VA and PCI ASV, run cycle by cycle.
Vulnerability assessments and PCI ASV scans come round again and again. Cerberos Nexus runs them as continuous projects: cycles on a set cadence, scans that start on schedule, findings followed from scan to scan, and a clear status for every cycle.
A cycle, then
the next one.
Six steps repeat every cycle. Findings carry across cycles, so each scan shows what is new, what keeps coming back and what looks fixed.
Scope
Each cycle records which assets are in or out of scope, so the scope behind every result is on file.
Scan
Primary scans start on schedule or on demand in Nessus, Nexpose or Burp Pro, or arrive as imports.
Track
Repeat detections roll up into one finding, followed across hosts and scans, cycle after cycle.
Share
Findings, scans and published reports sit in the Client Portal beside the cycle's status.
Dispute
The client raises disputes with evidence and reviewers decide. ASV disputes need the QA reviewer.
Verify
Verification scans flag findings that look fixed, and an analyst confirms each one.
Results from every source.
One-time or continuous?
Both run in Cerberos Nexus and both reach the client's portal. The difference is how the work repeats.
Three things define a project.
Managers set them when the project is created, and can change the cadence and quotas as the contract changes. The client and the assessment type stay fixed.
Assessment type
Vulnerability assessment or PCI ASV, matching a service the client has.
Cadence
Monthly, quarterly, biannual, annual or ad hoc. PCI ASV is always quarterly.
Quotas
The networks and domains in scope, and the primary scans included.
Continuous projects, answered.
Vulnerability assessments and PCI ASV scanning. Penetration tests, segmentation tests and red team engagements each have their own workflow in the same platform.
Its latest scan with evidence must cover the whole scope and leave no failing findings. Findings with an accepted dispute do not count against it. Vulnerability assessment cycles complete rather than pass or fail.
Yes. Clients raise disputes with evidence from the Client Portal, and reviewers accept or reject them. For PCI ASV, only the ASV QA reviewer can accept a dispute.
Someone other than the QA reviewer, and only once the quarter is passing and QA has signed it off. Any change to the quarter after sign-off clears the sign-off.
Run a verification scan. Findings it no longer detects are flagged as looking fixed, and an analyst confirms each one before it is resolved.