We begin each project by defining the list of external targets. Per the ASV Program Guide this is all externally accessible system components owned or utilized by the scan customer that are part of the cardholder data environment (CDE), any externally facing system component that may provide access to the CDE, and those which could impact the security of the CDE.
After the agreement and authorization letter are executed, a timeline is established to conduct scans. This is to ensure that Schellman and the Client are fully aware of the what, who, when, why, and how prior to the beginning of testing.
The kickoff is considered the start of the engagement. If needed, Schellman will schedule a call at the beginning of, or just prior to, the kickoff to finalize any outstanding items, review AuditSource (the proprietary project management portal) and address any questions.
By including communication prior to starting, Schellman ensures that no last-minute changes to the project or team have occurred and the Client has the plan prior to beginning the scans.
The scan process begins with discovery, even if the scope remains unchanged. From these results, detailed scanning occurs. The outputs from this phase are the basis for reporting and recommendation of actions.
Schellman has a no surprise policy and critical items will be posted to AuditSource as soon as they are reviewed.
Schellman’s testing methodology ends with reporting, but the entire assessment is focused on creating a deliverable that is clear, concise, and accurate.
Schellman’s report takes into account the entire process and customizes a report for each Client. The scan results will be provided within one week after the scan concludes. Within AuditSource, like vulnerabilities are aggregated for ease of review while detailed findings are provided to the client for downloading and analysis.
Upon correction of vulnerabilities, Schellman will rescan for those specific issues.
The cost of an ASV scan depends on the count and variability of endpoints. 100 endpoints that are all unique require more work than 100 endpoints which are mirrors of each other.
Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing: