An Approved Scanning Vendor (ASV) is a data security firm using a scanning solution to determine
whether or not the customer meets the PCI DSS external vulnerability scanning requirement. Approved Scanning Vendor
are qualified by the PCI Security Standards Council to perform external network and system scans as
required by the PCI DSS. An Approved Scanning Vendor may use its own software or an approved commercial or open source
solution. Approved Scanning Vendor solutions must be non-disruptive to customers’ systems and data – they must never
cause a system reboot, or interfere with or change domain name server (DNS) routing, switching,
or address resolution. Root-kits or other software should not be installed unless part of the solution
and pre-approved by the customer. Tests not permitted by the Approved Scanning Vendor solution include denial of service,
buffer overflow, brute force attack resulting in a password lockout, or excessive usage of available
communication bandwidth. An Approved Scanning Vendor scanning solution includes the scanning procedures and tool(s), the
associated scanning report, and the process for exchanging information between the scanning vendor
and the scan customer. Approved Scanning Vendor may submit compliance reports to the acquiring institution on behalf of
a merchant or service provider, if agreed by the Approved Scanning Vendor and their customer. A list of Approved Scanning Vendor is available at
www.pcisecuritystandards.org/approved_companies_providers/approved_scanning_vendors.php.