Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Qualys Policy Compliance Connector Guide

Prev Next

Qualys Policy Compliance is a cloud service that performs automated security configuration assessments on your IT systems, whether they're on-premises, remote, or in the cloud. The Balbix integration with Qualys Policy Compliance ingests IT system security configurations discovered by Qualys Policy Compliance.

Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.

Integration Summary

This table provides a summary of the Balbix integration for the Qualys Policy Compliance connector.

Integration Type

Fetch: An inbound API integration used to fetch assets, vulnerabilities, control assessment information, policies information, and posture information.

Types of Assets Fetched

Infrastructure devices such as servers, virtual machines, desktops, laptops, networking, IoT.

Types of Data Fetched

Asset names, interface information (MAC address, IP address), controls assessment information (e.g., control_id, control_statement, control_details), policy information, posture information, relevant timestamps (e.g., control_source_created_date, control_source_updated_date, policy_source_created_date, policy_source_updated_date, posture_source_created_date, posture_source_updated_date).

Prerequisites

To configure the Balbix connector, you must have a Qualys Policy Compliance user account with the appropriate roles and permissions. These credentials are required for completing the configuration process.

Required Role Name(s)/Permissions

  • Manager role with full scope

  • Reader role with full scope

  • Non-manager role with the following permissions:

    • Access Permission: API Access

    • Asset Management Permission: Read Asset

    • Requested assets within scope

Permissions and Roles

To provide permissions and access to all objects in the subscription::

  1. From the Qualys administration utility, select Users > User Management.

  2. Click the user account, then Actions > Edit.

  3. Go to Roles and Scopes.

  4. Click the Allow user full permissions and scope option.

Enable User Access

To enable user access to the API:

  1. From the Qualys administration utility, click User > User Profile.

  2. On the Edit User page, click User Role, then select the API option.

  3. Click Save.

Create and Configure the Connector

After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Qualys Policy Compliance.

API Reference Documentation

To learn more about the Qualys Policy Compliance API, see the references listed below: