{"id":8373,"date":"2024-08-01T10:03:15","date_gmt":"2024-08-01T15:03:15","guid":{"rendered":"https:\/\/iqcol.com\/?p=8373"},"modified":"2024-08-01T10:15:07","modified_gmt":"2024-08-01T15:15:07","slug":"analisis-de-vulnerabilidades-y-proveedores-aprobados","status":"publish","type":"post","link":"https:\/\/iqcol.com\/en\/analisis-de-vulnerabilidades-y-proveedores-aprobados\/","title":{"rendered":"Complete guide to Vulnerability Analysis and Providers Approved by PCI"},"content":{"rendered":"<p>Data security is critical to any business that handle online transactions. The Data Security Standard PCI (PCI DSS) has established strict requirements to protect the information of the payment, and one of the key components is the analysis of vulnerabilities, external made by Analytics Providers that are Approved (ASV).<\/p>\n<h2><strong>What is the Analysis of Vulnerabilities ASV?<\/strong><\/h2>\n<p>The analysis of vulnerabilities ASV is a comprehensive assessment by approved suppliers to identify and mitigate potential risks in e-commerce systems. These analyses are essential to ensure that the environments of payment are safe and comply with the standards of the PCI DSS.<\/p>\n<h2><strong>New Requirements in PCI DSS v4.x<\/strong><\/h2>\n<p>With the update to PCI DSS v4.x you have added specific requirements for the traders who use the self-assessment questionnaire (SAQ) A. These new requirements are designed to address violations are common and increase safety in environments of e-commerce.<\/p>\n<p>Traders SAQ now must complete the Requirement 11.3.2 of <a href=\"https:\/\/www.pcisecuritystandards.org\/\" target=\"_blank\" rel=\"noopener\">PCI DSS<\/a>that requires evidence of approval of scans external performed by an ASV at least once every three months. This step is crucial to minimize the risk of breaches that could compromise the payment transactions.<\/p>\n<figure id=\"attachment_8374\" aria-describedby=\"caption-attachment-8374\" style=\"width: 300px\" class=\"wp-caption alignleft\"><img fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-8374 size-medium\" src=\"https:\/\/iqcol.com\/wp-content\/uploads\/2024\/08\/Analisis-de-Vulnerabilidades-300x225.jpg\" alt=\"An\u00e1lisis de Vulnerabilidades\" width=\"300\" height=\"225\" title=\"\" srcset=\"https:\/\/iqcol.com\/wp-content\/uploads\/2024\/08\/Analisis-de-Vulnerabilidades-300x225.jpg 300w, https:\/\/iqcol.com\/wp-content\/uploads\/2024\/08\/Analisis-de-Vulnerabilidades-1024x768.jpg 1024w, https:\/\/iqcol.com\/wp-content\/uploads\/2024\/08\/Analisis-de-Vulnerabilidades-768x576.jpg 768w, https:\/\/iqcol.com\/wp-content\/uploads\/2024\/08\/Analisis-de-Vulnerabilidades-16x12.jpg 16w, https:\/\/iqcol.com\/wp-content\/uploads\/2024\/08\/Analisis-de-Vulnerabilidades-440x330.jpg 440w, https:\/\/iqcol.com\/wp-content\/uploads\/2024\/08\/Analisis-de-Vulnerabilidades-240x180.jpg 240w, https:\/\/iqcol.com\/wp-content\/uploads\/2024\/08\/Analisis-de-Vulnerabilidades.webp 1200w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><figcaption id=\"caption-attachment-8374\" class=\"wp-caption-text\">Analysis of Vulnerabilities<\/figcaption><\/figure>\n<h2><strong>Who Applies?<\/strong><\/h2>\n<p>These scanning requirements ASV apply to e-commerce systems which:<\/p>\n<ol>\n<li>Redirected to the payment transaction to a third party service provider (TPSP) that complies with PCI DSS.<\/li>\n<li>Include a page or form of integrated payment from a TPSP to comply with PCI DSS.<\/li>\n<\/ol>\n<p>The goal is that traders identify and remediate vulnerabilities that can expose your link to the payment page of the TPSP, thereby ensuring the security of the transactions.<\/p>\n<h2><strong>Resources and Key Considerations<\/strong><\/h2>\n<p>The PCI Security Standards Council has created this guide to provide educational resources, and answer frequently asked questions about the Requirement 11.3.2 of the PCI DSS. This guide is indispensable for those traders who are completing this requirement for the first time and need to better understand the process of scanning and the benefits of working with an ASV.<\/p>\n<h2><strong>Some of the topics covered include:<\/strong><\/h2>\n<ul>\n<li>Importance of the analysis of vulnerabilities.<\/li>\n<li>How to select an approved scanning vendor.<\/li>\n<li>Frequency and requirements of the scans.<\/li>\n<li>Steps to resolve the vulnerabilities identified.<\/li>\n<\/ul>\n<h2><strong>Conclusion<\/strong><\/h2>\n<p>To maintain the security of payment data is a critical responsibility for any trader. To follow the requirements of the PCI DSS and perform regular scans with analytics service providers approved, the traders can protect their e-commerce systems and provide an experience of a secure payment for their clients.<\/p>\n<p>Explore the complete guide and make sure to comply with the highest safety standards!<\/p>\n<h3><a href=\"https:\/\/docs-prv.pcisecuritystandards.org\/PCI%20DSS\/Supporting%20Document\/PCI%20SSC%20ASV%20Resource%20Guide.pdf?hsCtaTracking=61b9f4c1-279b-43df-a6e0-6b05d3c4c7f9%7C0541d1fc-dc1c-4e11-95f8-3b9a1f1eb766\" target=\"_blank\" rel=\"noopener\">See the resource guide<\/a><\/h3>\n<h3><a href=\"https:\/\/iqcol.com\/en\/nuestro-blog\/\">Discover more tips and strategies to protect your digital business on our blog<\/a><\/h3>\n<h6>Fuente: https:\/\/n9.cl\/iq_information_quality<\/h6>\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>La seguridad de los datos es fundamental para cualquier negocio que maneje transacciones en l\u00ednea. El Est\u00e1ndar de Seguridad de Datos PCI (PCI DSS) ha establecido requisitos estrictos para proteger la informaci\u00f3n de pago, y uno de los componentes clave es el an\u00e1lisis de vulnerabilidades externos realizados por Proveedores de An\u00e1lisis Aprobados (ASV). \u00bfQu\u00e9 es [&hellip;]<\/p>","protected":false},"author":1,"featured_media":8374,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-8373","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sin-categorizar"],"blocksy_meta":[],"_links":{"self":[{"href":"https:\/\/iqcol.com\/en\/wp-json\/wp\/v2\/posts\/8373","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/iqcol.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/iqcol.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/iqcol.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/iqcol.com\/en\/wp-json\/wp\/v2\/comments?post=8373"}],"version-history":[{"count":0,"href":"https:\/\/iqcol.com\/en\/wp-json\/wp\/v2\/posts\/8373\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/iqcol.com\/en\/wp-json\/wp\/v2\/media\/8374"}],"wp:attachment":[{"href":"https:\/\/iqcol.com\/en\/wp-json\/wp\/v2\/media?parent=8373"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/iqcol.com\/en\/wp-json\/wp\/v2\/categories?post=8373"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/iqcol.com\/en\/wp-json\/wp\/v2\/tags?post=8373"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}