Quantcast
Channel: PCI Compliance Requirements
Viewing all articles
Browse latest Browse all 9

PCI Compliance Scanning Companies

$
0
0

A question that you need to be asking yourself once you have realized the importance of PCI Compliance is, “What PCI compliance scanning company to use?” Once you have asked yourself this question then you need to start searching for a great company to help you on your way to security. Here are some questions to ask those companies:

  • How many vulnerabilities do you scan for?
  • Does your company offer Daily Scanning, Quarterly Scanning or both?
  • Does your company offer PCI Seals to place on my website to show my customers that they can trust me? (Very Important)
  • Is your company an ASV certified scanner or are you partnered up with an ASV Certified vendor?
  • How long does the process take?
  • Do you offer me PCI Compliance tools such as the Self Assessment Questionnaire (SAQ) and the Compliance Validation Basics information to help me become compliant?
  • Does the scanning vendor send you the scanning reports frequently or can you download them?
  • Will you support me in becoming PCI compliant?

So make sure you save these questions or print out this post so that when you go to these PCI Compliance scanning vendors that you can ask these important questions. Lets go over each question in detail at this time to really understand their unique importance.

How many vulnerabilities do you scan for?

The number of vulnerabilities scanned for on you servers and external facing IP addresses is important due to the very fact that hackers are finding different ways all the time to hack into our information. The company that you go with to provide your PCI scanning needs to stay up-to-date on all the vulnerabilities that are out there.

Does your company offer Daily Scanning, Quarterly Scanning or both?

This is really a preference of yours. A lot of people including myself would want daily scanning mainly for the fact that I would want to show my visitors and customers that my site is scanned daily. But to become compliant with the PCI Security Standards Council all that you will need is Quarterly. So really it is up to you. Most companies offer at least quarterly so that should be a minimum requirement.

Does your company offer PCI Seals to place on my website to show my customers that they can trust me?

Placing a seal on your website letting your visitors know that your site is secure is so very important and is a must. Providing trust and confidence to your visitors and customers mean more sales, higher conversion rate and more repeat purchases. Make sure that the company that you are purchasing from has seals for all of their PCI scanning services.

Is your company an ASV certified scanner or are you partnered up with an ASV Certified vendor?

To be in compliance with the PCI Security Standards you must be scanned by an approved ASV certified vendor. So when you are shopping around this is a must. Some companies partner directly with ASV certified companies, so and if you can’t find them listed as an ASV certified scanner, simply ask them who their ASV certified partner is.

How long does the process take?

The actual process of becoming PCI compliant can take some time but to actually get your servers scanned should take that long to implement. So this is a great question to ask, if you are impatient like me.

Do you offer me PCI Compliance tools such as the Self Assessment Questionnaire (SAQ) and the Compliance Validation Basics information to help me become compliant?

Having these tools are essential in becoming PCI compliant and your scanning vendor should have these readily available for you with simple explanations of how to fill them out. Granted you can find it all online but it is nice when the scanning vendor has it ready for you to fill out.

Does the scanning vendor send you the scanning reports frequently or can you download them?

Once you have been scanned your PCI scanning vendor should either send you the scanned reports to you by email or have a secure control panel where you can download them easily. It is that simple.

Will you support me in becoming PCI compliant?

Although the PCI scanning vendor really has nothing to do with you becoming compliant other than scanning your website for vulnerabilities and giving you the reporting required. It is important that they guide you through the process and give you a helping hand.

All of these things need to be answered the way you would like to hear them and if they are then you have found the correct company.

Trust Guard offers a great pci scanning comparison chart that you really need to check out. They compare website verification companies and PCI compliance scanning companies. So learn more about Trust Guard PCI Scanning and also compare McAfee Secure and Control Scan.

So there it is a great checklist of items to help you with your PCI compliance scanning vendor searching. Hope it has helped direct you in the correct path.


Viewing all articles
Browse latest Browse all 9

Trending Articles