Guides and Whitepapers

Download our complimentary guides, whitepapers, briefs, webcasts and more.

Vulnerability Management

FEATURE DOC:

Vulnerability Management for Dummies

Vulnerability Management for Dummies arms you with the facts and shows you how to implement a successful Vulnerability Management program. Whether your network consists of just a handful of computers or thousands of servers distributed around the world, this 5-part book will help:

  • Explain the critical need for Vulnerability Management (VM)
  • Detail the essential best-practice steps of a successful VM Program
  • Outline the various VM Solutions - including the pros & cons of each
  • Highlight the award-winning QualysGuard VM solution
  • Provide a 10-point checklist for removing vulnerabilities from your key resources

More Information >


Whitepaper:
The Need for Vulnerability Management
Whitepaper:
7 Essential Steps to Achieve, Measure and Prove Optimal Security Risk Reduction
Whitepaper:
Dynamic Best Practices of Vulnerability Management
Whitepaper:
Business Enablement with On Demand Vulnerability Management
Whitepaper:
Operationalizing Security & Policy Compliance
Guide:
Strengthening Network Security with On Demand Vulnerability Management & Policy Compliance
Guide:
Effective Remediation of Network Vulnerabilities & Policy Compliance
Brief:
Vulnerability and Policy Management for NERC Compliance
Webcast:
Proactive Vulnerability Management
Webcast:
On Demand Vulnerability Management
Webcast:
There's a Hole in Your Network - Vulnerability Management Is No Mystery
Webcast:
Developing a Vulnerability Management Habit the Easy Way
Webcast:
Effective Workflow for Fixing Network Vulnerabilities & Policy Compliance
Webcast:
Addressing Compliance Challenges with Automated Vulnerability Management
Webcast:
How One Company Conquered the Audit Challenge
Demo:
Vulnerability Management & Policy Compliance Overview

Policy Compliance

FEATURE DOC:

Strengthening Network Security with On Demand Vulnerability Management & Policy Compliance

Despite defensive efforts with firewalls, intrusion detection, antivirus and the like, criminals, careless employees and contractors have exposed more than 158 million digital records of consumers' personally identifiable information since 2005. This security guide describes the requirements and on demand software-as-a-service (SaaS) solution called QualysGuard for effective vulnerability management and policy compliance.

More Information >


Guide:
Effective Remediation of Network Vulnerabilities & Policy Compliance
Guide:
Operationalizing Network Security with Vulnerability Management and Policy Compliance
Guide:
HIPAA Guide
Guide:
FISMA Guide
Guide:
SB 1386 Guide
Brief:
Vulnerability and Policy Management for NERC Compliance
Webcast:
Addressing Compliance Challenges with Automated Vulnerability Management
Webcast:
Effective Workflow for Fixing Network Vulnerabilities & Policy Compliance

PCI Compliance

FEATURE DOC:

Winning the PCI Compliance Battle

A Guide for Merchants and Member Service Providers

This white paper reviews the basics of PCI, including who must comply, compliance requirements, validation requirements and penalties. It also examines key things to look for when selecting a PCI network testing service and introduces QualysGuard PCI.

Topics in this white paper include:

  • Compliance Requirements of the PCI Data Security Standard
  • Participation and Validation Requirements
  • Selecting a PCI Network Security Testing Service
  • Automating the PCI Validation Process with QualysGuard PCI

More Information >


Brief:
Meeting Vulnerability Scanning Requirements for PCI
Webcast:
Winning the PCI Compliance Battle - Best Practices to Manage the PCI Process
Webcast:
PCI Tools & Techniques
Demo:
QualysGuard PCI Demo

The Need for Vulnerability Management

Overview:
This guide describes the need for vulnerability management. It introduces the sources of vulnerabilities and their related fallout, then relates why the nature of modern threats to the network requires automated technology to counter sophisticated exploits. The guide defines elements of vulnerability management and how it controls the detection and remediation process. As an important byproduct, vulnerability management can also document compliance with security provisions mandated by legislation, industry and business policy. Vulnerability management can be implemented for networks of all sizes with cost-effective technology that automates much of what used to be a complex, manual process.

7 Essential Steps to Achieve, Measure and Prove Optimal Security Risk Reduction

Overview:

Whether protecting 5 servers or 5,000, organizations must be able to:

  1. Measure the security status of their infrastructure
  2. Continuously monitor and mitigate emerging threats

This paper details the essential aspects of putting into place a measurable and sustainable vulnerability management program.

Dynamic Best Practices of Vulnerability Management

Overview:
Yankee Group research reveals best practices in proactively identifying and correcting network weaknesses. Guidelines are based on Qualys' "Laws of Vulnerabilites" research.

Business Enablement with On Demand Vulnerability Management

Overview:
This whitepaper discusses the challenges of security in today's business world and provides insight into the value of an on demand Web based service for vulnerability assessment. It closes with summary information and feedback regarding the QualysGuard service, as compiled from Qualys customers.

Operationalizing Security & Policy Compliance

Overview:

A Unified Approach for IT, Audit and Operation Teams

This paper provides a detailed discussion of the internal and external regulatory challenges now faced by organizations, the scope of these challenges, and of the ways in which they can be addressed through better business processes and automation.

Strengthening Network Security with On Demand Vulnerability Management & Policy Compliance

Overview:
Despite defensive efforts with firewalls, intrusion detection, antivirus and the like, criminals, careless employees and contractors have exposed more than 158 million digital records of consumers' personally identifiable information since 2005. This security guide describes the requirements and on demand software-as-a-service (SaaS) solution called QualysGuard for effective vulnerability management and policy compliance.

Effective Remediation of Network Vulnerabilities & Policy Compliance

Overview:

Consistent, ongoing execution of vulnerability management and policy compliance is difficult, if not impossible to do on a manual basis. There are simply too many ""moving parts"" to juggle and act on in a timely and cost-effective manner. This guide provides a step-by-step guide for automating the vulnerability and compliance workflow process.

8 step vulnerability and compliance workflow:

  1. Create security policies and controls
  2. Track inventory and categorize assets
  3. Scan systems for vulnerabilities
  4. Compare vulnerabilities against inventory
  5. Classify and rank risks
  6. Pre-test patches, fixes and workarounds
  7. Apply patches, fixes and workarounds
  8. Re-scan to confirm fixes and verify compliance

Vulnerability and Policy Management for NERC Compliance

Overview:
NERC Standards are a U.S. regulation for managing the Critical Cyber Assets of Bulk Electric Systems. CIP-002 through CIP-009 provides a cyber security framework for the identification and protection of these assets, and supports reliable operation of the Bulk Electric System. This brief explains how on demand vulnerability and policy management can ensure NERC compliance.

Proactive Vulnerability Management

Speaker:
Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc.
Overview:

In this talk, Dr. Chenxi Wang, Principal Analyst for Security and Risk Management at Forrester Research, will cover the key aspects of proactive vulnerability management and more importantly, the steps via which you can follow to achieve proactive vulnerability management. More specifically:

  • Continuing assessment of network and devices
  • Integration with your IT risk management systems
  • Effective analysis of assessment results
  • Implementation of proactive remediation

We will also cover success metrics via which organizations can use to measure the maturity of their vulnerability management programs.

On Demand Vulnerability Management

Speaker:
Jonathan Bitle, Senior Product Manager, Qualys
Overview:

This podcast examines what to look for in a self-auditing solution, how to use vulnerability management to ease the pain and why your software solution really matters.

Government and industry regulations, along with mounting security threats, are causing corporations to consider continual self-audits. These drive down costs, help focus remediation efforts and improve your overall security posture. Learn how to start your own self-auditing process by setting goals and answering key questions about your infrastructure.

There's a Hole in Your Network - Vulnerability Management Is No Mystery

Speaker:
Paul Gillin, Principal, Paul Gillin Communications
Overview:

Learn how vulnerability management allows you to keep on top of these problems by identifying an organization's greatest security vulnerabilities and proactively recommending fixes.

Open networks and supply chain integration create great business opportunities but also substantial security risks. The bad guys are using more sophisticated tools to create viruses, worms, rootkits and other attacks, and malware is spreading faster than ever. Learn how vulnerability management allows you to keep on top of these problems by identifying an organization's greatest security vulnerabilities and proactively recommending fixes.

Developing a Vulnerability Management Habit the Easy Way

Speaker:
Simon Herring, Founder and CTO of Jacadis
Overview:

Listen to Core Security, Jacadis and Qualys discuss how you can bring potent vulnerability management into your organization. Simon Herring, founder and CTO of Jacadis, shares his insights on how you can develop and maintain a vulnerability management program that provides ongoing protection against hacking, spear phishing, and other IS threats. In this webcast, you'll also see security testing tools that allow you to:

  • Identify network weaknesses and safely prove their exploitability
  • Evaluate end-user response to social engineering attacks
  • Test and tune defensive applications such as IPS, IDS and firewalls
  • Validate patches and other vulnerability fixes
  • Establish a comprehensive, in-house VM methodology

Effective Workflow for Fixing Network Vulnerabilities & Policy Compliance

Speaker:
Sandra Gittlen, Technology Editor, NetworkWorld
Speaker:
Terry Ramos, Director of Strategic Development, Qualys
Overview:

This webcast overviews the 8 workflow processes that create an effective vulnerability management solution to ensure security and document compliance. Discover how the right software-as-a-service (SaaS) solution automates these processes for fast, cost-effective remediation and policy compliance.

View this webcast and learn about and effective remediation plan that provides continuous protection from network vulnerabilities and helps comply with regulations such as PCI, GLBA and HIPAA.

Addressing Compliance Challenges with Automated Vulnerability Management

Speaker:
Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc.
Overview:
Automated, on-demand vulnerability assessment and management is a powerful instrument for organizations to stay compliant and stay one step ahead of attackers. In this webcast, we will briefly address different compliance requirements and the industry best practices of using vulnerability management to achieve compliance.

How One Company Conquered the Audit Challenge

Speaker:
Randy Harris, Network Manager, United States Marine Corps - MCCS
Overview:

The Marine Corps Community Services (MCCS) manages a global network that serves Marines and their families. MCCS chose a managed service to conduct comprehensive vulnerability assessments and prioritize patches and fixes.

With thousands of nodes spread throughout the world, security is a real concern. MCCS chose a managed service to conduct comprehensive vulnerability assessments and prioritize patches and fixes. The service has saved time and money while contributing to peace of mind. MCCS manager of network services Randy Harris talks about the project.

Vulnerability Management & Policy Compliance Overview

Overview:
Watch a quick introduction to Qualys' vulnerability management and policy compliance solutions.

Effective Remediation of Network Vulnerabilities & Policy Compliance

Overview:

Consistent, ongoing execution of vulnerability management and policy compliance is difficult, if not impossible to do on a manual basis. There are simply too many ""moving parts"" to juggle and act on in a timely and cost-effective manner. This guide provides a step-by-step guide for automating the vulnerability and compliance workflow process.

8 step vulnerability and compliance workflow:

  1. Create security policies and controls
  2. Track inventory and categorize assets
  3. Scan systems for vulnerabilities
  4. Compare vulnerabilities against inventory
  5. Classify and rank risks
  6. Pre-test patches, fixes and workarounds
  7. Apply patches, fixes and workarounds
  8. Re-scan to confirm fixes and verify compliance

Operationalizing Network Security with Vulnerability Management and Policy Compliance

Overview:

A Unified Approach for IT, Audit and Operation Teams

This paper provides a detailed discussion of the internal and external regulatory challenges now faced by organizations, the scope of these challenges, and of the ways in which they can be addressed through better business processes and automation.

HIPAA Guide

Overview:

The Health Insurance Portability and Accountability Act has had substantial impact on the healthcare industry. Our free guide explains how on demand security audits make HIPAA compliance easier to achieve.

FISMA Guide

Overview:

Becoming FISMA compliant can be challenging. To help you overcome the pitfalls faced by all agencies, we've put together a step-by-step guide to ease compliance and help you make the grade. When you download our complimentary guide, you will learn:

How FIMSA is Defined

Receive detailed information on the major requirements of FISMA and how to implement a best practice based approach to overcome common challenges.

How QualysGuard Supports FISMA Compliance

See how QualysGuard's tailored solution meets each of the FISMA requirements and delivers the proper reports so you can achieve indisputable compliance.

How QualysGuard Automates Compliance

Learn how QualysGuard's on demand solution provides an automated solution so you're always in control of your network security - even during fast-moving worm and virus attacks.

SB 1386 Guide

Overview:
Prevention of security breaches is vital. Download our free guide to learn more about compliance with SB1386.

Vulnerability and Policy Management for NERC Compliance

Overview:
NERC Standards are a U.S. regulation for managing the Critical Cyber Assets of Bulk Electric Systems. CIP-002 through CIP-009 provides a cyber security framework for the identification and protection of these assets, and supports reliable operation of the Bulk Electric System. This brief explains how on demand vulnerability and policy management can ensure NERC compliance.

Addressing Compliance Challenges with Automated Vulnerability Management

Speaker:
Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc.
Overview:
Automated, on-demand vulnerability assessment and management is a powerful instrument for organizations to stay compliant and stay one step ahead of attackers. In this webcast, we will briefly address different compliance requirements and the industry best practices of using vulnerability management to achieve compliance.

Effective Workflow for Fixing Network Vulnerabilities & Policy Compliance

Speaker:
Sandra Gittlen, Technology Editor, NetworkWorld
Speaker:
Terry Ramos, Director of Strategic Development, Qualys
Overview:

This webcast overviews the 8 workflow processes that create an effective vulnerability management solution to ensure security and document compliance. Discover how the right software-as-a-service (SaaS) solution automates these processes for fast, cost-effective remediation and policy compliance.

View this webcast and learn about and effective remediation plan that provides continuous protection from network vulnerabilities and helps comply with regulations such as PCI, GLBA and HIPAA.

Meeting Vulnerability Scanning Requirements for PCI

Overview:
The credit card industry is stepping up efforts to strengthen cardholder data security by raising member validation requirements for compliance with the Payment Card Industry Data Security Standard (PCI-DSS). As part of these requirements, both internal and external network scanning play a critical role in achieving compliance. This security guide describes the scanning requirements for PCI-DSS and provides a quick-reference requirements matrix for both Merchants and Service Providers of all levels.

Winning the PCI Compliance Battle - Best Practices to Manage the PCI Process

Speaker:
Terry Ramos, Director Strategic Development, Qualys
Overview:

The Payment Card Industry Security Data Standard, or PCI, protects cardholders and businesses by establishing standard practices for processing, storing and transmitting credit card data but thefts still occur at an unprecedented rate.

This webcast will explore:

  • Compliance Requirements of the PCI Data Security Standard
  • Participation and Validation Requirements
  • Selecting a PCI Network Security Testing Service
  • Automating the PCI Validation Process with QualysGuard PCI

PCI Tools & Techniques

Overview:
Technologies for Meeting the PCI DSS

QualysGuard PCI Demo

Overview:
See how QualysGuard PCI makes achieving compliance with the PCI Data Security Standard easy and cost effective.