With the content scans, Nessus can be used to scan the network for PCI DSS issues such as unprotected credit card numbers, social security numbers, or drivers license numbers. It can also be used to scan for information leakage requests by searching for files that contain source code, HR compensation data or corporate financial spreadsheets.
The necessary plugins and .audit files can be downloaded from Nessus if you are a Direct Feed customer. Tenable has security configuration compliance templates for the following standards, but customers can also scan against custom security configurations to insure internal compliance:
- NIST
- GLBA
- CERT
- HIPAA
- NSA
- DISA
