How ASV Scan Works in Modern IT Society

How ASV Scan Works in Modern IT Society 1

ASV scanning is a unique and perfect automated check of all points of connection of the information infrastructure to the Internet for vulnerabilities. Today, the topic of security is probably the most relevant in modern society. We all buy or sell in one way or another on the Internet. We enter our personal data, including the data of our cards, making a large number of transactions. We all want to be sure that our data is safe and processed properly.

Therefore, the largest payment systems have developed PCI DSS. It is the global standard for the security of your payments and personal data. Companies that fall under the data processing list are required to conduct ASV scans on a quarterly basis. This is a high-level test and it helps to find vulnerabilities in the architectures of the IT technologies of these companies.

Statistics for 2019 show that in the United States alone, more than 650 thousand cases of identity theft have been officially registered. The vast majority of these thefts are personal bank card details. At the same time, if attackers gain access to bank cards and CVC2 or CVV numbers, then the fault lies with the company that processed this data. It is for such cases that ASV scanning is carried out and the companies responsible for this are obliged to conduct it regularly, in order to avoid such unpleasant incidents.

ASV scan is a procedure that takes place on a quarterly basis. To do this, a check is carried out directly from all points of connection to the Internet for vulnerabilities. Developed by the Payment Card Industry Data Security Standards Board (sponsored by American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa, Inc.). This check has all PCI DSS security standards. This check applies to all organizations that process, store or transmit the data of holders of bank payment cards. There is an international classification standard based on the volume of transactions. This number of transactions takes place every year. So, below will be given 4 levels.

4 Level Companies Conducting ASV Scanning

ASV scan is a quarterly procedure. To do this, a check is carried out directly from all points of connection to the Internet for vulnerabilities. Developed by the Payment Card Industry Data Security Standards Board (sponsored by American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa, Inc.). This check has all PCI DSS security standards. This check applies to all organizations that process, store or transmit the data of holders of bank payment cards. There is an international classification standard based on the volume of transactions. This number of transactions takes place every year. So, below will be given 4 levels.

The description of the levels will go from the largest (4) to the smallest (1). This principle can be explained by the fact that the 4th level falls under a smaller volume of transactions per year, and the first one is more than six million.

  • Fourth level: for asv scanning companies that process up to 20 thousand transactions per year. This falls under the quarterly scanning of external addresses for vulnerabilities and completing the self-assessment sheet. This level (as well as the third) is subject to the least amount of verification.
  • Third level: – companies that process from 20 thousand to 1 million transactions per year (similar requirements as for companies of the 4th level).
  • Second level: – companies that process from 1 million to 6 million transactions per year. Such companies are required to undertake quarterly scans with the involvement of the entire auditor company.
  • The Firstmore than 6 million transactions per year. These companies are required to undertake quarterly scans with only an independent auditor.

More About ASV Scanning

PCI DSS stands for Payment Card Industry Data Security Standard. It is the main document that protects information in the payment card industry. It was developed by the PCI SSC (Payment Card Industry Security Standards Council). The standard defines the requirements for ensuring the security of transmission, storage, processing of data of cardholders of international payment systems – MPS: MasterCard, Visa, American Express, JCB Card, Diners Club International.

According to authoritative sources, various international payment systems have specific requirements for the PCI DSS compliance verification process. These different stages of confirmation vary for organizations. Depending on the number of card transactions they process. There are the following methods for confirming compliance with PCI DSS requirements:

  • external QSA audit (English) performed by a PCI QSA company at the facility of the auditee;
  • self-assessment performed by the organization on its own with the completion of a self-assessment sheet (SAQ).
  • The conformity verification method, or combination of methods, is selected depending on the level of the merchant or service provider.

It is also worth noting that the people in charge of ASV scans have an important responsibility. They reserve the obligation to ensure that their AVS scanning solution is supported in terms of security and integrity for their vendors. Also, it will not in any way affect the optimal performance of the client scanning environment.

This will also be included in all required client and ASV certifications in the scan report in accordance with this document and the applicable ASV program requirements. It also guarantees the company the provision of all documentation on ASV scarring. This is necessary to meet or fail to meet scanning client components for external vulnerability scanning.

By purchasing services from Hostry, you can be sure that your payment data will be reliably protected. Cooperation with suchpayment systems as Vetotel, PayPal, CoinPayments, Webmoney and many others gives a guarantee for this. The Hostry team is very concerned about this and completely trusts the ASV scanning procedure to such payment systems.