<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PCI Compliance Requirements &#187; ASV</title>
	<atom:link href="http://www.pci-compliance-requirements.net/tag/asv/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pci-compliance-requirements.net</link>
	<description>PCI Compliance Requirements</description>
	<lastBuildDate>Wed, 26 May 2010 16:39:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>PCI Scanning</title>
		<link>http://www.pci-compliance-requirements.net/pci-scanning/</link>
		<comments>http://www.pci-compliance-requirements.net/pci-scanning/#comments</comments>
		<pubDate>Sat, 28 Mar 2009 17:18:34 +0000</pubDate>
		<dc:creator>PCI Compliance Mentor</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ASV]]></category>
		<category><![CDATA[ASV Scanning Vendors]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PCI Scanning]]></category>

		<guid isPermaLink="false">http://www.pci-compliance-requirements.net/?p=23</guid>
		<description><![CDATA[PCI Scanning vendors are a very important part of PCI Scanning Compliance learn more about ASV Scanning Vendors.]]></description>
			<content:encoded><![CDATA[<p>What does PCI stand for?  It stands for &#8220;Payment Card Industry&#8221;.  In other words, credit cards such as MasterCard, Visa, Discover, etc.  If you are a business owner and accept credit cards for merchant payments, then you will more than likely be required to do a <strong>PCI Scanning</strong> process through an approved scanning vendor.  The following web address will give you a complete list of these approved PCI Scanning vendors:  <a href="https://www.pcisecuritystandards.org/">https://www.pcisecuritystandards.org/</a>. </p>
<p>The reason why <a href="http://www.trust-guard.com/PCI-Scanning-s/39.htm">PCI scanning</a> vendors were put into place is to create an additional level of protection for consumers by ensuring that merchants meet minimum levels of security when they store, process and transmit cardholder data.</p>
<p>Wikipedia has this to say about internet fraud of credit cards.  “Most internet fraud is done through the use of stolen credit card information which is obtained in many ways, the simplest being copying information from retailers, either online or offline. Despite efforts to improve security for remote purchases using credit cards, systems with security holes are usually the result of poor implementations of card acquisition by merchants. For example, a website that uses SSL to encrypt card numbers from a client may simply email the number from the webserver to someone who manually processes the card details at a card terminal. Naturally, anywhere card details become human-readable before being processed at the acquiring bank, a security risk is created. However, many banks offer systems where encrypted card details captured on a merchant&#8217;s webserver can be sent directly to the payment processor.”</p>
<p>In order to apply to be able to do this PCI Scanning a company has to first complete a Self-Assessment Questionnaire on an annual basis. During the Spring of 2008 a new SAQ was launched and was re-designed to make the questions more relevant to what merchants actually do. There are now four parts, and depending on which part best matches what a company does, will determine the number of questions that will need to be answered – and whether or not quarterly vulnerability scanning is required. Companies will also need to make sure they attest to the truthfulness and accuracy of their responses on the SAQ.</p>
<p>Scans help identify vulnerabilities and misconfigurations of websites and IT infrastructures containing externally facing IP addresses. This is very important for your company&#8217;s piece of mind. </p>
<p>Who has to comply to <strong>PCI scanning</strong>?  If you are a merchant or service provider and accept credit cards you must validate PCI compliance at least annually.</p>
<p>Even if you are a small business and only take a handful of cards on a daily basis, you still need to comply with the <a href="http://www.trust-guard.com/PCI-Scanning-s/39.htm">PCI scanning</a>.</p>
<p><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-init.js"></script><script>var domainAddress   = "http://www.letsgetsocialnow.com/";
					 var bookmarkPage    = "bookmarkthis.php";
					 var url     = "http://www.pci-compliance-requirements.net/pci-scanning/";
					 var title   = "PCI Scanning";
					 var js_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var css_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var img_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var bookmark_button_id = "bookmark_button_23";
					 </script><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-end.js"></script></p>]]></content:encoded>
			<wfw:commentRss>http://www.pci-compliance-requirements.net/pci-scanning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability Scanning</title>
		<link>http://www.pci-compliance-requirements.net/vulnerability-scanning/</link>
		<comments>http://www.pci-compliance-requirements.net/vulnerability-scanning/#comments</comments>
		<pubDate>Wed, 25 Feb 2009 21:02:34 +0000</pubDate>
		<dc:creator>PCI Compliance Mentor</dc:creator>
				<category><![CDATA[PCI Scanning]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<category><![CDATA[Approved Scanning Vendor]]></category>
		<category><![CDATA[ASV]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Vulnerability scanner]]></category>

		<guid isPermaLink="false">http://www.pci-compliance-requirements.net/?p=21</guid>
		<description><![CDATA[Unfortunately, we live in a world where identity theft and other electronic crimes are rampant.  As such, the PCI Council has compiled a number of specifications or shall we say requirements that must be put in place by all merchants accepting credit cards online and offline to provide Vulnerability Scanning. Inside a series of [...]]]></description>
			<content:encoded><![CDATA[<p>Unfortunately, we live in a world where identity theft and other electronic crimes are rampant.  As such, the PCI Council has compiled a number of specifications or shall we say requirements that must be put in place by all merchants accepting credit cards online and offline to provide <strong>Vulnerability Scanning</strong>. Inside a series of specifications as the number of &#8220;recommendations&#8221; set forth by the PCI Council designed to ensure that your company adheres to the regulations set forth by the Council.  One such recommendation is vulnerability scanning.</p>
<p>The primary goal of vulnerability scanning is to pinpoint and identify any device inside your network, which may be susceptible or vulnerable to threats.  It&#8217;s important to remember that not all vulnerability scanners are created equally.  And for this reason, you should do your homework prior to utilizing any vulnerability scanning vendor.</p>
<p><span id="more-21"></span></p>
<p>As of late, it has become increasingly important that online e-commerce retailers utilize vulnerability scanning in order to protect themselves from the many electronic threats lurking in the dark reaches of the Internet.  The use of a vulnerability scanner can help protect your network in your system from hackers and other electronic &#8220;vulnerabilities&#8221;.  The use of the vulnerability scanning is considered to be a proactive approach to protecting yourself and your customers during the process of e-commerce.</p>
<p>Running a vulnerability scan can reveal areas in your network that are weak or prone to attack.  This can allow you to make necessary changes to your network in order to protect yourself and your customers.<br />
As with anything else, it is important to note that the use of a vulnerability scanning is not foolproof.  It is important to combine the use of a scanning with other means of protection in order to ensure security.</p>
<p>As mentioned before, it&#8217;s a good idea to do your homework and review some of the available Approved Scanning Vendors on the market today.  You will find that researching available vulnerability scanning vendors to online resources is one of the smartest ways, and the most time efficient ways, to locate a high-quality vulnerability scanner.  You may find it in a fit to note that most vulnerability scanners are relatively simple to use.  A few simple instructions should have you up and running in no time.  If you find the use of <a href="http://www.trust-guard.com/Vulnerability-Scanning-s/69.htm">vulnerability scanning</a> to be too complicated, it is possible to find a professional to perform the service for you.</p>
<p>Remember, the reputation of your online business could be at stake, spending a little time in proactive research of your network could end up saving you lots of effort, time, and even money in the long run. So start your <strong>vulnerability scanning</strong> today.</p>
<p><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-init.js"></script><script>var domainAddress   = "http://www.letsgetsocialnow.com/";
					 var bookmarkPage    = "bookmarkthis.php";
					 var url     = "http://www.pci-compliance-requirements.net/vulnerability-scanning/";
					 var title   = "Vulnerability Scanning";
					 var js_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var css_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var img_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var bookmark_button_id = "bookmark_button_21";
					 </script><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-end.js"></script></p>]]></content:encoded>
			<wfw:commentRss>http://www.pci-compliance-requirements.net/vulnerability-scanning/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>PCI Compliance Scanning Companies</title>
		<link>http://www.pci-compliance-requirements.net/pci-compliance-scanning-companies/</link>
		<comments>http://www.pci-compliance-requirements.net/pci-compliance-scanning-companies/#comments</comments>
		<pubDate>Fri, 13 Feb 2009 22:00:32 +0000</pubDate>
		<dc:creator>PCI Compliance Mentor</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[PCI Scanning]]></category>
		<category><![CDATA[PCI Scanning Vendor]]></category>
		<category><![CDATA[ASV]]></category>
		<category><![CDATA[IP address]]></category>
		<category><![CDATA[PCI Compliance Scanning Companies]]></category>
		<category><![CDATA[PCI Compliant]]></category>
		<category><![CDATA[PCI Security Standards Council]]></category>
		<category><![CDATA[PCI Standard]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Website]]></category>

		<guid isPermaLink="false">http://www.pci-compliance-requirements.net/?p=13</guid>
		<description><![CDATA[Learn what PCI Compliance scanning companies are our there and what to ask them. Learn what items and services you need in a PCI compliance scanning vendor.]]></description>
			<content:encoded><![CDATA[<p>A question that you need to be asking yourself once you have realized the importance of <strong>PCI Compliance</strong> is, &#8220;<em>What <a href="http://www.trust-guard.com/PCI-Compliance-s/65.htm">PCI compliance</a> scanning company to use?</em>&#8221; Once you have asked yourself this question then you need to start searching for a great company to help you on your way to security. Here are some questions to ask those companies:</p>
<ul>
<li>How many vulnerabilities do you scan for?
</li>
<li>Does your company offer Daily Scanning, Quarterly Scanning or both?</li>
<li>Does your company offer <strong>PCI Seals</strong> to place on my website to show my customers that they can trust me? (Very Important)</li>
<li>Is your company an ASV certified scanner or are you partnered up with an ASV Certified vendor?</li>
<li>How long does the process take?</li>
<li>Do you offer me PCI Compliance tools such as the Self Assessment Questionnaire (SAQ) and the Compliance Validation Basics information to help me become compliant?</li>
<li>Does the scanning vendor send you the scanning reports frequently or can you download them?</li>
<li>Will you support me in becoming PCI compliant?</li>
</ul>
<p>So make sure you save these questions or print out this post so that when you go to these PCI Compliance scanning vendors that you can ask these important questions. Lets go over each question in detail at this time to really understand their unique importance.</p>
<p><span id="more-13"></span></p>
<p><strong>How many vulnerabilities do you scan for?</strong></p>
<p>The number of vulnerabilities scanned for on you servers and external facing IP addresses is important due to the very fact that hackers are finding different ways all the time to hack into our information. The company that you go with to provide your PCI scanning needs to stay up-to-date on all the vulnerabilities that are out there.</p>
<p><strong>Does your company offer Daily Scanning, Quarterly Scanning or both?</strong></p>
<p>This is really a preference of yours. A lot of people including myself would want daily scanning mainly for the fact that I would want to show my visitors and customers that my site is scanned daily. But to become compliant with the PCI Security Standards Council all that you will need is Quarterly. So really it is up to you. Most companies offer at least quarterly so that should be a minimum requirement. </p>
<p><strong>Does your company offer <strong>PCI Seals</strong> to place on my website to show my customers that they can trust me?</strong></p>
<p>Placing a seal on your website letting your visitors know that your site is secure is so very important and is a must. Providing trust and confidence to your visitors and customers mean more sales, higher conversion rate and more repeat purchases. Make sure that the company that you are purchasing from has seals for all of their PCI scanning services.</p>
<p><strong>Is your company an ASV certified scanner or are you partnered up with an ASV Certified vendor?</strong></p>
<p>To be in compliance with the PCI Security Standards you must be scanned by an approved ASV certified vendor. So when you are shopping around this is a must. Some companies partner directly with ASV certified companies, so and if you can&#8217;t find them listed as an ASV certified scanner, simply ask them who their ASV certified partner is.</p>
<p><strong>How long does the process take?</strong></p>
<p>The actual process of becoming PCI compliant can take some time but to actually get your servers scanned should take that long to implement. So this is a great question to ask, if you are impatient like me.</p>
<p><strong>Do you offer me PCI Compliance tools such as the Self Assessment Questionnaire (SAQ) and the Compliance Validation Basics information to help me become compliant?</strong></p>
<p>Having these tools are essential in becoming PCI compliant and your scanning vendor should have these readily available for you with simple explanations of how to fill them out. Granted you can find it all online but it is nice when the scanning vendor has it ready for you to fill out.</p>
<p><strong>Does the scanning vendor send you the scanning reports frequently or can you download them?</strong></p>
<p>Once you have been scanned your PCI scanning vendor should either send you the scanned reports to you by email or have a secure control panel where you can download them easily. It is that simple.</p>
<p><strong>Will you support me in becoming PCI compliant?</strong></p>
<p>Although the PCI scanning vendor really has nothing to do with you becoming compliant other than scanning your website for vulnerabilities and giving you the reporting required. It is important that they guide you through the process and give you a helping hand.</p>
<p>All of these things need to be answered the way you would like to hear them and if they are then you have found the correct company.</p>
<p>Trust Guard offers a great <a href="http://www.trust-guard.com/compare-trust-mark-services-s/5.htm">pci scanning comparison chart</a> that you really need to check out. They compare website verification companies and <strong>PCI compliance scanning companies</strong>. So learn more about <a href="http://www.trust-guard.com/pci-scanning-s/39.htm">Trust Guard PCI Scanning</a> and also compare <a href="http://www.trust-guard.com/McAfee-Secure-s/53.htm">McAfee Secure</a> and <a href="http://www.trust-guard.com/Control-Scan-s/45.htm">Control Scan</a>.</p>
<p>So there it is a great checklist of items to help you with your <strong>PCI compliance</strong> scanning vendor searching. Hope it has helped direct you in the correct path.</p>
<p><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-init.js"></script><script>var domainAddress   = "http://www.letsgetsocialnow.com/";
					 var bookmarkPage    = "bookmarkthis.php";
					 var url     = "http://www.pci-compliance-requirements.net/pci-compliance-scanning-companies/";
					 var title   = "PCI Compliance Scanning Companies";
					 var js_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var css_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var img_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var bookmark_button_id = "bookmark_button_13";
					 </script><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-end.js"></script></p>]]></content:encoded>
			<wfw:commentRss>http://www.pci-compliance-requirements.net/pci-compliance-scanning-companies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
