Trusted Partner Network (TPN) compliance
Meet MPA control TS-25 with scheduled external and internal scans, remediation tracking, and audit-ready reports for your TPN assessment.

What It Is
What is the Trusted Partner Network?
The Trusted Partner Network is a security initiative established by the Motion Picture Association (MPA). The TPN publishes the MPA Content Security Best Practices and registers compliant vendors as trusted partners. The TPN was established to improve security among vendors working in the entertainment industry and protect valuable content.
The Solution
MPA vulnerability scanning best practices
The MPA Best Practices v5.0 documentation describes the best practices and guidelines for vulnerability management. Specific to vulnerability scanning is control TS-25, which states:
Best Practices
Establish and regularly review a process and policy for Vulnerability Management, including vulnerability scans for both internal and external networks, cloud deployments, and virtual machines/containers, to include the following:
- For external IP ranges and hosts, perform scans monthly at a minimum
- For internal IP ranges and hosts, perform scans quarterly at a minimum
- Investigate and have a remediation plan for issues
- Perform a vulnerability scan after any major application or cloud infrastructure change
- Apply internal scan to WFH/remote worker endpoints where possible
Also scan the following if applicable:
- Production networks
- Non-Production networks
- Application Programming Interfaces (APIs)
Implementation Guidelines
Recommend implementing the following:
- Investigate and have a remediation plan for critical issues within 48 hours
- Authenticated and unauthenticated scanning
- Leverage Open Web Application Security Project (OWASP)
Benefits of using HostedScan
How can HostedScan help with your TPN strategy?
HostedScan provides automated vulnerability scanners and vulnerability management tools, which can help you achieve and maintain TPN compliance.
Scanners for every surface
Networks, servers, websites, and APIs covered by industry-leading vulnerability scanners in one platform.
Scheduled, automated scans
Run scans daily, weekly, or monthly. Get alerted the moment something new is found, without the manual effort.
Prioritized risk management
CVEs, OWASP Top 10, and exploitable weaknesses ranked by severity so your team knows exactly what to fix first.
Audit-ready reporting
Generate executive-ready vulnerability reports in seconds. Full coverage across all targets, prioritized by risk.
Our Customers
5,000+ MSPs and IT teams who move faster
Speed and power,
without the complexity
The world's leading vulnerability scanners, all in one platform.



