What is our primary use case?
Qualys Policy Compliance is used to define hardening policies for different technology platforms, such as Windows member servers, Windows domain controllers, Linux flavors, and networking appliances. This is what it is used for.
How has it helped my organization?
In one platform, we can see the compliance level.
It takes time to realize its benefits, but that is not because of the platform. It is related to the enterprise. It depends on how long it takes for the infrastructure team to deploy and maintain the policy for existing assets and new assets and to maintain the Qualys agents and get them up and running. It is also based on the enterprise-wise agreement on how often compliance should be validated. After all these parameters are clear and defined by the enterprise, the platform is straightforward. It allows validation and follow-up for the status.
What is most valuable?
The platform allows multiple features that are very useful. The first one is being able to define the enterprise policy. The second one is to be able to automatically check the compliance level based on that policy, and the third one is that it allows us to generate reports and dashboards to see the compliance level easily.
What needs improvement?
Policy implementation is sometimes a little bit different than, for example, the CIS standards. If you are using a CIS type of standard, controls will be differently implemented, and that implementation is not straightforward. There is no clear mapping for the CIS controls in terms of how they should be implemented into Qualys, so the implementation stage might be a little bit challenging for the customer. That means that the customer will end up opening support cases, which will overload their support team to explain those. If they are somehow published somewhere, it would save time and effort for both sides.
For how long have I used the solution?
I have been using Qualys Policy Compliance for five years.
What do I think about the stability of the solution?
This is a very stable module. I have not encountered any crashing of this module.
What do I think about the scalability of the solution?
It is just out of the box because it is either based on cloud agents that need to be deployed or it is based on scanning, so it is very scalable. There is no problem with that.
The only thing that needs to be adjusted is the license. If the infrastructure is suddenly growing to twice the host number, the license should be adjusted. Apart from that, it is very scalable.
How are customer service and support?
I have contacted their support many times. Most of the time, their support team is very responsive and helpful. From a customer perspective, it can be sometimes challenging when support asks for different types of evidence. That is completely understandable because to review and fix, they need the information. That is completely understandable, but it is a mini project because we need to respond in time and provide the needed evidence. Sometimes it needs a meeting that usually saves time for both sides to see what exactly is not going well and get help, but they are responsive. They adjust themselves to the customer's needs.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
In the beginning, some of the assets were manually hardened, but that was not good enough at the enterprise level. We needed a way to automatically have visibility over the posture. This is the first tool that we are using, and we are very happy with it.
How was the initial setup?
Its implementation is somewhere in the middle. That is because some of the controls are pretty straightforward and can be easily defined, but other controls cannot be found in Qualys. They need some kind of research and maybe opening a support case or multiple support cases. Depending on the technology, the primary deployment or the primary configuration might be challenging. However, our effort is paying off because the same platform allows us to have multiple features. It saves a lot of time, and time is money.
What about the implementation team?
The number of people required depends on the enterprise. For a small to medium enterprise, it would be enough to have one member who is responsible for vulnerability management and policy compliance. For bigger enterprises, it depends on the number of hosts.
Maintenance is required but not from a Qualys perspective. The maintenance is from a hardening perspective. For example, if an upgrade changes some of the hardening configuration, it needs to be maintained on the box in order to keep compliance. However, once the policy is deployed and defined in Qualys, unless the enterprise policy changes, there is no need for maintenance.
What's my experience with pricing, setup cost, and licensing?
The prices might be a little bit high. I cannot compare it with another product because we did not try any other product, but this is my impression when comparing different modules.
Which other solutions did I evaluate?
I inherited Qualys when I started to work with the bank. We just had that module. We were happy to see a platform that allows us multiple features, such as vulnerability management, asset inventory, and policy compliance. All those are based on the same configuration and the same platform. It saves a lot of time, a lot of money, and a lot of effort. Having the Qualys agent deployed allows us to do all of those together and also scan the assets that cannot have a Qualys agent. We use the very same scanners to perform all those requirements. It is very important for us to have one platform that allows all those together.
What other advice do I have?
Doing the homework before going to Policy Compliance in Qualys would be a very good idea. Decide what type of hardening standards to use and approve the standards. Decide how often the policy compliance should be validated and reported, what types of reports are needed, and which individuals need different types of access or different types of reports. Knowing all those will make the implementation pretty straightforward.
We had a module from Qualys, but we did not fully implement it, so we had to define enterprise policies, update those in Qualys, enforce them, and check the compliance level. It was a work process that took more than a year. It is still ongoing because Policy Compliance allows checking compliance against a policy, but the policy itself needs to be defined by the enterprise. It then needs to be approved and tested. Only after that, it is updated in Qualys and followed up on the compliance level.
I would rate Qualys Policy Compliance an eight out of ten.