Advanced Qualys configurations and modifications
Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
For more tips for Qualys imports, see the Performance tuning tips for Qualys import jobs knowledge article in the HI Knowledge Base.
Modify the Qualys to ServiceNow priority and state mapping values
Modify mapping values for priority and state for your requirements.
始める前に
このタスクについて
手順
Restrict the ability to write to a record based on an assignment group
You can restrict write/read rights on records based on membership to an assigned group. Modify conditions and script based on specific requirements.
始める前に
手順
Set up scanner appliances
If you are initiating scans from your ServiceNow AI Platform® instead of directly from Qualys, you can set up scans for IP address ranges.
始める前に
The data comes from the Qualys integration based on Qualys asset groups and their related default appliances (scanners).
If no appliances are configured for the targeted IP address ranges, the appliance that is set as the default for the integration instance is used for the scan.
Role required: sn_vul_qualys.admin手順
Configure and manage Qualys vulnerability scanners and scans
Qualys vulnerability scans can be performed to find software vulnerabilities that affect your CIs. You can initiate scans from a vulnerable item record or by creating a scan record directly for configuration items (CIs) and IP addresses.
If you scan Qualys vulnerable items directly from the Vulnerable Items screen, you also have the option of scanning multiple vulnerable items at the same time.
If Security Incident Response is activated, you can also initiate a scan from the security incident catalog, a security incident record, or a security scan request.
Scans submitted from Qualys vulnerable items, the Security Incident Catalog, security incidents, or security scan requests are performed by the default Qualys scanner.
You can select the option profile you want to use for scans for matching configuration items.
- Option profiles contain Qualys scan settings.
- An option profile is required when you initiate a Qualys scan from your ServiceNow AI Platform®.
Configure the ServiceNow-initiated Qualys IP scan
The Qualys scanner included with the base system provides a baseline integration to initiate scans based on IP addresses.
始める前に
You can select the option profile you want to use for scans for matching configuration items.
- Option profiles contain Qualys scan settings.
- An option profile is required when you initiate a Qualys scan from your ServiceNow AI Platform®.
Role required: sn_vul_qualys.admin
Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see Assign the Vulnerability Response persona roles using Setup Assistant. For more information about managing granular roles, see Manage persona and granular roles for Vulnerability Response.
手順
Scan multiple Qualys vulnerabilities or vulnerable items
You can simultaneously scan multiple Qualys vulnerabilities or vulnerable items that contain at least one affected configuration item (CI) or an IP address populated on the form.
始める前に
Role required: sn_vul.vulnerability_write
Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see Assign the Vulnerability Response persona roles using Setup Assistant. For more information about managing granular roles, see Manage persona and granular roles for Vulnerability Response.
手順
Configure the Qualys auto scan for resolved remediation tasks
You can schedule the scan that runs automatically to update your Qualys vulnerable items.
始める前に
After a remediation task is transitioned to Resolved, a scan is initiated automatically to update the state of the associated vulnerable items.
- The scan is disabled by default.
- Enable the scan with the scan_on_resolved integration instance parameter in the Qualys record located at . See the following steps for more information.
- This scan is instance-specific. If you have multiple instances and you want to enable or disable this scan, you must disable the scan_on_resolved parameter in the integration instance parameters in each instance you want changed.
- When the scan is enabled, you can initiate the scan on-demand, or you can schedule the scan to run only within a specified time window. See Configure Qualys rescans to run only within scheduled intervals for how to set the start and end times for the time window.
Role required: sn_vul_qualys.admin
手順
Configure Qualys rescans to run only within scheduled intervals
For the Qualys Vulnerability Integration, set the scan start and end time parameters so that rescans run, or are available, only during the hours that you want.
始める前に
This configuration applies to both scheduled rescans and the rescans you initiate manually in the Qualys product from your ServiceNow AI Platform® instance.
Setting the scan start and end time parameters for integration instances permits you to specify time windows when rescans in the Qualys product are available. For example, you might prefer to specify that rescans are only available during off-hours, for example, midnight to 10 AM.
This setting is instance-specific. If you have multiple instances, you must configure the scan_start_time and scan_end_time values in the integration instance parameters in each instance you want to change.
Role required: sn_vul_qualys.admin
手順
Qualys vulnerability scan rate limits
You can define the rate that different types of scans are performed to limit the number of requests that are sent to an external scanner. After you have defined rate limits, you can apply them to the Qualys scanners.
Define Qualys scan rate limits
You can define the rate that different types of scans are performed to balance the load in your scan queue. Conditions defined in the rate limit determine whether the rate limits are applied to queued entries.
始める前に
Role required: sn_vul.admin
Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see Assign the Vulnerability Response persona roles using Setup Assistant. For more information about managing granular roles, see Manage persona and granular roles for Vulnerability Response.
手順
Apply scan rate limits to Qualys scanners
After you have defined scan rate limits using Rate Limit Definitions, you can apply rate limits to specific Qualys scanners.
始める前に
Role required: sn.vul_admin
Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see Assign the Vulnerability Response persona roles using Setup Assistant. For more information about managing granular roles, see Manage persona and granular roles for Vulnerability Response.
手順
View the Qualys vulnerability scan queue
Vulnerability scan requests submitted to Qualys vulnerability scanning integration are queued so as not to overload system resources. You can view the status of queued requests, as needed.
始める前に
Role required: sn_vul.vulnerability_admin or sn_vul.admin (deprecated)
Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see Assign the Vulnerability Response persona roles using Setup Assistant. For more information about managing granular roles, see Manage persona and granular roles for Vulnerability Response.
このタスクについて
手順
Enable base system filter for confirmed detection imports
Enable a default filter using integration parameters to import only confirmed detections from Qualys Cloud Platform.
始める前に
Role required: sn_vul_qualys.admin, sn_vul.vr_import_admin
このタスクについて
A base system integration instance parameter “include_only_confirmed” is available to import a filtered list of detections from Qualys Cloud Platform. By default, this parameter is set to FALSE, and all detections whether potential, confirmed, or informational are imported.
手順
タスクの結果
By default, only confirmed detections from the Qualys Cloud Platform integration are imported when the next Qualys Vulnerability Import runs. All other detections such as informational and potential are ignored and not imported. For more information, see View Vulnerability Response vulnerable item detection data.
Initiate rescan for the Qualys Vulnerability Integration
Verify your vulnerable items have been remediated between scheduled scanning cycles by initiating rescans in the Qualys product from your ServiceNow AI Platform on-demand.
始める前に
You can initiate rescans from the Vulnerability Response workspaces. For more information, see Rescan records and remediation tasks in the Vulnerability Manager Workspace and Rescan vulnerable items and remediation tasks in the IT Remediation Workspace.
For rescans in the classic environment, see the following sections for how to initiate rescans.
Required setup for rescans in the Qualys product initiated from your ServiceNow AI Platform:
You can initiate a rescan on-demand for vulnerable items for the Qualys product from your ServiceNow AI Platform® instance.
To help reduce the overhead and volume involved with scheduled, full scans, remediation owners, IT specialists, vulnerability analysts, or vulnerability managers can initiate targeted rescans on-demand for specific vulnerabilities on assets (configuration items) in their environments. You can initiate rescans in the Qualys product from vulnerable item (VI), remediation tasks (RT), third-party entry (TPE), or discovered item records from your ServiceNow AI Platform instance.
Rescans permit you to verify that your remediation activities, patches, and other actions have successfully fixed specific vulnerabilities on your configuration items (CIs).
Use case:
As an example, say your entire environment is scanned once every three weeks. The most recent full scan was completed a week ago, but you applied a patch yesterday to fix a critical vulnerability. Due to the nature of this vulnerability, you cannot wait two weeks for the next scheduled scan to verify that it has been remediated. To verify that your patch successfully fixed a critical vulnerability discovered during an earlier scan, you can initiate a targeted rescan from your ServiceNow AI Platform for Qualys vulnerable items.
You can initiate rescans for VIs that have Qualys as the source in states other than closed. See Rescan records and remediation tasks in the Vulnerability Manager Workspace and Rescan vulnerable items and remediation tasks in the IT Remediation Workspace.
Verify you have completed the following setup required for rescans. See the steps starting with Configure and manage Qualys vulnerability scanners and scans listed in the previous sections for more information.
Role required: sn_vul_manually_initiate_rescan
手順
次のタスク
As shown in the previous image, during the rescan, if hosts (configuration items) in your environment are not accessible, any detections and VIs associated with these assets are not updated when the rescan is completed. To help you understand why they are not included, after the rescan is completed, the asset IP addresses for these CIs are listed on Vulnerability records in the Hosts not scanned field.