Qualys Blog

www.qualys.com
Tim White

Qualys Policy Compliance Notification: Policy Library Update

Qualys’ library of built-in policies makes it easy to comply with commonly adhered to security standards and regulations. Qualys provides a wide range of policies, including many that have been certified by CIS as well as ones based on security guidelines from vendors such as Microsoft and VMware.  We are also expanding our coverage of mandate-based policies with out of the box coverage of industry and government regulations such as PCI and HIPAA.

In order to keep up with the latest changes in security control requirements and new technologies, Qualys publishes new content to the Policy Library monthly.

New and Updated CIS Benchmarks

CIS Benchmarks are developed through consensus, providing an industry recognized collection of best practice controls.  Qualys is committed to broad coverage of the CIS Benchmarks and regularly releases certified policies as well as contributing to the development of new benchmarks through the CIS Community.

Qualys' Certification Page at CIS has been updated:  https://benchmarks.cisecurity.org/membership/certified/qualys

Recent additions to the policy library include the following certified CIS Benchmarks:

  • CIS Benchmark for Apache HTTP Server 2.4, v1.2.1
  • CIS – Apple OS X 10.10, v1.0.0
  • CIS Benchmark for Red Hat Enterprise Linux 7, v1.1.0
  • CIS Benchmark for SuSE Enterprise Linux Server 10.x v2.0
  • CIS Benchmark for SuSE Enterprise Linux Server 11.x, v1.1.0
  • CIS – VMware ESXi 5.5, V1.2.0

New Vendor Recommended Best Practice Policies

  • MS SCM – Compliance and Security Policy for Microsoft Windows 8.1

New Mandate-based Policies

  • NIST Cyber Security Framework (CSF) v1.0
  • Health Insurance Portability and Accountability (HIPAA) – Security Rule Standards and Implementation Specifications)

If you have any questions please contact your TAM or Technical Support.

Leave a Reply