Approved Scanning Vendor (ASV)
Definition
An organisation qualified by the PCI Security Standards Council to conduct external vulnerability scans of cardholder data environments. PCI-DSS requirement 11.3.2 mandates that external scans be performed by an ASV. The ASV designation is the compliance framework's assurance that the scanner is competent and independent.
- Qualifying body
- PCI Security Standards Council
- Requirement
- PCI-DSS 11.3.2, external vulnerability scans
- Scope
- Cardholder data environments
Common questions
Why must an external scan be run by an ASV rather than any competent vulnerability scanner?+
PCI-DSS ties compliance to a vendor the Council has independently qualified, so a merchant's own internal team or an unaccredited tool cannot satisfy requirement 11.3.2 no matter how thorough the scan itself is.
How often must ASV scans be performed for PCI-DSS compliance?+
PCI-DSS requires quarterly external scans by an ASV, plus a scan after any significant change to the cardholder data environment, with passing results needed before certification of compliance.
Related terms
- Audit Evidence
- Any information the auditor uses to draw conclusions about a control. To be acceptable, audit evidence must be sufficient (enough of it),...
- CVSS (Common Vulnerability Scoring System)
- An open standard maintained by FIRST (Forum of Incident Response and Security Teams) that assigns a numeric score from 0 to 10...
- Remediation Prioritisation
- The process of ordering vulnerability remediation by risk. Factors include CVSS base score, asset criticality, threat intelligence about active exploitation, and compensating...
- Risk Acceptance
- A formal decision by an authorised senior manager to tolerate a finding without full remediation, typically because the cost of remediation exceeds...
- Vulnerability Assessment
- A systematic process of identifying, classifying, and prioritising security weaknesses in systems, software, and infrastructure. Produces a list of findings with severity...