Qualys’ library of built-in policies makes it easy to comply with commonly adhered to security standards and regulations. Qualys provides a wide range of policies, including many that have been certified by CIS as well as ones based on security guidelines from vendors such as Microsoft and VMware. We are also expanding our coverage of mandate-based policies with out of the box coverage of industry and government regulations such as PCI and HIPAA.
In order to keep up with the latest changes in security control requirements and new technologies, Qualys publishes new content to the Policy Library monthly.
New and Updated CIS Benchmarks
CIS Benchmarks are developed through consensus, providing an industry recognized collection of best practice controls. Qualys is committed to broad coverage of the CIS Benchmarks and regularly releases certified policies as well as contributing to the development of new benchmarks through the CIS Community.
Qualys' Certification Page at CIS has been updated: https://benchmarks.cisecurity.org/membership/certified/qualys
Recent additions to the policy library include the following certified CIS Benchmarks:
- CIS Benchmark for Oracle Enterprise Linux 7 v1.1.0
- CIS Benchmark for Microsoft SQL Server 2014 Database Engine
- CIS Benchmark for CentOS Linux 7, v1.1.0
- CIS Benchmark for Microsoft IIS 8.x, v1.1.0 (Updated)
- CIS Benchmark for Microsoft IIS 7.x v1.3.0 (Updated)
New and Updated Vendor Recommended Best Practice Policies
- MS SCM – Compliance and Security Policy for Microsoft Windows Server 2012 R2 [Domain Controller]
- MS SCM – Compliance and Security Policy for Microsoft Windows Server 2012 R2 [Member Server]
- MS SCM – Compliance and Security Policy for Microsoft Windows 8.1 (Updated)
If you have any questions please contact your TAM or Technical Support.