TruRisk™ Quick Start
These five steps align with the core methodology of the TruRisk™ model and help you systematically measure, prioritize, and reduce cyber risk.
Step 1: Define Risk Tolerance and Asset Value
|
Begin by understanding your organization’s risk appetite and the business value of each asset. Ask:
Classify assets based on business importance. This enables Qualys TruRisk™ to apply meaningful context to every vulnerability, instead of treating all systems equally. |
Step 2: Build an Accurate Asset Inventory
|
Get full visibility of your asset inventory. With Qualys TruRisk™, you can:
|
Step 3: Tag Assets and Assign Impact Scores
|
Business impact is a crucial part of risk prioritization. Many organizations already define asset importance in their Business Continuity or Disaster Recovery plans, but rarely translate that into effective security controls. Assign an Asset Criticality Score (ACS) to each asset based on:
Start with your “crown jewels” (e.g., production databases, payment systems) and assign them the highest criticality. Then tier the remaining assets into medium and low impact. This approach combines technical exposure (QDS) with business impact (ACS), giving you a true picture of where remediation creates the greatest risk reduction. |
Step 4: Prioritize Using Real Risk Signals
|
Prioritization must go beyond counting vulnerabilities. It requires understanding both the likelihood of exploitation and the business impact. Qualys TruRisk™ calculates risk using this formula:
This dynamic scoring model helps you remediate the risks that truly matter first and not just the highest CVSS scores. As environments and threats evolve, you can continuously validate and adjust your risk strategy. |
Step 5: Track Progress and Show Risk Reduction
|
Identifying and prioritizing vulnerabilities is only half the job proving measurable risk reduction is just as important. Qualys TruRisk™ provides multiple ways to track improvements and communicate results: If you're using Patch Management, you can launch remediation jobs directly from its UI. Watch Now.
|