PCI Security Standards DSS Approved Scanning Vendor

PCI DSS ASV Vulnerability Scans

Following a number of instances of hackers stealing cardholder information and using it to commit fraud, the major payment card providers including Visa, MasterCard and American Express have developed a number of industry wide security standards that merchants must adhere to in order to process card transactions.

The Payment Card Industry Data Security Standard (PCI DSS) is focused on online transactions, however it applies to any company that stores, processes or transmits cardholder data and consequently effects merchants with physical stores as well as banks, processors and service providers.

To comply fully with the PCI DSS an organisation must meet the following 12 key requirements:

  1. Install and maintain a firewall configuration to protect cardholder data
  2. Do not use vendor-supplied defaults for system passwords and other security parameters
  3. Protect stored cardholder data
  4. Encrypt transmission of cardholder data across open, public networks
  5. Use and regularly update anti-virus software
  6. Develop and maintain secure systems and applications
  7. Restrict access to cardholder data by business need-to-know
  8. Assign a unique ID to each person with computer access
  9. Restrict physical access to cardholder data
  10. Track and monitor all access to network resources and cardholder data
  11. Regularly test security systems and processes
  12. Maintain a policy that addresses information security

Dionach is a PCI Approved Scanning Vendor (ASV) and is accredited to undertake PCI DSS Vulnerability Scans to fulfil requirement 11 of the Standard.

The outputs of a Dionach PCI DSS Vulnerability Scan are two reports: one an executive summary and the other a list of technical issues. Dionach will discuss any non-compliant issues with you, and determine whether a fix and retest is required or whether they are false positives. The aim is to ensure an efficient route to a passing quarterly scan report.

Contact us now for a free no-obligation initial consultation