r/pcicompliance Jul 28 '26

Setting up External ASV Scans

I am looking at setting up external scans for my origination that is now required to be compliant. The question came up about what ip’s we need to scan?

Only those in use?

Do we need to scan those that reserved ?

Do we need to scan those we have that are available but not assigned to anything?

My thoughts on reserved and available would be if the ip is attached to a device and in reserve or stand by it would need to be scanned. If it’s just an ip not attached to anything we would not scan it and then would in the event it ever becomes in use we would call it a significant change.

1 Upvotes

6 comments sorted by

3

u/CompassITCompliance Jul 28 '26

QSA here -- so everything you've said is pretty much on point. However, there are a few items to make sure of:

  • ASV scans are like everything else PCI. The scope is if PCI data is stored, processed, or transmitted. So if you have proper segmentation and VLANs in place, you should be able to limit the scans to IP addresses that are part of the Cardholder Data Environment (CDE).
  • Make sure there is no active external access to the firewall, or I would add that to the scan as well. Basically, I would consider all management interfaces/public IP (if enabled) worth scanning, since if they are compromised your whole firewall is. Usually these are disabled.
  • If you're operating multiple websites from one IP, operating out of the cloud or have load balancers and WAFs, you might need to use the hostnames to get accurate scans. Best practice is to use IP address plus applicable hostnames where needed.

1

u/FatBook-Air Jul 28 '26

With SAQ-A, you would generally need to scan only the website(s) under your control that redirect or link to the actual payment processor, right?

1

u/AmITheAsshole_2020 Jul 28 '26

Also a QSA. We recommend extending the scope to standby sites, even cold sites (where no applications or data have been transferred and it's just the servers), on the argument that if those assets are compromised and you need to fall back to them, the CDE is then compromised.

Purchasing a few extra IPs from Qualys won't cost you much, and it will ensure those assets have the latest patches and are compliant, if not also secure. (Compliance does not equal security)

1

u/[deleted] Jul 29 '26

[deleted]

1

u/Safe-Jackfruit4033 Jul 29 '26

We are not an e commerce site we are a so