Skip to main content

Qualys proof types and permissions

Note

Hyperproof connects to many third-party systems that frequently change, including the system interface. Contact your System Administrator or the third-party provider for assistance meeting the requirements to integrate with Hyperproof and collect the proof you need.

When you create a Hypersync between Hyperproof and Qualys, you can automatically collect proof based on the following services:

  • List of Assets

  • List of Users

  • List of VM Scans

  • List of PC Scans

  • VM Remediation Tickets

Additional documentation

Note

You only need to connect Hyperproof to the app once, and then you can create as many Hypersyncs as you need. Additionally, you can create multiple Hypersyncss for a single control or label.

Important

If your Qualys instance uses Single Sign-On (SSO), you’ll need your Qualys administrator to create a Qualys service account with SSO disabled. SSO can be disabled on a per-account basis. For more information, refer to this Qualys help article.

Tip

If you don’t know your platform, see the Qualys documentation.

Supported platforms

The Qualys Hypersync supports the following platforms:

  • AE1

  • AU1

  • CA1

  • EU1

  • EU2

  • EU3

  • IN1

  • KSA1

  • UK1

  • US1

  • US2

  • US3

  • US4

For help identifying your platform, see Identify your Qualys platform in the Qualys documentation.

Permissions

The minimum permissions needed for a Qualys user to create a Hypersync are:

  • Read access to the Manage VM and Manage SCA modules

  • API Access turned on

  • Additional setup may be required for the List of Assets proof.

    • To include Cloud Agent assets in the List of Assets proof create a new Manager User and limit that user's permissions under User Management as follows:

      • Select Quick Actions > Edit > Roles and Scopes and uncheck the Allow user full permissions and scope option.

      • Add the following minimum roles: READER, Reporting Reader, Unified Dashboard User, and VM User.

      • Ensure that the Allow user view access to all objects is checked.

Creating a Qualys user with minimum permissions

  1. Log in to Qualys as an Administrator.

  2. Click the drop-down menu in the upper-left corner.

  3. Scroll to Utilities, and then select Administration.

  4. From the User Management tab, click Create User and then select Create Reader User.

    The New Reader User window opens.

  5. Enter all required information.

    Important

    Do not click the Save button until step 11.

  6. From the left navigation menu, select the User Role tab.

  7. From the User Role drop-down menu, select Reader.

  8. Select the GUI and API checkboxes.

  9. From the left navigation menu, select the Permissions tab.

  10. Select the Manage VM Module and Manage PC Module checkboxes.

  11. Click Save.

  12. Assign hosts to the Reader User using Asset Groups in VMDR and PC:

    1. Navigate to VMDR or PC.

    2. Select the Users tab.

    3. Mouse over the Reader User, click the arrow, and then click Edit.

    4. From the Asset Groups tab, add the appropriate asset group(s).

    5. Click Save.

    Refer to the Qualys documentation for help with managing asset groups.

Completing new user setup

You’ll receive an email from Qualys with the subject Qualys Registration—Start Now.

  1. Copy and save the username provided by Qualys.

  2. Click Link to access your password.

  3. Copy the OTP code from the email, paste it, and then click Submit.

  4. Copy and save the password provided by Qualys.

  5. Click the URL to log in to Qualys.

  6. Confirm the user’s information, and then click Save.

    After clicking Save, you’ll be prompted to change the user’s password.

Removing GUI access for a new user

  1. Log in to Qualys as an Administrator.

  2. Click the drop-down menu in the upper-left corner.

  3. Scroll to Utilities, and then select Administration.

  4. Mouse over the user, click the drop-down arrow, and then select Edit Basic Details.

    The Edit User window opens.

  5. From the left navigation menu, select the User Role tab.

  6. Clear the checkbox labeled GUI.

  7. Click Save.