Security Services: QualysGuard Security and Compliance Suite - Information Security Magazine

Security Services: QualysGuard Security and Compliance Suite

QualysGuard Security and Compliance Suite
Qualys
Price:

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Enterprise Edition, $25,000/ year; Express Edition, $2,500


The Qualys service model has enabled global consumer credit reporting bureau TransUnion to streamline its vulnerability management program and extend it beyond corporate headquarters into its many locations.

"The product approach requires individual purchases of the license at each location, purchasing a platform to load licenses on and administration of that platform, then the care and feeding of it," says Victor Hsiang, director of TransUnion's information security architecture group. "With the service approach, from a corporate perspective, we can pick up the cost of Qualys and absorb the business units into the whole process."

He says certifications that would have taken days take minutes.

Qualys, known for its vulnerability management service, is building a more comprehensive security suite, starting with the recently announced Policy Compliance 1.0 module, which allows automated scans and reporting mapped to numerous security frameworks. Qualys will add a Customizable Audit Service, NAC Service for Unmanaged Devices and Web Application Scanning Manager in Q4.

Hsiang will beta test the Policy Compliance module at TransUnion, and expects it to integrate with his group's program of using the vulnerability management service and a central database to certify systems through a cycle of vulnerability scanning, ticketing and remediation.

"We won't have to reinvent the wheel; the compliance module fits into the architecture we've developed for tracking and fixing vulnerabilities," says Hsiang.

This was first published in June 2008