Answered step by step
Verified Expert Solution
Question
1 Approved Answer
Your organization is required to conduct quarterly ASV ( Approved Scanning Vendor ) scans as part of PCI DSS compliance. However, due to unforeseen circumstances,
Your organization is required to conduct quarterly ASV Approved Scanning Vendor scans as part of PCI DSS compliance. However, due to unforeseen circumstances, the scheduled ASV scan for this quarter was missed. In this situation, which of the following would be an acceptable compensating control to address the missed ASV scan?
Compensating with an increased frequency of the next ASV scan eg conducting the next scan after one month instead of three to ensure quarterly coverage.
Conducting an external penetration test by a certified ethical. hacker to ensure the security of the network, which provides an alternative assessment of vulnerabilities.
Implementing a manual vulnerability assessment by an internal security team to assess vulnerabilities and report findings to meet compliance requirements.
Continuing with business as usual and conducting the ASV scan as soon as possible to make up for the missed quarter.
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started