ASV Quarterly Vulnerability Scanning
Quarterly vulnerability scanning helps secure your network and comply with PCI requirements by proactively identifying weaknesses in your network environment. SecureConnect provides quarterly vulnerability scans to help organizations minimize vulnerabilities and alert you of security flaws in your network.
PCI DSS requires all companies processing card payments to comply with a quarterly external vulnerability scan. The automated vulnerability scans are executed on the external IP addresses of your network. These scans look for known vulnerabilities and configuration issues that potentially could be exploited by hackers, worms, or viruses.
The scan will identify computer or network vulnerabilities and configuration issues related to the Routers, Firewalls, Web Servers, Application Servers, DNS Servers, Mail Servers, Virtual Hosts, and Wireless Access Points.
The Scanning Process
Upon subscribing to quarterly vulnerability scans, SecureConnect will automatically obtain the Internet-facing Internet Protocol (IP) addresses at each SecureConnect location. The list of active IP addresses and/or domains will be scanned for known vulnerabilities and configuration issues. If any exploits or vulnerabilities are detected, the customer will be notified. Upon completion of remediation steps, the PCI ASV vulnerability scan is performed again to verify the remedied vulnerabilities.
SecureConnect will provide the following to vulnerability scan customers:
- Automatically obtain the Internet-facing Internet Protocol (IP) addresses at each SecureConnect location.
- Automatically scan the list of active IP addresses and/or domains quarterly for known vulnerabilities and configuration issues.
- If any exploits or vulnerabilities are detected, the customer will be notified. Upon remediation steps being taken, the PCI ASV vulnerability scan will be performed again to verify the vulnerability has been remedied.
- Provide an executive summary report with compliance statement
- Provide a detailed finding report with recommendations
- Reports will be delivered securely via the mySecureConnect web portal
|