RecurringContinuous projects

VA and PCI ASV, run cycle by cycle.

Vulnerability assessments and PCI ASV scans come round again and again. Cerberos Nexus runs them as continuous projects: cycles on a set cadence, scans that start on schedule, findings followed from scan to scan, and a clear status for every cycle.

How it works

A cycle, then
the next one.

Six steps repeat every cycle. Findings carry across cycles, so each scan shows what is new, what keeps coming back and what looks fixed.

01

Scope

Each cycle records which assets are in or out of scope, so the scope behind every result is on file.

02

Scan

Primary scans start on schedule or on demand in Nessus, Nexpose or Burp Pro, or arrive as imports.

03

Track

Repeat detections roll up into one finding, followed across hosts and scans, cycle after cycle.

04

Share

Findings, scans and published reports sit in the Client Portal beside the cycle's status.

05

Dispute

The client raises disputes with evidence and reviewers decide. ASV disputes need the QA reviewer.

06

Verify

Verification scans flag findings that look fixed, and an analyst confirms each one.

Scans and imports

Results from every source.

Scheduled scansPrimary scans start on their own when the schedule says so.
Launched scansRun on demand through Nessus, Nexpose or Burp Pro.
Imported resultsExports from Nessus, Nexpose, Burp, Acunetix or CSV.
Verification scansA rescan that shows which findings look fixed.
Ad hoc scansAn extra scan when something changes mid-cycle.
Compare

One-time or continuous?

Both run in Cerberos Nexus and both reach the client's portal. The difference is how the work repeats.

AspectPenetration testContinuous project
ShapeOne project with a start and an end.Cycles that repeat on a cadence.
CadenceWhenever the client books it.Monthly to annual. PCI ASV is always quarterly.
ScopeAgreed for the project.Decided again for each cycle.
FindingsLogged by testers and scored with CVSS 3.1.From scans and imports, rolled up across hosts and scans.
FixesConfirmed by a retest the client requests.Flagged by verification scans, confirmed by an analyst.
Closes withA delivered report.Cycle reports and, for PCI ASV, an attestation.
Project setup

Three things define a project.

Managers set them when the project is created, and can change the cadence and quotas as the contract changes. The client and the assessment type stay fixed.

01

Assessment type

Vulnerability assessment or PCI ASV, matching a service the client has.

02

Cadence

Monthly, quarterly, biannual, annual or ad hoc. PCI ASV is always quarterly.

03

Quotas

The networks and domains in scope, and the primary scans included.

FAQ

Continuous projects, answered.

Vulnerability assessments and PCI ASV scanning. Penetration tests, segmentation tests and red team engagements each have their own workflow in the same platform.

Ready when
your auditor is.

See your engagements, findings and retests come together in one record, on a workflow like yours.