers.
When a vendor has successfully passed the testing process, it becomes an ASV and is listed on the PCI Security Standards Council Web site. To ensure ongoing compliance with program requirements, all ASVs are subject to an annual recertification process.
