The PCI compliance standard requires that all merchants have quarterly external scans performed. These must be performed by an Approved Scanning Vendor (ASV). Only levels 1-3 are required to have quarterly scans. It is, however, recommended for level 4s. ASVs must be approved by the PCI standards council.
Additionally, the standard does require that firms have a yearly penetration test. This is different from scanning. Scans merely look for known exploits and weaknesses. A penetration test attempts to actually break into the network and gain access to resources. A penetration test is much more involved. Companies are not required to outsource this function, but realistically they should, since it would be difficult to prove that good penetration testing skills exist in-house.
#206 - 1441 Ellis Street Kelowna, BC, V1Y 6P5 p: 250.862.8010
Sitemap