Choosing an Approved Scanning Vendor
An Approved Scanning Vendor (ASV) is a data security firm using a scanning solution to determine
whether or not the customer meets the PCI DSS external vulnerability scanning requirement. ASVs
are qualified by the PCI Security Standards Council to perform external network and system scans as
required by the PCI DSS. An ASV may use its own software or an approved commercial or open source
solution. ASV solutions must be non-disruptive to customers’ systems and data – they must never
cause a system reboot, or interfere with or change domain name server (DNS) routing, switching,
or address resolution. Root-kits or other software should not be installed unless part of the solution
and pre-approved by the customer. Tests not permitted by the ASV solution include denial of service,
buffer overflow, brute force attack resulting in a password lockout, or excessive usage of available
communication bandwidth. An ASV scanning solution includes the scanning procedures and tool(s), the
associated scanning report, and the process for exchanging information between the scanning vendor
and the scan customer. ASVs may submit compliance reports to the acquiring institution on behalf of
a merchant or service provider, if agreed by the ASV and their customer. A list of ASVs is available at
www.pcisecuritystandards.org/approved_companies_providers/approved_scanning_vendors.php.