The passing scan that proves nothing
A green ASV scan says only one thing: nothing critical was found in what was scanned. It says nothing about the real question, namely whether the right things were scanned. Why the scan scope is the assessment point in PCI DSS, and why the chain of quarterly scans counts as much as any single result.
A passing ASV scan feels like security. Green checkmark, report filed, quarter done. What it actually states is more modest: nothing critical was found in what was scanned. About the question that comes up first in an assessment, it says nothing. Namely whether the right things were scanned.
The scope is the assessment point, not the result
PCI DSS requires quarterly external vulnerability scans by an Approved Scanning Vendor in requirement 11.3.2. The scan itself is the easy part, handled by an approved provider. Harder is what comes before: which systems belong to the cardholder data environment? Which external addresses and services count? And if a component was excluded from the scan scope, why? An assessor asks in exactly that order, and an exception without documented justification is more uncomfortable than a finding with a treatment plan.
The chain counts, not the single checkmark
Then there is the time dimension. A scan result holds for 90 days, after which the next is due. Whoever scans cleanly in spring and then skips a quarter over the summer no longer has an unbroken chain for that year, however good the individual results were. And a failed scan is not an end state: it requires remediation and a rescan until the result holds. Whoever does not manage this as a chain quickly loses track of which rescan belongs to which original scan.
How isidaten runs scan management
The new PCI DSS module maps both. The cardholder data environment is kept with its components, and whoever excludes something from the scan scope must justify it. Quarterly scans run as a chain with rescans and 90 days of validity; due-date reminders arrive 30, 14 and 7 days ahead rather than afterwards. Findings are scored by the rules of the ASV Program Guide, including the CVSS threshold, automatic failures and the exception for denial-of-service checks; observations require an explanation. Alongside sits the requirement catalog with 12 requirements across six goal areas, and a readiness comparison places your own view of the attack surface next to the scan scope, so gaps surface before the quarterly scan rather than after.
More is shown on the PCI DSS solution page and the module page. Why your own attack surface is the starting point was covered here recently.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.