Our offer includes both external and internal scanning services and PCI ASV scans. Audits consist of checking external-facing, publicly available IT resources (IPv4 and/or IPv6 addresses, networks, domains, etc.) using over 150,000 non-invasive tests designed for various technologies, platforms and applications.
The aim of the network vulnerability scan is to detect deficiencies in the architecture and configuration of the analyzed system that could be used to penetrate firewalls and servers and reach the internal network. Auditors explain the scope and course of the scan, present the most common errors and provide assistance with any non-compliances found.
PCI DSS — Requirements
11.2 Run internal and external network vulnerability scans at least quarterly and after any significant change in the network (new system component installations, changes in network topology, firewall rule modifications, product upgrades).
- 11.2.1 Perform quarterly internal vulnerability scans; address vulnerabilities and rescan to verify all "high risk" vulnerabilities are resolved. Scans must be performed by qualified personnel.
- 11.2.2 Perform quarterly external vulnerability scans via a PCI SSC Approved Scanning Vendor (ASV). Perform rescans as needed until passing scans are achieved.
- 11.2.3 Perform internal and external scans, and rescans as needed, after any significant change.