ENTERPRISE EDITION
  • Free Tools and Trials
Operationalize Vulnerability and Risk Management — On Demand

QualysGuard® Vulnerability Management (VM) automates the lifecycle of network auditing and vulnerability management across the enterprise, including network discovery and mapping, asset prioritization, vulnerability assessment reporting and remediation tracking according to business risk. QualysGuard Vulnerability Management allows security managers to audit, enforce and document network security in accordance with internal policies and external regulations. As an on demand Software-as-a-Service (SaaS) solution, there is no infrastructure to deploy or manage.

QualysGuard Vulnerability Management for Large Distributed Enterprises
   

QualysGuard VM enables enterprises to effectively manage their vulnerabilities and maintain control over their network security with centralized reports, verified remedies, and full remediation workflow capabilities with trouble tickets. QualysGuard provides comprehensive reports on vulnerabilities including severity levels, time to fix estimates and impact on business, plus trend analysis on security issues.

QualysGuard Vulnerability Management Lifecycle
   
Benefits of QualysGuard Vulnerability Management:
   
  • Mitigate risk by automating vulnerability identification and prioritizing remediation based on risk to business operations
  • Agent-less auditing, tamper resistant audit trails and the certainty that comes with third-party assessment
  • On demand SaaS technology offers significant economic advantages with no capital expenditures, extra human resources or infrastructure to deploy and manage
  • Unprecedented scalability makes it ideal for large, distributed organizations
  • Rapidly identify, visualize and organize network assets into Business Units and Asset Groups
 
Centralized Vulnerability Management
Scalability/Deployability
  • Automatic centralized reporting from distributed scans
  • Consolidated administration of both internal and external (perimeter) scanning
  • Executive Dashboard
  • Asset-based solution with an interactive asset search portal
  • Authorized user access from any location
  • Export reports to HTML, MHT, PDF, CSV and XML formats

Automation
  • Scheduled scans and network discoveries
  • Automated daily updates to vulnerability KnowledgeBase
  • Automated remediation ticket generation and verification

QualysGuard Scanner Appliances deliver an easy-to-use scanning infrastructure for distributed networks that can be deployed in minutes.

Accuracy
  • Comprehensive vulnerability KnowledgeBase incorporates thousands of unique checks
  • Trusted, third-party certification of network security with tamper resistant audit trails
  • Inference-based scanning engine with nonintrusive scanning techniques
  • Both un-trusted and authenticated scanning capabilities
  • Internal and external scanning provides a 360-degree view of network vulnerabilities
  • Configurable scans for customized audits
  • Unique fingerprints for over 2,000 operating systems, applications and protocols
  • On demand SaaS technology allows users to scan globally with no additional infrastructure
  • Fast scanning through load balancing of scanner appliances
  • User definable Business Units and Asset Groups that tie into business operations
  • End-to-end encryption of vulnerability data
  • Hierarchical role-based user access controls allow delegation of responsibilities to reflect organizational structure
  • Policy-based remediation workflow management with automatic trouble ticket creation and assignment

Interoperability
  • Extensible XML API Library
  • Out-of-the-box integration with leading SIM solutions
  • Integration with Helpdesk systems
  • Integration with Patch Management systems for auto-remediation capabilities
  • Industry standard support for vulnerability scoring with Common Vulnerability Scoring System (CVSS)
  • Industry standard support for the addition of custom detections using Open Vulnerability Assessment Language (OVAL)
Reporting
  • Customizable reports for on demand reporting by business unit for executives and managers
  • Automated trending and differential reports
  • Remediation reporting: ticket trending by asset group, user and vulnerability
  • Scorecard reports for enterprise stakeholders
  • Automated report generation and distribution
  • Multiple report distribution options including
  • encrypted PDF
Support/Maintenance
  • 24x7x365 live customer support
  • Daily signature updates and feature enhancements are completed automatically, transparent to the user
  • Ongoing Web-based customer training
  • Technical training and certification workshops
Pricing
  • Annual Subscription:
    Unlimited assessments of a predefined number of IP devices. Ideal for regular security assessments of network assets.
  • Per Scan:
    Flexible use of QualysGuard Enterprise in environments with quarterly or periodic scanning requirements. QualysGuard Vulnerability Management is also available as part of the QualysGuard Security & Compliance Suite, which includes:
  • QualysGuard Vulnerability Management
  • QualysGuard Policy Compliance
  • QualysGuard PCI Compliance
  • QualysGuard Web Application Scanning
EXPRESS EDITION
The Easiest Way to Eliminate Vulnerabilities and Manage IT Security Risk For SMBs

QualysGuard® Vulnerability Management is an on demand solution, fully automated to identify vulnerabilities, track remediation and reduce network security threats. Driven by the most comprehensive vulnerability KnowledgeBase in the industry, QualysGuard delivers continuous protection against the latest worms and security threats without the substantial cost, resource and deployment issues associated with traditional software.

   

By continuously and proactively monitoring all network access points, QualysGuard VM dramatically reduces security managers’ time researching, scanning and fixing network exposures and enables companies to eliminate network vulnerabilities before they can be exploited.

QualysGuard Vulnerability Management Lifecycle
   
Benefits of QualysGuard Vulnerability Management:
   
  • Turnkey deployability requires no software to install, update or maintain
  • Automates all steps of vulnerability assessment, management and threat reduction
  • Trusted, unbiased third-party security auditing and compliance reporting meets industry and regulatory compliance requirements
  • Discover all assets across the entire network
  • Accurate and always up-to-date vulnerability audits
  • Easy-to-use, comprehensive reporting
  • Integrated remediation and trouble-ticketing workflow
  • Cost efficient with no hidden costs
  • Secure, with complete end-to-end data encryption
 
Easily Deployed On Demand Service
Remediation Management
  • Deploys in minutes with no software installation, setup complications or maintenance upgrades
  • Immediately accessible anytime, anywhere via a Web browser

Accurate and Thorough Security Audits
  • Network mapping rapidly detects and identifies servers, desktops, routers, wireless access points and other network devices
  • Comprehensive vulnerability KnowledgeBase incorporates thousands of unique security checks
  • Automatic, daily updates to vulnerability KnowledgeBase
  • Non-intrusive detection techniques
  • Inference-based scanning engine
  • Authenticated scanning capabilities
  • Internal and external scanning provides a 360-degree view of network vulnerabilities
  • Configurable scans for customized audits
  • Unique fingerprints for over 2,000 operating systems, applications and protocols

QualysGuard Scanner Appliances deliver an easy-to-use scanning infrastructure for distributed networks that can be deployed in minutes.

Asset Prioritization
  • Manage your network by categorizing
    discovered assets into groups
  • Assign a business value to assets based on
    their criticality to your business operation
  • Automatically generate and verify trouble tickets
  • via dedicated remediation workflow
  • Create ticket policies to focus and automate remediation efforts
  • Ticket trending and reports by owner, asset group and vulnerability help track performance
  • Easy-to-follow instructions to eliminate risks

Interoperability
  • Extensible XML API
  • Out-of-the-box integration with existing and legacy security management consoles
  • Out-of-the-box integration with ticketing systems and helpdesk solutions
  • Industry standard support for the addition of custom detections using Open Vulnerability Assessment Language (OVAL)

Support / Maintenance
  • 24x7x365 live customer support
  • Daily signature updates and feature enhancements are completed automatically, transparent to the user
  • Ongoing Web-based customer training
  • Technical training and certification workshops
Pricing
Annual subscription options:
  • Perimeter Scanning: Pricing is based on the number of IP addresses.
  • Internal & Perimeter Scanning: Pricing is based on the number of IP addresses (up to 3,072).
QualysGuard Vulnerability Management is also available as part of the QualysGuard Security & Compliance Suite, which includes:
  • QualysGuard Vulnerability Management
  • QualysGuard Policy Compliance
  • QualysGuard PCI Compliance
Reporting
  • Easy access to automatically generated reports via a Web browser
  • Executive Dashboard
  • Graph and trend reports for managers
  • Detailed reports with verified remediation
  • actions for technicians
  • Network topology visualization
  • CVE and Security Focus-linked vulnerability checks with detailed remediation instructions
  • Export reports to HTML, MHT, PDF, CSV and XML formats
   




Download a .pdf printable version
ENTERPRISE EDITION
EXPRESS EDITION

Qualys has thousands of subscribers around the world including more than 35 of the Fortune Global 100 and has the world’s largest VM deployment at a Fortune 50 company with over 223 appliances, distributed in 53 countries and scanning over 700,000 systems.

“QualysGuard has made the job of auditing our network much easier. We used to have to dig through results and do a lot of manual analysis to get meaningful reports, and those were inconsistent.â€
Chris Lalonde, Senior Manager of Information Security eBay

“QualysGuard enables us to perform security audits as often as necessary, spot vulnerabilities immediately as they are added to the QualysGuard database, and work proactively to remediate them. This helps us secure all of our network entry points, enforce ICI security policies and assists us in meeting federal requirements.â€
Paul Simmonds, Director of Global Information Security ICI


QualysGuard Named Best Audit and Vulnerability Solution for Second Consecutive Year



Customizable Dashboard Per User



Business Risk Trending Report















Network Discovery Map



Vulnerability Risk Report