Qualys provides best practices policies based on vendor's suggested best practices, industry practices and some research. Currently, policies in the library are used for assessment purpose as they are. As we increase the content (number of controls) for each SaaS, we also offer to combine some of the controls from CIS, or best practices polices or vendor policies.

Some policies which are provided out of the box, are filtered under 'System-defined' category. The user-defined policies (aka custom policies) are filtered under 'User-defined' category. System-defined policies are shown as locked, indicating that these policies cannot be changed.


Related Links

Enable Policy for Connectors

Manage Policies

Control Library

Custom Policies