Qualys integration with Configuration Compliance
Summarize
Summary of Qualys integration with Configuration Compliance
The Qualys integration with ServiceNow's Configuration Compliance automates the collection and analysis of configuration data. This integration enables you to map configuration findings to Configuration Items (CIs) and business services, helping identify misconfigurations and their potential impacts. It supports multiple deployments of the Qualys Cloud Platform, consolidating asset and vulnerability data into a single Vulnerability Response instance.
Show less
Key Features
- Host Tags Integration: All host tags from the Qualys Host List integration are imported and used for filtering in Vulnerability Response Assignment and Remediation Task Rules. Ensure to run the Host List integration before creating these rules.
- Tag Management: Host tags are case-insensitive and are used for organizing assets. The global system property snvul.importhosttags controls their functionality.
- Test Group Association: Enable the snvulc.addpolicyaskey system property to associate tests with test groups. This cannot be disabled once activated, so review the impact before enabling.
- Ignored Passed Test Results: As of version 15.2.5, a new integration parameter allows for the option to ignore passed test results upon import, enhancing flexibility in test result management.
- API Credentials Management: For different API credentials, update them through the Setup Assistant in Vulnerability Response to maintain accurate integration across Qualys services.
Key Outcomes
By leveraging the Qualys integration, ServiceNow customers can streamline vulnerability management, ensuring accurate tracking and reporting of configuration compliance. This integration enhances the ability to manage assets effectively, prioritize remediation efforts, and maintain organizational security posture through improved visibility and control over vulnerabilities and configurations.
The Qualys Policy Compliance collects the data and automatically sends it to the Qualys application, which continuously analyzes and correlates the information. It easily integrates as the Qualys Integration for Security Operations to map configuration findings to CIs and business services to determine the impact and priority of potential misconfigurations.
Host tags
- Tag storage is not case-sensitive. If a San Diego tag is created, then a SAN DIEGO tag cannot be stored in the Host tag table. “San Diego” and “SAN DIEGO” are considered to be the same host tag. Whichever tag was imported first wins.
- Using host tags as a Group Key in a Remediation Task Rule can have unexpected results. Host tags are intended for use only in the condition builder.
- Host tags are controlled by the global system property sn_vul.import_host_tags. This property is set to true by default. Turning off tags turns them off across all instances.
Host tags (also called asset tags) are used for organizing and tracking the assets in your organization. You can assign tags to your host assets. Then, when launching scans, you can select tags associated with the hosts you want to scan. The Host Tags module enables you to download host tag data from Qualys to your instance on a scheduled basis.
Associating a Test with its Test Group
- identify the Test Group to which a Test Result belongs to by dot-walking from Test to Test Group.
- differentiate Test records with same Test id that are associated with different Test Groups.
Integrating Qualys with the ServiceNow® Configuration Compliance application
Ignore passed test results
- Set the parameter to true to ignore passed test results on import.
- If activated, this parameter does not impact the closure of the test results.
For example, if you activate the parameter, and a failed test result from a previous import has since passed, it will be closed correctly.
API credentials
If the Qualys Vulnerability Integration is already installed on your system, and your API credentials are different than the ones you want to use for Configuration Compliance, go into Setup Assistant (in Vulnerability Response) and assign them to each Qualys PC integration.
Navigate to and edit the Qualys API Credentials field under the Qualys REST Details tab.