Prepare Your Environment for the ETM Journey 

Enterprise TruRisk Management (ETM) combines asset inventory, vulnerability, misconfigurations, and business context to provide a unified view of your organization's cyber risk posture.

Before configuring ETM, you should be ready with the prerequisites described in this topic. Establishing these foundations helps ensure accurate risk calculations, meaningful TruRisk™ insights, and effective risk prioritization from the start.

Platform and Access Requirements

ETM is available through the Qualys Enterprise TruRisk Platform. Before you begin, ensure that ETM is provisioned for your subscription and identify the users who will perform the initial configuration.

Prerequisite Why It Matters
Qualys Enterprise TruRisk Platform account ETM is available only through the Qualys platform and requires an active Qualys subscription.
ETM Application Activation ETM must be provisioned and enabled for your subscription.
User Role Permissions Users who configure profiles, connectors, and dashboards need the ETM Manager role or an equivalent role permissions.

Data Source and Integration Setup

ETM derives risk insights from the data collected from connected Qualys applications and third-party sources. Prepare the following before connecting data sources.

Prerequisite Why It Matters
Qualys applications Qualys applications such as VMDR, CSAM, Policy Audit, and Web Application Scanning supply the asset, vulnerability, and misconfiguration data that TruRisk scores are based on.
Third-Party Tool Access (Optional) If you plan to integrate a solution/tool such as ServiceNow, Wiz, or Microsoft Defender, ensure the required API credentials for that tool are ready and available.
Network access Connectors and data sources require outbound API or file upload access to exchange data with the Qualys platform.

Business Context Preparation

Business context helps ETM prioritize risk based on organizational impact rather than technical severity alone. Decide the following before you configure business entities.

Prerequisite

Why it matters

Business entities

Business Entities are the logical groups that ETM uses to aggregate and track TruRisk scores for entities such as Finance or Cloud Platform. Choose a structure that aligns with how your organization’s ownership is assigned and remediation responsibilities.
Business impact and value metrics Financial or operational value for each entity lets ETM express cyber risk in business terms.
Risk appetite The level of risk that your organization accepts, either overall or per business entity. For example, you might define a threshold of 450 out of 1,000 and refine it over time as your risk program matures.

Asset and Inventory Readiness

ETM scores the assets that appear in your Qualys asset inventory. Assets that have not been discovered and inventoried are not included in TruRisk™ calculations, so ensure your asset inventory is complete before relying on ETM risk insights.

Prerequisite Why It Matters
Asset Discovery Ensure that every asset, whether on-premises, in the cloud, or part of a hybrid setup, is thoroughly scanned and listed in the Qualys asset inventory. This visibility is crucial for maintaining a secure and well-managed environment.
Tagging Structure Use consistent tagging logic (based on departments, applications, or IP ranges) to group assets into business entities.
Asset Criticality Criteria Define importance levels (1–5) to prioritize risk mitigation based on asset value for TruRisk™ calculation and prioritization.