Qualys Policy Compliance is a cloud service that performs automated security configuration assessments on your IT systems, whether they're on-premises, remote, or in the cloud. The Balbix integration with Qualys Policy Compliance ingests IT system security configurations discovered by Qualys Policy Compliance.
Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.
Integration Summary
This table provides a summary of the Balbix integration for the Qualys Policy Compliance connector.
Integration Type | Fetch: An inbound API integration used to fetch assets, vulnerabilities, control assessment information, policies information, and posture information. |
Types of Assets Fetched | Infrastructure devices such as servers, virtual machines, desktops, laptops, networking, IoT. |
Types of Data Fetched | Asset names, interface information (MAC address, IP address), controls assessment information (e.g., control_id, control_statement, control_details), policy information, posture information, relevant timestamps (e.g., control_source_created_date, control_source_updated_date, policy_source_created_date, policy_source_updated_date, posture_source_created_date, posture_source_updated_date). |
Prerequisites
To configure the Balbix connector, you must have a Qualys Policy Compliance user account with the appropriate roles and permissions. These credentials are required for completing the configuration process.
Required Role Name(s)/Permissions
Manager role with full scope
Reader role with full scope
Non-manager role with the following permissions:
Access Permission: API Access
Asset Management Permission: Read Asset
Requested assets within scope
Permissions and Roles
To provide permissions and access to all objects in the subscription::
From the Qualys administration utility, select Users > User Management.
Click the user account, then Actions > Edit.
Go to Roles and Scopes.
Click the Allow user full permissions and scope option.
Enable User Access
To enable user access to the API:
From the Qualys administration utility, click User > User Profile.
On the Edit User page, click User Role, then select the API option.
Click Save.
Create and Configure the Connector
After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Qualys Policy Compliance.
API Reference Documentation
To learn more about the Qualys Policy Compliance API, see the references listed below: