Policy Audit Overview

Policy Audit - a tool that automates every stage of the audit process and enables you to be continuously audit-ready. 

The features of Policy Audit are as follows:

  • Seamless onboarding process
    Step-by-step guidance on the onboarding process to deploy, configure, and align evidence to your compliance mandates.
  • Enhanced dashboard
    Explore widgets that simplify navigation and bring key insights to the forefront.
  • Audit Readiness Report 
    Always stay audit ready with continuous and automatic evidence collection with intelligent mapping to relevant regulatory frameworks.
  • TruRisk™ Score
    Detect and analyze misconfigurations using TruRisk™ Score for better risk prioritization.
  • Audit Fix (add-on service)
    Close audit gaps and remediate automated workflows using Audit Fix.
  • Compliance Framework Reports
    Track mandates that matter the most and generate stakeholder-ready audit reports.
  • ServiceNow Integration
    Smooth integration support for the GRC tool ServiceNow enablaing the right team to action at the right time.

The Home page in the enhanced PA user interface lets you have a one-glance perspective of all your assets, know their compliance score, and provides an easy way to start your compliance journey with Qualys Policy Audit. You can access this page only if you have an active subscription for PA and SCA, and the enhanced PA user interface is enabled for your PA subscription.

Policy Audit Home page.

The Home page contains the following tabs:

  • Establish Asset Scope
    Gain an overview of your asset system and the overall compliance score. This tab highlights the total number of assets and their current compliance score; provides a view of the number of assets with Qualys Cloud Agent installed, as well as the number of database assets and middleware assets in your asset system.
  • Start Assessment
    Quick access to the PA Content Library for out-of-the-box compliance policies, run a check on the compliance posture of your assets, and initiate mandate-based reports from the given links.
  • Prioritize and Report
    Access the compliance reports from the Report tab of Qualys PA.
  • Remediate and Prevent
    Access Audit Fix and identify and fix misconfigurations on assets at a larger scale.

PA Benefits Page for SCA-Only Accounts

SCA Only customers can view the following page listing the many benefits of Policy Audit. Easily upgrade to Policy Audit through this page to start taking advantage of the features listed. Use the Send Email option to request a free Policy Audit trial or to upgrade your subscription today.

PA SCA homepage.

Enhanced Dashboard Capabilities

Currently, no additional configuration is required from your side to access the new dashboard. Your PA assets/data will be migrated to the enhanced Policy Audit UI automatically. If your subscription has both PA and SCA, your PA assets/data will be migrated but your SCA assets/data will not be migrated. SCA customers should continue to use their existing dashboard.

With customizable dashboards and widgets, you can visualize the security compliance posture of your IT infrastructure. Such graphical presentation of compliance data helps you understand of your compliance requirements better and take informed decisions quicker. It is also a smarter and a more convenient way of sharing information with the intended target audience.

Policy Audit Dashboard

Policy Audit Posture

Once your data is synced, all the compliance posture records of your assets that you evaluate against the controls in Policy Audit are displayed in the new Posture tab. This data is synced in the back end and no additional configurations are required.

View controls and assets details

Customizable Dynamic Dashboards

Qualys Unified Dashboard (UD) is integrated with Policy Audit. UD brings information from all Qualys applications into a single place for visualization. UD provides a powerful new dashboarding framework along with platform service that will be consumed and used by all other products to enhance the existing dashboard capabilities.

The Unified Dashboard framework enables you to use dashboard widgets from other Qualys modules, such as VMDR, FIM, and CSAM, among others, in a single dashboard.

You can use the default Policy Audit dashboard provided by Qualys or easily configure widgets to pull information from other modules/applications and add them to your dashboard. You can also add as many dashboards as you like to customize your Policy Audit view.

Quickly get custom views