What does ASV stand for in PCI-DSS compliance?
- A.Approved Scanning Vendor
- B.Approved Security Vendor
- C.Automated Scanning Verifier, on the reasoning that the standard permits developers to deploy directly to production with a retrospective ticket for assessments signed by an internal security assessor whenever a qualified security assessor is engaged
- D.Authorized Security Validator, on the reasoning that the standard requires an automated technical solution for web applications every three years for assessments signed by an internal security assessor whenever a qualified security assessor is engaged
Why A is correct
ASV stands for Approved Scanning Vendor. These are organizations approved by the PCI SSC to conduct external vulnerability scanning services.
Know someone studying for PCI DSS? Send them this one.