Support
Launching Scans

Running official PCI DSS Scans and PCI DSS Group Scans

This document is for:
Invicti Enterprise On-Demand

With Invicti Enterprise, you can efficiently run individual PCI DSS scans or group scans, streamlining the compliance process and enabling you to generate approved compliance reports tailored to your business needs.

NOTE:

Invicti Enterprise provides two approaches for generating PCI DSS compliance reports to assist organizations in assessing their compliance with the Payment Card Industry Data Security Standard. Refer to Overview of Official and Informal PCI DSS Compliance Reports for more information.

This document explains how to configure and execute official PCI DSS scans and group scans within Invicti Enterprise.

IMPORTANT:

PCI DSS scans are available exclusively to Invicti Enterprise On-Demand users and for websites configured with the Agent Mode set to Cloud. For details on the differences between the Cloud and Internal Agent Modes, refer to the related documentation.

To create an official PCI DSS Compliance report, you must have the ‘Account can create PCI Scan’ option enabled. Contact your CSM if you have PCI DSS requirements, and need a report from a PCI ASV.

Prerequisites

Refer to our whitelisting guidelines for Invicti Enterprise On-Demand to see what IP addresses to whitelist to achieve full PCI coverage.

How to run an official PCI DSS scan

  1. In Invicti Enterprise, select Scans > New Scan from the left-side menu.
  2. Fill in the Target URL and the Scan Profile.
  3. Select the PCI Scan tab while configuring the scan options.

NOTE:

This PCI scan is related to but not identical to your Invicti Enterprise Scan. Scan options configured in Invicti Enterprise do not affect the PCI scan, and the two scans work independently of each other.

  1. Select the Create PCI Scan checkbox.

  1. Configure the remaining settings as required.
  2. Click Launch to start the scan.

NOTES:

  • Your Invicti Enterprise scan may finish before the PCI Scan is completed.
  • Pausing an ongoing Invicti Enterprise scan will also pause the PCI Scan.
  • Canceling an Invicti Enterprise scan will automatically cancel the PCI Scan as well.

How to run an official PCI DSS group scan

  1. In Invicti Enterprise, select Scans > New Group Scan from the left-side menu.
  2. Fill in the Target URL and the Scan Profile.
  3. Select the PCI Scan tab while configuring the scan options.

NOTE:

This PCI scan is related, but not identical, to your Invicti Enterprise Scan. Scan options configured in Invicti Enterprise do not affect the PCI scan, and the two scans work independently of each other.

  1. Select the Create PCI Scan checkbox.

  1. Configure the remaining settings as required.
  2. Click Launch to start the scan.

NOTES:

  • Your Invicti Enterprise scan may finish before the PCI Scan is completed.
  • Pausing an ongoing Invicti Enterprise scan will also pause the PCI Scan.
  • Canceling an Invicti Enterprise scan will automatically cancel the PCI Scan as well.

Configuring quarterly assessments

If you would like to set up quarterly assessment scans, our Technical Support team will be delighted to help. Open a support ticket, and we will set this up for you.

Running authenticated scans

PCI scanning does not require authenticated scans. However, authenticated scans can be performed using the Invicti Enterprise Vulnerability Scanning service. If you wish to conduct authenticated scans through Clone Systems, Invicti Enterprise Technical Support can help you with the appropriate setup.

Exporting official PCI DSS Reports

Invicti Enterprise allows you to export three types of PCI DSS reports:

  1. Attestation Report: This report provides the compliance results, summarizing whether the requirements have been met.
  2. Detailed Report: This report includes comprehensive information about the scanned IP addresses. It is intended for internal use only and should not be shared with third parties.
  3. Executive Report: This report outlines whether your environment complies with the ASV scanning guidelines established by the PCI Security Council.

For instructions on how to export these reports, refer to our Exporting the official PCI DSS Compliance Report document.