Qualys QualysGuard version 2.0
| Scorecard | Audience | Description |
|---|---|---|
|
|
Operations |
Distribution by Vulnerability ID illustrates the relative concentration of vulnerabilities in the environment. This scorecard displays the total number of occurrences for each unique vulnerability ID. |
|
|
Operations |
Hosts Exempt from Vulnerability Scanning presents trended metrics results for the percentage of hosts exempt from vulnerability scanning. |
|
|
Operations |
Hosts Exempt from Vulnerability Scanning presents trended metrics results for the percentage of hosts exempt from vulnerability scanning. Grouped by Asset Scope |
|
|
Operations |
Hosts Scanned within Policy illustrates the organization's adherence to vulnerability scanning policies. This scorecard presents trended metrics results for the percentage of hosts scanned within the time frame specified by user-defined policy. |
|
|
Operations |
Hosts Scanned within Policy illustrates the organization's adherence to vulnerability scanning policies. This scorecard presents trended metrics results for the percentage of hosts scanned within the time frame specified by user-defined policy. Grouped by Asset Scope |
|
|
Operations |
Hosts With No Vulnerabilities presents trended metrics results for the percentage of hosts with no vulnerabilities detected. |
|
|
Operations |
Hosts With No Vulnerabilities presents trended metrics results for the percentage of hosts with no vulnerabilities detected. Grouped by Asset Scope |
|
|
Operations |
Hosts With Severe Vulnerabilities presents trended metrics results for the percentage of hosts with severe vulnerabilities detected. |
|
|
Operations |
Hosts With Severe Vulnerabilities presents trended metrics results for the percentage of hosts with severe vulnerabilities detected. Grouped by Asset Scope |
|
|
Operations |
Host Vulnerability presents the distribution and severity of vulnerabilities detected across hosts. This scorecard displays metrics results identifying the most vulnerable hosts and vulnerability impact. |
|
|
Operations |
Host Vulnerability Distribution shows the distribution of vulnerabilities across hosts. |
|
|
Operations |
Mean Age of Open Tickets presents trended metrics results for support ticket aging. |
|
|
Operations |
Mean Age of Open Tickets presents trended metrics results for support ticket aging. Grouped by Asset Scope |
|
|
Operations |
Mean Time Since Last Scan presents trended metrics results for the average number of days since the last vulnerability scan. |
|
|
Operations |
Mean Time Since Last Scan presents trended metrics results for the average number of days since the last vulnerability scan. Grouped by Asset Scope |
|
|
Operations |
Mean Time to Close a Ticket illustrates the activity time for remediation support tickets. This scorecard presents trended metrics results for the mean number of days between support ticket initiation and ticket closure. |
|
|
Operations |
Mean Time to Close a Ticket illustrates the activity time for remediation support tickets. This scorecard presents trended metrics results for the mean number of days between support ticket initiation and ticket closure. Grouped by Asset Scope |
|
|
Operations |
Most Common Severe Vulnerabilities lists the ten severe vulnerabilities with the most number of instances detected across all hosts. |
|
|
Operations |
Most Common Vulnerabilities lists the ten vulnerabilities with the most number of instances detected across all hosts. |
|
|
Operations |
Open Tickets by Month Created illustrates seasonal changes and spikes in the vulnerability scanning process. This scorecard shows support ticket aging grouped by ticket creation month. |
|
|
Operations |
Open Tickets by Month Created illustrates seasonal changes and spikes in the vulnerability scanning process. This scorecard shows support ticket aging grouped by ticket creation month. Grouped by Asset Scope |
|
|
RiskManagement |
This scorecard demonstrates compliance with PCI Data Security Standard Requirement 11. The scorecard presents trended metrics results for vulnerability scanning, tracking average time since last scan and adherence to scanning policy. |
|
|
RiskManagement |
This scorecard demonstrates compliance with PCI Data Security Standard Requirement 11. The scorecard presents trended metrics results for vulnerability scanning, tracking average time since last scan and adherence to scanning policy. Grouped by Asset Scope |
|
|
RiskManagement |
This scorecard demonstrates compliance with PCI Data Security Standard Requirement 6. The scorecard presents trended metrics results for the percentage of hosts covered by vulnerability scans. |
|
|
RiskManagement |
This scorecard demonstrates compliance with PCI Data Security Standard Requirement 6. The scorecard presents trended metrics results for the percentage of hosts covered by vulnerability scans. Grouped by Asset Scope |
|
|
Operations |
Percentage of Hosts Scanned presents trended metrics results for percentage of hosts covered by a vulnerability scanning system. |
|
|
Operations |
Percentage of Hosts Scanned presents trended metrics results for percentage of hosts covered by a vulnerability scanning system. Grouped by Asset Scope |
|
|
Operations |
Percentage of Vulnerable Hosts presents trended metrics results for percentage of hosts with at least one detected vulnerability. |
|
|
Operations |
Percentage of Vulnerable Hosts presents trended metrics results for percentage of hosts with at least one detected vulnerability. Grouped by Asset Scope |
|
|
Operations |
Remediation Activity displays statistics for vulnerability remediation process time and remediation ticket duration. This scorecard presents trended metrics results for average process time, process time within policy, average ticket close time, and ticket close time within policy. |
|
|
Operations |
Remediation Activity displays statistics for vulnerability remediation process time and remediation ticket duration. This scorecard presents trended metrics results for average process time, process time within policy, average ticket close time, and ticket close time within policy. Grouped by Asset Scope |
|
|
Operations |
Residual Risk Level displays statistics for ticket processing. This scorecard presents trended metrics results for open patching tickets and for ticket aging. |
|
|
Operations |
Residual Risk Level displays statistics for ticket processing. This scorecard presents trended metrics results for open patching tickets and for ticket aging. Grouped by Asset Scope |
|
|
Operations |
Scan Configuration illustrates the organization's adherence to vulnerability scanning policies. This scorecard presents trended metrics results for mean days since last scan, and for percentage of hosts scanned within the time frame specified by user-defined policy. |
|
|
Operations |
Scan Configuration illustrates the organization's adherence to vulnerability scanning policies. This scorecard presents trended metrics results for mean days since last scan, and for percentage of hosts scanned within the time frame specified by user-defined policy. Grouped by Asset Scope |
|
|
Operations |
Scan Coverage illustrates host coverage by an automated vulnerability scanning system. This scorecard displays trended metrics results for hosts covered by vulnerability scanning, hosts exempt from scanning, hosts with severe vulnerabilities, and hosts with no known vulnerabilities. |
|
|
Operations |
Scan Coverage illustrates host coverage by an automated vulnerability scanning system. This scorecard displays trended metrics results for hosts covered by vulnerability scanning, hosts exempt from scanning, hosts with severe vulnerabilities, and hosts with no known vulnerabilities. Grouped by Asset Scope |
|
|
Operations |
Time to Process in Policy illustrates the organization's adherence to policy for overall remediation process time, from identification of the issue to closure. This scorecard presents trended metrics results for the percentage of vulnerabilities remediated within user-defined policy. Default policy is 45 days. |
|
|
Operations |
Time to Process in Policy illustrates the organization's adherence to policy for overall remediation process time, from identification of the issue to closure. This scorecard presents trended metrics results for the percentage of vulnerabilities remediated within user-defined policy. Default policy is 45 days. Grouped by Asset Scope |
|
|
Operations |
Top Ten Vulnerable Hosts lists the ten hosts with the highest vulnerability scores. |
|
|
Operations |
Vulnerabilities by Impact shows the distribution of vulnerabilities classified by impact rating. |
|
|
Operations |
Vulnerabilities by Impact shows the distribution of vulnerabilities classified by impact rating. Grouped by Asset Scope |
|
|
Operations |
Vulnerabilities by Type shows the distribution of detected vulnerabilities classified by vulnerability type. |
|
|
Operations |
Vulnerabilities by Type shows the distribution of detected vulnerabilities classified by vulnerability type. Grouped by Asset Scope |
|
|
Operations |
Vulnerability Count by Impact displays the total number of detected vulnerabilities grouped by impact rating. |
|
|
Executive |
This rollup template scorecard illustrates the organizations overall vulnerability scanner host coverage. This scorecard displays aggregate information collected in other metrics and scorecards, as defined in the Rollup configuration. |
|
|
Executive |
Vulnerability Coverage Rollup by Asset Scope evaluates the exposure of hosts not being monitored by a vulnerability scanning system. |
|
|
Operations |
Vulnerability Management presents the distribution of detected vulnerabilities. This scorecard displays metrics results for vulnerabilities classified by impact and type, and lists the most common vulnerabilities detected. |
|
|
Operations |
Vulnerability Management presents the distribution of detected vulnerabilities. This scorecard displays metrics results for vulnerabilities classified by impact and type, and lists the most common vulnerabilities detected. Grouped by Asset Scope |
|
|
Executive |
This template rollup scorecard illustrates the organizations overall vulnerability management performance. This scorecard displays aggregate information collected in other metrics and scorecards, as defined in the Rollup configuration. |
|
|
Executive |
The Vulnerability Statistics Rollup by Asset Scope scorecard illustrates the organizations overall vulnerability management performance. This scorecard displays aggregate information collected in other metrics and scorecards, as defined in the Rollup configuration.illustrates the organizations overall vulnerability management performance. This scorecard displays aggregate information collected in other metrics and scorecards, as defined in the Rollup configuration. |
|
|
Operations |
Fully Patched Hosts scorecard examines the percentage of hosts under patch management that are fully patched. |
|
|
Operations |
Fully Patched Hosts scorecard examines the percentage of hosts under patch management that are fully patched. |
|
|
Operations |
This scorecard lists all hosts that are not covered nor exempt from patch management. |
|
|
Operations |
The chart displays the percentage of hosts exempt from patch management. |
|
|
Operations |
The chart displays the percentage of hosts exempt from patch management. |
|
|
Operations |
The chart displays a list of hosts missing critical patches. Missing critical patches are patches with a not installed status and a severity value over 4. |
|
|
Operations |
The Patch Application scorecard examines the number and mean time to install patches. |
|
|
Operations |
The Patch Application scorecard examines the number and mean time to install patches. |
|
|
Operations |
Patch Application Policy examines how well the organization applies patches within the organization. The scorecard focuses on two policies: the percentag e of patches applied within policy and the time to apply patches. |
|
|
Operations |
Patch Application Policy examines how well the organization applies patches within the organization. The scorecard focuses on two policies: the percentag e of patches applied within policy and the time to apply patches. |
|
|
Operations |
Patched Hosts examines how well the organization's host are up-to-date on their patches. The scorecard examines the following policies: percentage of hosts fully patched and the list of hosts missing critical patches. |
|
|
Operations |
Patched Hosts examines how well the organization's host are up-to-date on their patches. The scorecard examines the following policies: percentage of hosts fully patched and the list of hosts missing critical patches. |
|
|
Operations |
Patches Applied Within Policy displays the percentage patches applied within policy. |
|
|
Operations |
Patches Applied Within Policy displays the percentage patches applied within policy. |
|
|
Operations |
Patch Management Coverage presents statistics for host coverage by an automated patch management system. This scorecard displays trended metrics results for patched systems and exemptions. |
|
|
Operations |
Patch Management Coverage presents statistics for host coverage by an automated patch management system. This scorecard displays trended metrics results for patched systems and exemptions. |
|
|
Executive |
This scorecard communicates the coverage of hosts by an automated patch management system by presenting the performance score for a key performance indicator: assets covered by a patching system. Scores are based on user-defined goals. Performance scores are trended and displayed as RYG rating visuals. |
|
|
Executive |
This scorecard communicates the coverage of hosts by an automated patch management system by presenting the performance score for a key performance indicator: assets covered by a patching system. Scores are based on user-defined goals. Performance scores are trended and displayed as RYG rating visuals. |
|
|
Operations |
The Patch Management Host Coverage metric calculates the percentage of hosts covered by the patch management system. The metric does not include hosts excluded from coverage. |
|
|
Operations |
The Patch Management Host Coverage metric calculates the percentage of hosts covered by the patch management system. The metric does not include hosts excluded from coverage. |
|
|
Executive |
This scorecard communicates the coverage of hosts by an automated patch management system by presenting the performance scores for two key performance indicators: percentage of hosts fully patched and percentage of patches applied within policy. Scores are based on user-defined goals. Performance scores are trended and displayed as RYG rating visuals. |
|
|
Executive |
This scorecard communicates the coverage of hosts by an automated patch management system by presenting the performance scores for two key performance indicators: percentage of hosts fully patched and percentage of patches applied within policy. Scores are based on user-defined goals. Performance scores are trended and displayed as RYG rating visuals. |
|
|
RiskManagement |
Vulnerability and Patch demonstrates compliance with PCI Data Security Standard Requirement 6. This scorecard presents trended metrics results for patch management coverage, patching activity, and residual risks due to unpatched hosts. |
|
|
Operations |
Time to Apply Patches displays statistics on the amount of time to patch. Patch time is measured as the number of days from when the patch was released to last status update with a patch status of installed. |
|
|
Operations |
Time to Apply Patches displays statistics on the amount of time to patch. Patch time is measured as the number of days from when the patch was released to last status update with a patch status of installed. |
|
|
RiskManagement |
This scorecard demonstrates compliance with PCI Data Security Standard Requirement 6. The scorecard presents trended metrics results for the percentage of hosts covered by vulnerability scans. |