Preparing for the Qualys Vulnerability Integration

  • Release version: Xanadu
  • Updated August 1, 2024
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Preparing for the Qualys Vulnerability Integration

    This guide outlines the necessary steps to prepare for a successful integration of the Qualys Vulnerability Integration with your ServiceNow instance. Proper planning and execution of pre-integration tasks are crucial for optimal performance.

    Show full answer Show less

    Important Prerequisites

    • Validate your instance sizing to accommodate the expected number of vulnerable items; consult Customer Service and Support if unsure.
    • Use filters to limit the number of items in the initial import and phase your deployment by adjusting filters in subsequent imports.
    • Qualys scanners are deactivated by default in the Vulnerability Response application; the Rescan button will not be available for certain tasks.

    Actions to Take

    • Determine an initial start date for Host Detection List Import integrations, ideally the date of the last Qualys scan.
    • Add users to the necessary roles: admin, snvuln.admin, and snvulqualys.admin.
    • Keep the default configured run-as user for integration records as VR.System.
    • If not using vulnerability calculators, disable the default and any other defined calculators to enhance initial import performance.
    • Disable notification-related business rules prior to the initial import to minimize performance impact.
    • Prepare your Qualys server URL and authentication credentials, ensuring they have sufficient permissions for your Qualys subscription.
    • If using host tags in Vulnerability Response Assignment or Vulnerability Group Rules, ensure the Qualys Host List integration has been run beforehand.

    A successful integration requires planning and careful execution of pre-integration tasks. It is essential that you prepare for the integration by performing these procedures. The Qualys Vulnerability Integration assumes that you are familiar with and run Qualys Cloud Platform scans in your environment.

    Note:
    Make any necessary configuration changes based on your requirements before running the integrations.

    Important prerequisites

    Validate your instance sizing based on the number of vulnerable items you expect to import. An undersized instance can lead to long load times. If you do not know the size of your instance, contact Customer Service and Support.

    Use filtering to limit the number of items for initial import and phase your deployment by adjusting filters in subsequent imports.

    The Qualys scanners are deactivated by default in the Vulnerability Response application. If you try to perform a rescan from the vulnerable items or remediation tasks that have these applications as a source, the Rescan button is not available.

    Actions to take

    • Determine an initial start date for Host Detection List Import integrations.

      Consider setting the Start time field to a few hours or days in the past. Ideally, choose the date of the last Qualys scan. The start date can include vulnerabilities discovered prior to using the vulnerability management solution. Set the earliest start time used to the start of your scanning cycle. So, if it takes a week before all hosts are scanned, set this value to a week prior to that time.

    • Add users to the roles for admin, sn_vuln.admin, and sn_vul_qualys.admin. For more information see, Assign a role to a user.
    • There is a configured run-as user for each integration record. The default value for this user is VR.System. Do not change this value.

    • If you do not use vulnerability calculators, Disable the default vulnerability calculator if not used, in addition to any others you have defined. Vulnerability calculators run every time a vulnerable item record is created or updated, and can impact initial import performance.
    • During the initial import of records, certain notification-related business rules can cause many notifications to be generated, impacting performance. Prior to your initial import, disable the business rules.
    • If you wish to use a different scanner than the Qualys default, see set up scanner appliances.
    • Have your Qualys server URL and authentication credentials ready. The credentials must provide adequate permissions for retrieving knowledge, scan, and detection information for a Qualys subscription.
    • If you plan to use host tags in Vulnerability Response Assignment or Vulnerability Group Rules, ensure the Qualys Host List integration was run prior to creating rules.