Migration from Web Application Scanning to TotalAppSec
Qualys TotalAppSec is an advanced application security platform. It combines web application scanning, API security testing, and malware detection in a single platform. TotalAppSec replaces and enhances the Web Application Scanning (WAS) solution. It helps organizations manage application security risks more effectively from a single, integrated platform.
Why Migrate to TotalAppSec?
Unified Risk Management
TotalAppSec manages security for web applications and APIs through one centralized platform, eliminating the need for multiple tools.
Enhanced Discovery and Coverage
- Comprehensive Asset Inventory: Discover known, unknown, rogue, shadow, and forgotten web applications and APIs.
- Multi-Cloud and API Gateway Support: Discover assets across AWS, Azure, GCP, Mulesoft, Apigee, Azure API Management, Swagger, Postman, and Burp Suite.
- Advanced Import Options: Supports Swagger, Postman, and Burp Suite for API discovery.
Advanced Security Testing
- OWASP Top 10 coverage for web apps and APIs.
- OpenAPI v3 compliance testing.
- Sensitive data and PII exposure detection.
- Deep-learning malware detection for zero-day threats.
Prioritization with TruRisk™ Scoring
- Prioritizes and consolidates vulnerabilities from tools like Burp, Bugcrowd, and more.
- Supports automated remediation through integrations with JIRA, ServiceNow, and CI/CD platforms.
Future-Ready Platform
- All new feature enhancements are exclusive to TotalAppSec.
- WAS will continue to receive critical bug fixes only, with no new feature development.
Key Differences: TotalAppSec vs WAS
| Feature | Web Application Scanning | TotalAppSec |
|---|---|---|
| Web Application Scanning | Basic Coverage | Advanced Coverage |
| API Security Testing | Limited Support | Comprehensive Support |
| Web Malware Detection | Not Available | Included |
| Asset Discovery | Manual | Automated (multi-cloud) |
| OpenAPI Compliance | Not Available | Supported |
| TruRisk™ Scoring | Not Available | Included |
| Future Enhancements | Limited (bug fixes only) | Active Development |
Migration Process
- Review current WAS configuration
- List all web applications and APIs currently scanned.
- Plan License Allocation
- Allocate flexible licenses across web apps and APIs as needed.
- Migrate Configurations
- Qualys supports seamless migration of WAS configurations and data into TotalAppSec.
- Enable new features
- Enable API discovery, malware detection, and TruRisk™ scoring.
- Integrate with CI/CD Pipelines
- Utilize integrations for Jenkins, Bamboo, ADO, and more.
Frequently Asked Questions
- Why should we migrate if WAS already meets our needs?
- TotalAppSec builds upon WAS capabilities by integrating API security and malware detection into a single platform. Any future feature enhancements will only be added to TotalAppSec.
- Will migration be disruptive?
- No. The migration process is designed to be seamless, allowing reuse of existing WAS configurations and data.
- Will there be additional costs?
- TotalAppSec consolidates functionalities of multiple tools, improving ROI and reducing overall costs.
- What if API security or malware detection is not a priority for us?
- Even if these are not current focus areas, shadow APIs and malware targeting web apps are growing exponentially. TotalAppSec helps address these emerging threats.
- Even if these are not current focus areas, shadow APIs and malware targeting web apps are growing exponentially. TotalAppSec helps address these emerging threats.