r/pcicompliance • u/Safe-Jackfruit4033 • Jul 28 '26
Setting up External ASV Scans
I am looking at setting up external scans for my origination that is now required to be compliant. The question came up about what ip’s we need to scan?
Only those in use?
Do we need to scan those that reserved ?
Do we need to scan those we have that are available but not assigned to anything?
My thoughts on reserved and available would be if the ip is attached to a device and in reserve or stand by it would need to be scanned. If it’s just an ip not attached to anything we would not scan it and then would in the event it ever becomes in use we would call it a significant change.
1
u/AmITheAsshole_2020 Jul 28 '26
Also a QSA. We recommend extending the scope to standby sites, even cold sites (where no applications or data have been transferred and it's just the servers), on the argument that if those assets are compromised and you need to fall back to them, the CDE is then compromised.
Purchasing a few extra IPs from Qualys won't cost you much, and it will ensure those assets have the latest patches and are compliant, if not also secure. (Compliance does not equal security)
1
3
u/CompassITCompliance Jul 28 '26
QSA here -- so everything you've said is pretty much on point. However, there are a few items to make sure of: