External Vulnerability Scanning

PCIComplianceHubLast updated

Scanning performed from outside the network against every internet-facing IP address and domain in scope, to find what an attacker on the internet could reach. PCI DSS requires it on two triggers with different rules, and conflating them is a common error. The quarterly scan under Requirement 11.3.2 must be performed by an Approved Scanning Vendor and must produce a passing result: under the ASV Program Guide a vulnerability with a CVSS base score of 4.0 or above normally fails the scan, so findings are remediated and the scan repeated until it passes. The scan after a significant change, under Requirement 11.3.2.1, resolves the same 4.0-and-above findings but may be run by qualified personnel with organizational independence from the systems scanned; it need not be an ASV or a QSA. Scope completeness is agreed between the scan customer and the ASV, and getting it right is the responsibility of the organization, not the vendor.

In PCI DSS v4.0.1. 11.3.2, 11.3.2.1