As audit and assessment complexity increases, traditional email, document and spreadsheet-based audit methods have become more laborious, costly and often inaccurate. Qualys SAQ 2.0 enables organizations to better consolidate and orchestrate their assessment of third-party business processes and vendor risk by centrally capturing all relevant information from technical and human sources, drastically reducing time and cost. The service also allows companies to demonstrate compliance against internal policies, standards and mandates such as PCI-DSS, HIPAA, COBIT and ISO 27001/2.
SAQ 2.0 enables organizations to assess business process requirements, including:
- Vendor risk assessment
- End-to-end security and compliance
- Internal audit management
- Assessment of employee training and awareness program
SAQ 2.0 offers:
- Campaign Management: Campaigns are new ways of easily distributing and tracking questionnaires required for compliance. SAQ's campaign wizard walks users through creation of a campaign step by step.
- Template Creation: Users can start with one of the standard templates, like HIPAA or SOX, or create their own with
Qualys' easy drag and drop Template Builder. The predefined templates are prepared by security and risk experts and are always up-to-date on compliances. - Questionnaire Distribution: A questionnaire template can be assigned to all relevant parties -- colleagues, partners, vendors or groups. Questionnaire results can be grouped together to simplify the management of multiple ongoing campaigns. Users have the option to extend the campaigns to include reviewers and/or approvers as needed.
- Result Analysis: Features include campaign progress tracking and customizable dashboards, reflecting vendor risk and compliance posture. Response gathering happens automatically without the need for spreadsheets or other reporting tools. Campaigns track compliance in one centralized place for all stakeholders. Real time analytics help users monitor the campaigns at the executive level with live charts or drill down to details needed by security and risk professionals.
"Qualys SAQ has allowed
Recent mega-breaches have demonstrated the potential high cost of hidden vendor vulnerabilities, as evidenced by the 2014 attack on third-party climate control systems used by
"Third party risk management and vendor compliance is rapidly growing in importance as organizations increasingly turn to third-party providers to reduce operating costs and increase their focus on core competencies," said
"Our SAQ service extends the Qualys Cloud Platform capabilities to help organizations proactively identify potential risks, verifying that third-party providers and their employees are compliant and monitoring for changes that might create new risks or compliance gaps."
Pricing and Availability
Qualys SAQ is sold as an annual subscription that includes 24x7 support and product updates. It starts at
Additional Resources:
- Visit the
Qualys expo booth (#311) at Gartner Security & Risk Management Summit 2016 - Follow
Qualys on LinkedIn and Twitter
About
1 http://www.cio.com/article/2600345/security0/11-steps-attackers-took-to-crack-target.html
MEDIA CONTACT
LEWIS for
qualys@teamlewis.com
(781) 418-2406
Source:
News Provided by Acquire Media