Prepare Your Environment for the ETM Journey
Enterprise TruRisk Management (ETM) combines asset inventory, vulnerability, misconfigurations, and business context to provide a unified view of your organization's cyber risk posture.
Before configuring ETM, you should be ready with the prerequisites described in this topic. Establishing these foundations helps ensure accurate risk calculations, meaningful TruRisk™ insights, and effective risk prioritization from the start.
Platform and Access Requirements
ETM is available through the Qualys Enterprise TruRisk Platform. Before you begin, ensure that ETM is provisioned for your subscription and identify the users who will perform the initial configuration.
| Prerequisite | Why It Matters |
|---|---|
| Qualys Enterprise TruRisk Platform account | ETM is available only through the Qualys platform and requires an active Qualys subscription. |
| ETM Application Activation | ETM must be provisioned and enabled for your subscription. |
| User Role Permissions | Users who configure profiles, connectors, and dashboards need the ETM Manager role or an equivalent role permissions. |
Data Source and Integration Setup
ETM derives risk insights from the data collected from connected Qualys applications and third-party sources. Prepare the following before connecting data sources.
| Prerequisite | Why It Matters |
|---|---|
| Qualys applications | Qualys applications such as VMDR, CSAM, Policy Audit, and Web Application Scanning supply the asset, vulnerability, and misconfiguration data that TruRisk scores are based on. |
| Third-Party Tool Access (Optional) | If you plan to integrate a solution/tool such as ServiceNow, Wiz, or Microsoft Defender, ensure the required API credentials for that tool are ready and available. |
| Network access | Connectors and data sources require outbound API or file upload access to exchange data with the Qualys platform. |
Business Context Preparation
Business context helps ETM prioritize risk based on organizational impact rather than technical severity alone. Decide the following before you configure business entities.
|
Prerequisite |
Why it matters |
|---|---|
|
Business entities |
Business Entities are the logical groups that ETM uses to aggregate and track TruRisk scores for entities such as Finance or Cloud Platform. Choose a structure that aligns with how your organization’s ownership is assigned and remediation responsibilities. |
| Business impact and value metrics | Financial or operational value for each entity lets ETM express cyber risk in business terms. |
| Risk appetite | The level of risk that your organization accepts, either overall or per business entity. For example, you might define a threshold of 450 out of 1,000 and refine it over time as your risk program matures. |
Asset and Inventory Readiness
ETM scores the assets that appear in your Qualys asset inventory. Assets that have not been discovered and inventoried are not included in TruRisk™ calculations, so ensure your asset inventory is complete before relying on ETM risk insights.
| Prerequisite | Why It Matters |
|---|---|
| Asset Discovery | Ensure that every asset, whether on-premises, in the cloud, or part of a hybrid setup, is thoroughly scanned and listed in the Qualys asset inventory. This visibility is crucial for maintaining a secure and well-managed environment. |
| Tagging Structure | Use consistent tagging logic (based on departments, applications, or IP ranges) to group assets into business entities. |
| Asset Criticality Criteria | Define importance levels (1–5) to prioritize risk mitigation based on asset value for TruRisk™ calculation and prioritization. |