Tenable PCI ASV Workbench

The Tenable PCI ASV Workbench is the landing page for your Tenable PCI ASV product. Here, you can begin your scan review and attestation process.

To access the Tenable PCI ASV Workbench:

  1. Log in to Tenable PCI ASV.

    The PCI ASV Workbench page appears. By default, the New Scan Results tab is active.

The PCI ASV Workbench includes the following tabs:

New Scan Results

The New Scan Results tab includes a table that shows all of your Tenable PCI ASV scans eligible for attestation.

This table includes the following information:

Column Details
Name The name of the Tenable PCI ASV scan.

Scan Type

The type of scan, for example, Nessus or WAS.
Assets The number of assets discovered during the scan.
Failures The number of failures discovered during the scan.
Import Status The status of the scan import job, for example, In Progress or Complete.
End Date The date and time at which the scan completed.
Actions

Click the button to view available actions for the scan:

  • Start Attestation — Begin an attestation for the scan. For more information, see Create an Attestation.

Scan Customer Review

The Scan Customer Review tab includes a table that shows all scans with attestation drafts that have not yet been submitted for ASV review. These scans require customer action before they can be submitted for ASV review.

This table includes the following information:

Column Details
Name The name of the attestation.

Owner

The owner of, or person who created, the attestation.
Assets The number of assets associated with the attestation.
Failures The number of failures associated with the attestation.
Status

The status of the attestation draft:

  • Pending Submission — You are actively working on the attestation report.

  • Needs Work — The attestation report has been sent back to you to provide more information to the assessor before the attestation can be resubmitted for ASV review.

ASV Message Where applicable, a message from the ASV reviewer regarding the attestation status.
Last Modified The date and time at which the attestation was last modified by a user.
Actions

Click the button to view available actions for the attestation:

  • Send to ASV Review — Submit the attestation for ASV review. For more information, see Submit an Attestation for ASV Review.

  • ASV Scan Report Summary — Download the ASV Scan Report Summary as a PDF export file.

  • ASV Scan Report Vulnerability Details — Download the ASV Scan Report for Vulnerability Details as a PDF export file.

  • Feedback — Download a feedback form for the attestation in PDF format.

  • Export — Export the attestation. For more information, see Export Attestations.

In ASV Review

The In ASV Review tab includes a table that shows all attestations that are currently in ASV review.

This table includes the following information:

Column Details
Name The name of the attestation.

Owner

The owner of, or person who created, the attestation.
Assets The number of assets associated with the attestation.
Failures The number of failures associated with the attestation.
Disputes The number of disputes associated with the attestation.
Status The status of the attestation, for example, Assigned or In-Review.
Note: An attestation may show a status of Info Provided even if there are still disputes that require additional information. In this case, the number of disputes that require additional information appears in parentheses beside the attestation status.
Last Modified The date and time at which the attestation was last modified by a user.
Actions

Click the button to view available actions for the attestation:

  • ASV Scan Report Summary — Download the ASV Scan Report Summary as a PDF export file.

  • ASV Scan Report Vulnerability Details — Download the ASV Scan Report for Vulnerability Details as a PDF export file.

  • Feedback — Download a feedback form for the attestation in PDF format.

  • Export — Export the attestation. For more information, see Export Attestations.

Attestations

The Attestation tab includes a table that shows all completed attestations.

This table includes the following information:

Tip: An attestation is completed when it recieves a status of Passed, Failed, or Closed.
Column Details
Name The name of the attestation.

Owner

The owner of, or person who created, the attestation.
Assets The number of assets associated with the attestation.
Failures The number of failures associated with the attestation.
Disputes The number of disputes associated with the attestation.
Status The status of the attestation, for example, Passed or Failed.
Last Modified The date and time at which the attestation was last modified by a user.
Actions

Click the button to view available actions for the attestation:

  • ASV Scan Report Summary — Download the ASV Scan Report summary as a PDF export file.

  • ASV Scan Report Vulnerability Details — Download the ASV Scan Report for Vulnerability Details as a PDF export file.

  • Feedback — Download a feedback form for the attestation in PDF format.

  • Export — Export the attestation. For more information, see Export Attestations.

PCI Licensing

The PCI Licensing tab allows you to view important details about your PCI license, your attestations, and your utilization of each.

Note: This tab only appears for users on the New Tenable PCI ASV Licensing Model. For more information, see Tenable PCI ASV Licensing.

This tab includes the following sections:

Attestation History

The Attestation History section includes a table that highlights the 25 most recent attestations submitted for review and their utilization against licensed assets.

This table includes the following attestation information:

Column Details
Attestation The name of the attestation.

Licensed Assets

The total number of licensed assets available to include within the attestation.
Asset Utilized The number of assets utilized within the attestation.
Utilization The percentage of assets utilized within the attestation as compared to the total number of available licensed assets. This column also includes a pie chart visualization of the utilization.

License Information

The License Information section includes basic information about your Tenable PCI ASV license and the time frame during which it is valid.

Here, you can view:

Row Details
Started Date The date and time at which your Tenable PCI ASV license was provisioned.

Expires

The date and time at which your Tenable PCI ASV license expires.
License Type The type of license purchased, for example Standard or Enterprise. For more information, see Tenable PCI ASV Licensing.