ASV Scans and PCI-DSS Certification

Introduction

Some payment service providers require PCI-DSS certification, for which ASV (Approved Scanning Vendor) scans are an essential and important component of the certification process. To help you achieve the best possible results in these scans, this article describes several ways to thoroughly secure your server.


You can commission the ASV scan directly through our partner usd AG. You can request the ASV scan directly via the usd PCI platform.



Update Your Server

To prevent security vulnerabilities that can arise from outdated applications or an outdated operating system, we recommend that you regularly update the applications installed and in use on your server, as well as the server’s operating system.


Managed Servers

As part of our server support, we perform automatic minor updates to the operating system and applications in accordance with our Update Policy for Managed Servers.


Unmanaged Servers

At the Unmanaged support level, you are responsible for applying all automatic and security patches. Please note that we do not have access to your server at this support level.


Please note that software packages currently installed on the server may already be protected against known security vulnerabilities, as the ASV scan report may may recommend versions of software packages that are only available through beta channels of the corresponding repository and may lead to unstable or unexpected server behavior.



Access Restrictions via Firewall Rules

It is often unavoidable to use server services that allow a connection to the server.

Examples include connections via SSH, FTP(S) / SFTP, or access to the Plesk Control Panel.

In these cases, however, it is generally not necessary to allow connections from any IP address. A simple way to restrict these connections is to use your server’s cloud firewall, since no changes to the actual server configuration are required and unwanted connections can be effectively blocked in advance.


The following is a general example of a set of firewall rules that provides basic security:


Please note that firewall rules must be defined in the correct order, as rules are evaluated in descending order and the evaluation stops immediately once the first rule matches.


  • General requests to the server—such as those from visitors to your website—should only be allowed on port 80 (HTTP) and port 443 (HTTPS)

  • SSH and FTP(S)/SFTP access should only be allowed from specific IP addresses. To determine your public IP address, you can use our IP tool. You can access it via the following URL:

    https://ip.creoline.com/

  • To ensure that access to your control panel—such as Plesk—remains possible, access should be restricted to specific IP addresses that are actually in use. For Plesk, port 8443 must be opened by default.

  • All other incoming connections will be blocked


To avoid unintended restrictions, you should check in advance—or have someone check for you—to determine which services and connection options are actually used and required, as additional ports may need to be opened depending on the application.

A common and widely used example of this is data transfer via FTP(S).


You can find a corresponding overview for our server solutions at the following URL:

Server Service Ports



Avoid Default Login Credentials

Some applications use default login credentials to provide access for initial setup after installation. Depending on the application, access cannot be restricted—or can only be restricted to a limited extent—via your server’s firewall. One example of this is the Shopware administration interface, since it is accessed via a specific URL and thus uses port 80 (HTTP) and port 443 (HTTPS), and these ports are generally not restricted in order to allow visitors to access your website.

For this reason, it is essential to change the default login credentials after provisioning or installation to prevent unauthorized access and the associated risks.


During the provisioning of our server solutions, the default login credentials are automatically changed and stored in your server’s password vault.



Request an ASV Scan

You can request an ASV scan directly through our partner usd AG. You can request the ASV scan directly via the usd PCI Platform.


More information about usd AG: