Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Learning Center
Learning Center
Articles
Articles
Whitepapers
Whitepapers
Video
Video
Case Studies
Case Studies
Events & Live Webinars
Events & Live Webinars
On-Demand Webinars
On-Demand Webinars
Schellman Training
Schellman Training
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

PCI ASV Scanning

PCI DSS Requirement 11.3.2 (11.2.2 in PCI version 3.2.1) requires merchants and service providers to perform quarterly external vulnerability scans by an Approved Scanning Vendor (ASV). As a listed ASV, Schellman delivers the required scans and provides actionable feedback for organizations.

Contact a Specialist Build Your Compliance Roadmap

PCI DSS ASV Middle-1

With flexible deployment and technology solutions, Schellman’s ASV service works with organizations on a monthly or quarterly basis to scan targets in the external environment and conducts rescans on demand.

PCI DSS ASV Middle-1

Our Process

Effective communication and timely coordination of project planning activities are central to our methodology with our clients.
Image

Scoping and Planning

We begin each project by defining the list of external targets. Per the ASV Program Guide this is all externally accessible system components owned or utilized by the scan customer that are part of the cardholder data environment (CDE), any externally facing system component that may provide access to the CDE, and those which could impact the security of the CDE.

After the agreement and authorization letter are executed, a timeline is established to conduct scans. This is to ensure that Schellman and the Client are fully aware of the what, who, when, why, and how prior to the beginning of testing.

Image

Understanding and Kickoff

The kickoff is considered the start of the engagement. If needed, Schellman will schedule a call at the beginning of, or just prior to, the kickoff to finalize any outstanding items, review AuditSource (the proprietary project management portal) and address any questions.

By including communication prior to starting, Schellman ensures that no last-minute changes to the project or team have occurred and the Client has the plan prior to beginning the scans.

Image

Discovery and Scanning

The scan process begins with discovery, even if the scope remains unchanged. From these results, detailed scanning occurs. The outputs from this phase are the basis for reporting and recommendation of actions.

Schellman has a no surprise policy and critical items will be posted to AuditSource as soon as they are reviewed.

Image

Reporting

Schellman’s testing methodology ends with reporting, but the entire assessment is focused on creating a deliverable that is clear, concise, and accurate.

Schellman’s report takes into account the entire process and customizes a report for each Client. The scan results will be provided within one week after the scan concludes. Within AuditSource, like vulnerabilities are aggregated for ease of review while detailed findings are provided to the client for downloading and analysis.

Image

Rescanning

Upon correction of vulnerabilities, Schellman will rescan for those specific issues.

Your PCI ASV Specialist,
Ryan Renner

Ryan Renner is a Manager at Schellman, where he both manages PCI DSS assessments and the ASV service.
His veteran experience with vulnerability scanning merges both the ability to configure scans for efficacy and accuracy while providing functional recommendations on how to address findings.
  • Fixed-Fee Using an outcome-based, fixed-fee pricing model based on our extensive experience
  • Scope Creep Less than 5% of our clients require amendments to scope. Those that do occur are often the result of a scope expansion through growth.
  • Low Overhead Low overhead means a flexible financial structure

How much will your audit cost?

The cost of an ASV scan depends on the count and variability of endpoints. 100 endpoints that are all unique require more work than 100 endpoints which are mirrors of each other.

Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing:

  • Fixed-Fee Using an outcome-based, fixed-fee pricing model based on our extensive experience
  • Scope Creep Less than 5% of our clients require amendments to scope. Those that do occur are often the result of a scope expansion through growth.
  • Low Overhead Low overhead means a flexible financial structure