New solution enables application security teams to detect, prioritize and remediate vulnerabilities within company developed software and embedded open source components
In the digital transformation era, every organization develops its own software to run its business. This first-party, or company-developed, software often lacks the disciplined vulnerability and configuration management practices used for third-party software. Studies have shown that over 90% of first-party software includes open source components while more than 40% have high risks such as exploitable vulnerabilities. Today, application and security operations teams rely on manual checks or siloed scripts to evaluate the security of first-party software, resulting in ad-hoc security assessment that impedes the ability to prioritize and remediate risk effectively. Furthermore, traditional vulnerability assessment or software composition analysis tools do not detect the presence of embedded open source packages across the production environment. As a result, security teams face challenges in comprehending the true risk, particularly in security breaches like the Log4J incident.
The new
"In our complex enterprise environment, we've often encountered situations where our security needs surpassed the capabilities of off-the-shelf software," said
The new
Easily Build Your Own Signatures: Create Qualys Detections (QIDs) and remediations based on your own logic or scripts leveraging major scripting languages such as Python, PowerShell and others. These detections integrate directly into VMDR workflows and TruRisk scoring, helping SecOps teams unify and manage risk across first and third-party applications in their environment.
Proactively Detect, Manage and Reduce Supply Chain Risks: Get continuous, real-time visibility into deeply embedded open source software packages, such as Log4J, openSSL and commercial software components leveraging the Qualys Cloud Agent. Qualys TruRisk then prioritizes and correlates the information based on data from over 25 threat feeds and the asset's business criticality. This information allows security teams to rapidly mitigate the risk of high-profile security issues such as zero-day threats and Log4J outbreaks by crafting custom detection and responses.
Effectively Communicate Risk with Unified Reporting and Dashboarding: With native integration to VMDR workflows, effectively communicate the unified view of risk in first and third-party software to the right stakeholders via real-time dashboards and reports. Integration with ticketing systems such as ServiceNow and JIRA enables the automatic assigning of detailed remediation tickets to the right owners through a common view to quickly close tickets and reduce risk.
"First-party applications, being proprietary, often lack adequate risk detection, prioritization and remediation support from scanning tools," said
Availability – Visit us at
Enhancements to the Qualys Cloud Platform, including Custom Assessments and Remediation via VMDR integrations, will be available by the end of August. To sign up for a free trial, visit www.qualys.com/forms/vmdr. Learn more by reading the First-Party Software Risk Management blog or registering for our webinar.
To see our ground-breaking first-party solution in action and learn how to Get More Security with all our industry leading solutions, visit us at
Additional Resources
- Learn more about the Qualys First-Party Software Risk Management solution
- Read the First-Party Software Risk Management blog
- Learn more about the Qualys Cloud Platform
- Follow Qualys on LinkedIn and Twitter
About Qualys
The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies,
Media Contact:
Tami Casey
Qualys
media@qualys.com
View original content to download multimedia:https://www.prnewswire.com/news-releases/qualys-announces-ground-breaking-first-party-software-risk-management-solution-301892409.html
SOURCE