SlideShare a Scribd company logo
2
Most read
3
Most read
4
Most read
HCL BigFix
Align security teams using Qualys® with IT
operations teams using BigFix and dramatically
compress vulnerability resolution time.
HCL BigFix Insights for Vulnerability
Remediation Integration with Qualys
Highlights
• Dramatically reduce the
gap between Security and
IT operations, reducing time
required to close discovered
vulnerabilities
• Automatically correlates
vulnerabilities discovered by
Qualys with the recommended
remediation Fixlets using BigFix
supersedence engine
• Shrinks attack surfaces and
closes the loop between
vulnerability detection and
remediation
• Requires no additional agents
or relays and has no impact
on the endpoint or network
performance
Today, it can take days or weeks for IT Operations to remediate vulnerabilities
found by IT Security, exposing organizations to potential attacks. As a result,
mitigating the risk of cyberattacks continues to top CIO and CISO lists of
concerns.
Companies who detect vulnerabilities using Qualys® are focused on seeking
out vulnerabilities across the organization. IT operations teams using BigFix®
systematically find and deploy the right patch for each unique vulnerability
identified by Qualys. In many cases, there is a communication gap between
these two teams, resulting in excessive manual effort, spreadsheet errors and
long windows of vulnerability. In fact, studies show that up to one-third of all
detected vulnerabilities remain open after a year, and over one-quarter are
never remediated.
BigFix Insights for Vulnerability Remediation can reduce the time it takes for IT
Operations to remediate vulnerabilities found by IT Security from days or weeks
to minutes or hours. BigFix Insights for Vulnerability Remediation automatically
correlates vulnerabilities discovered by Qualys with the most appropriate
patch and configuration settings enabling organizations to quickly prioritize
and deploy remediation actions, reducing the enterprise attack surface. Unlike
other solutions. BigFix leverages the broadest set of remediation capabilities,
both in terms of supported OS platforms and out of-the-box, certified
remediations.
BigFix Insights for Vulnerability Remediation is designed specifically for
organizations who use BigFix Lifecycle, BigFix Compliance, or BigFix Remediate
and who also use Qualys for vulnerability management.
BigFix Remediate
can resolve
vulnerabilities faster...
up to 96% faster!
Speed Remediation of Vulnerabilities -
How it works
BigFix Insights for Vulnerability Remediation
speeds remediation by automating manual
processes that are commonly seen in
organizations. Automated correlation of
vulnerability scan data from Qualys with
available Fixlets along with simple, prioritized
deployment workflows from BigFix speeds
remediation of endpoint vulnerabilities across
the enterprise.
The operational flow is:
1. A Security Operator performs a scan using
Qualys to identify the vulnerabilities across
the enterprise.
2. The vulnerabilities or Common Vulnerabilities
and Exposures (CVE®) identified by Qualys
are automatically correlated with BigFix’s
comprehensive patch data using the BigFix
Advanced Patch Correlation Engine. The
correlation engine:
a) Correlating the asset between Qualys and
BigFix.
b) Correlating the asset vulnerabilities between
Qualys and BigFix using CVEs.
c) Identifying the BigFix Fixlet that mitigates the
discovered vulnerability.
3. After correlation, staff can examine the
information and take action.
a) Data or Security Analysts can leverage
Business Intelligence Reports, drilling down
into the details to better understand the
vulnerabilities and potential remediations.
b) BigFix Operators can leverage the Vulnerability
Remediation Dashboard to see vulnerabilities
that can be remediated using available BigFix
Fixlets, and more importantly, immediately
target and deploy remediations.
Using this operational workflow, organizations
using Qualys can leverage BigFix Insights for
Vulnerability Remediation to dramatically reduce
the remediation time, manual errors and the attack
surface.
HCL BigFix
hcl-software.com
A Case Study of BigFix for Insights
Vulnerability Remediation
Typically, an IT operations or Security specialist will spend
2-3 minutes researching the right remediation for each
vulnerability. With potentially hundreds or thousands, that is a
lot of time spent. BigFix Insights for Vulnerability Remediation
automates this process with the Advanced Patch Correlation
Engine which:
What does this mean in business terms?
An organization with 1,000 running vulnerabilities will spend
up to 50 person-hours per assessment cycle researching
and correlating available fixes to the correct assets. With
BigFix Insights for Vulnerability Remediation, this time can
be reduced to less than two hours by automating manual
processes and reducing errors and associated rework. That is
96% less effort!
IT organization can also quickly implement fixes and
effectively prove compliance to auditors and executive
stakeholders. With BigFix Insights for Vulnerability
Remediation, IT Security and IT Operation teams can
collaborate effectively to quickly remediate vulnerabilities
discovered in a prioritized manner, providing significant
operational and organizational value to the CIO and CISO.
BigFix Insights for Vulnerability Remediation delivers
signification business value by:
• Aligning Security and Operations teams with intelligent
automation
• Compressing security vulnerability remediation times by
an order of magnitude
• Implementing fixes and proving compliance to all
stakeholders
• Reducing enterprise security risk, helping prevent
cyberattacks
BigFix Insights for Vulnerability Remediation
Application
The BigFix Insights for Vulnerability Remediation Application for Qualys
provides actionable views of the correlated data from Qualys and BigFix.
Each view helps IT and Security operators understand the magnitude
and severity of the vulnerabilities in different ways to enable effective
prioritization of remediation actions. Operators can leverage the interactive
visualizations to filter and drill down to more detail associated with the
correlated vulnerabilities and devices.
Three Granular Views
(1) Graphical overview/summary - Comprises three graphs or charts for a
high-level visual overview to enable very quick prioritization across multiple
contexts. The three graphs are shown in the top half of the image below and
depicts:
Top 10 Critical Exposures by CVE/Qualys ID - The first chart depicts
the top ten critical exposures by either CVE or Qualys ID to help you
quickly identify critical vulnerabilities with high exposures that can be
remediated by BigFix.
Vulnerabilities by Severity - The second chart depicts vulnerabilities
with available Fixlets by Qualys severity score or by CVSS. Qualys’s
severity score enables prioritization of vulnerabilities and the CVSS
(Common Vulnerability Scoring System) is an industry standard for
assessing the severity of vulnerabilities.
Vulnerabilities by Date Published and Severity - The third chart
augments the details provided in the Vulnerabilities by Severity chart.
Specifically, this graph adds the date published (i.e. the date the
vulnerability record was first added to the CVE List) for the top 10
vulnerabilities
(2) Data view - Depicts vulnerabilities with available Fixlets, along with the
number of affected devices in a tabular format. The data view provides the
ability to search each column for a specific value, filter, or sort the values in
column. The data view is shown in the bottom half of the image below.
(3) Vulnerability view - From the Data view, select a specific vulnerability to
view more detail including vulnerability metadata, available Fixlet content for
remediation, applicable devices, and deployment statuses.
hcl-software.com
About HCLSoftware   
HCLSoftware is a division of HCLTech (HCL) that operates its primary software business. It develops, markets, sells, and supports
over 30 product families in the areas of Digital Transformation, Data Analytics & Insights, Al and Automation, and Enterprise Security.
HCLSoftware has offices and labs around the world to serve thousands of customers. Its mission is to drive ultimate customer
success with their IT investments through relentless innovation of its products.
© Copyright 2023 HCL
All product names, trademarks and registered trademarks are property of their respective owners
hcl-software.com

More Related Content

PDF
Future-Proof Your Security: Automate Patching and Minimize Vulnerabilities
PDF
HCL BigFix - The Endpoint Management Platform - DNUG Stammtisch Hamburg.pdf
PDF
HCL BigFix- Find More, Fix More & Do More
PDF
Trends in Cybersecurity - DNUG Stammtisch Wien
PDF
Maintaining Continuous Compliance with HCL BigFix
PDF
HCL BigFix - DNUG Stammtisch Salzburg
PDF
Solve Employee Experience, Security, and Silo Problems with HCL BigFix Workspace
PDF
DACHNUG50 HCL BigFix_Keynote.pdf
Future-Proof Your Security: Automate Patching and Minimize Vulnerabilities
HCL BigFix - The Endpoint Management Platform - DNUG Stammtisch Hamburg.pdf
HCL BigFix- Find More, Fix More & Do More
Trends in Cybersecurity - DNUG Stammtisch Wien
Maintaining Continuous Compliance with HCL BigFix
HCL BigFix - DNUG Stammtisch Salzburg
Solve Employee Experience, Security, and Silo Problems with HCL BigFix Workspace
DACHNUG50 HCL BigFix_Keynote.pdf

Similar to Integration of Qualys with HCL BigFix Insights for Vulnerability Remediation (20)

PDF
TENABLE AND HCL BIGFIX REDUCE RISK BY OPTIMIZING REMEDIATION WORKFLOWS
PDF
DACHNUG50 BigFix NIS2.pdf
PDF
Bigfix Lifecycle - Reduce Cost, Risk of Managing Endpoints
PDF
DACHNUG50 BigFix WorkspaceAndAutomation.pdf
PDF
BigFix Mobile- Extending modern endpoint management capabilities to iOS and A...
PDF
IBM BigFix Online Training
PDF
DACHNUG50 HCL BigFix mobile.pdf
PPTX
Slides zum Impulsreferat: HCL BigFix - DNUG Stammtisch Karlsruhe
PDF
Bigfix Multicloud Management
PPTX
VRX_ Presentation 2023 (1).pptx
PDF
11th Website Security Statistics -- Presentation Slides (Q1 2011)
PDF
BigFix Mobile: Expanding Modern Endpoint Management to iOS and Android
PDF
BigFix White Paper
PDF
Ensuring continuous compliance of security and regulatory policies
PPTX
Frustrated with Vulnerability Assessments you must put your Blood, Sweat, and...
PDF
Bigfix Multicloud Management
PPTX
Extending QRadar’s reach and simplifying incident response with BigFix
PDF
Service now vulnerability patching_move
PDF
BigFix Data Sheet
PDF
Outpost24 webinar - Differentiating vulnerabilities from risks to reduce time...
TENABLE AND HCL BIGFIX REDUCE RISK BY OPTIMIZING REMEDIATION WORKFLOWS
DACHNUG50 BigFix NIS2.pdf
Bigfix Lifecycle - Reduce Cost, Risk of Managing Endpoints
DACHNUG50 BigFix WorkspaceAndAutomation.pdf
BigFix Mobile- Extending modern endpoint management capabilities to iOS and A...
IBM BigFix Online Training
DACHNUG50 HCL BigFix mobile.pdf
Slides zum Impulsreferat: HCL BigFix - DNUG Stammtisch Karlsruhe
Bigfix Multicloud Management
VRX_ Presentation 2023 (1).pptx
11th Website Security Statistics -- Presentation Slides (Q1 2011)
BigFix Mobile: Expanding Modern Endpoint Management to iOS and Android
BigFix White Paper
Ensuring continuous compliance of security and regulatory policies
Frustrated with Vulnerability Assessments you must put your Blood, Sweat, and...
Bigfix Multicloud Management
Extending QRadar’s reach and simplifying incident response with BigFix
Service now vulnerability patching_move
BigFix Data Sheet
Outpost24 webinar - Differentiating vulnerabilities from risks to reduce time...
Ad

More from HCLSoftware (20)

PDF
Maximize Investment and Unlock New Potential with Domino's Restart Plus
PDF
Say Goodbye to Patching Pain Points: BigFix Delivers Continuous Security for ...
PDF
HCL Domino Leap: Your Low-Code Pathway to Complex Web Applications
PDF
Ready to Transform? Explore the Power of Domino v12 and CCB Licensing
PDF
Level Up Web App Security: Start Your Free Trial of HCL AppScan Source
PDF
Selecting an App Security Testing Partner: An eGuide
PDF
Streamline App Security Testing: Proven Solution for Risk Mitigation & Regula...
PDF
Cloud-Based, All-In-One Security Solution, Robust and Scalable
PDF
HCL Commerce Cloud: Elevate Sales with Integrated B2B Solutions
PDF
Leading Grocer Trusts Digital Experience for Staff Portal.pdf
PDF
Biopharmaceutical Giant Modernizes On a Cost-Efficient Single Platform with H...
PDF
All-In-One Security: Visibility, Risk Management. Versatile, Scalable, Deploy...
PDF
DRYiCE™ iAutomate: AI-enhanced Intelligent Runbook Automation
PDF
Elevate your SAP landscape's efficiency and performance with HCL Workload Aut...
PDF
Unlocking Success with Volt MX Lab Services for Low-Code Application Platforms
PDF
Maximizing Business Efficiency and User Experience with HCL Domino Resta Plus
PDF
HCL Enterprise Ecommerce Solution: The Transaction Platform that Helps You Se...
PDF
Technology company advances to an AI-powered Customer experience with HCL Dig...
PDF
Procuring an Application Security Testing Partner
PDF
HCLSoftware Launches HCL BigFix 11: A New Era of Gen AI Capabilities for Secu...
Maximize Investment and Unlock New Potential with Domino's Restart Plus
Say Goodbye to Patching Pain Points: BigFix Delivers Continuous Security for ...
HCL Domino Leap: Your Low-Code Pathway to Complex Web Applications
Ready to Transform? Explore the Power of Domino v12 and CCB Licensing
Level Up Web App Security: Start Your Free Trial of HCL AppScan Source
Selecting an App Security Testing Partner: An eGuide
Streamline App Security Testing: Proven Solution for Risk Mitigation & Regula...
Cloud-Based, All-In-One Security Solution, Robust and Scalable
HCL Commerce Cloud: Elevate Sales with Integrated B2B Solutions
Leading Grocer Trusts Digital Experience for Staff Portal.pdf
Biopharmaceutical Giant Modernizes On a Cost-Efficient Single Platform with H...
All-In-One Security: Visibility, Risk Management. Versatile, Scalable, Deploy...
DRYiCE™ iAutomate: AI-enhanced Intelligent Runbook Automation
Elevate your SAP landscape's efficiency and performance with HCL Workload Aut...
Unlocking Success with Volt MX Lab Services for Low-Code Application Platforms
Maximizing Business Efficiency and User Experience with HCL Domino Resta Plus
HCL Enterprise Ecommerce Solution: The Transaction Platform that Helps You Se...
Technology company advances to an AI-powered Customer experience with HCL Dig...
Procuring an Application Security Testing Partner
HCLSoftware Launches HCL BigFix 11: A New Era of Gen AI Capabilities for Secu...
Ad

Recently uploaded (20)

PDF
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
PPTX
Introduction to Artificial Intelligence
PPTX
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
PPTX
Computer Software and OS of computer science of grade 11.pptx
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PPTX
VVF-Customer-Presentation2025-Ver1.9.pptx
PDF
Digital Systems & Binary Numbers (comprehensive )
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
PPTX
L1 - Introduction to python Backend.pptx
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PDF
How to Migrate SBCGlobal Email to Yahoo Easily
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
top salesforce developer skills in 2025.pdf
PDF
Upgrade and Innovation Strategies for SAP ERP Customers
PPT
Introduction Database Management System for Course Database
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PDF
Softaken Excel to vCard Converter Software.pdf
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
Introduction to Artificial Intelligence
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
Computer Software and OS of computer science of grade 11.pptx
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
VVF-Customer-Presentation2025-Ver1.9.pptx
Digital Systems & Binary Numbers (comprehensive )
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
L1 - Introduction to python Backend.pptx
Navsoft: AI-Powered Business Solutions & Custom Software Development
How to Migrate SBCGlobal Email to Yahoo Easily
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
Wondershare Filmora 15 Crack With Activation Key [2025
Design an Analysis of Algorithms I-SECS-1021-03
top salesforce developer skills in 2025.pdf
Upgrade and Innovation Strategies for SAP ERP Customers
Introduction Database Management System for Course Database
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
Design an Analysis of Algorithms II-SECS-1021-03
Softaken Excel to vCard Converter Software.pdf

Integration of Qualys with HCL BigFix Insights for Vulnerability Remediation

  • 1. HCL BigFix Align security teams using Qualys® with IT operations teams using BigFix and dramatically compress vulnerability resolution time. HCL BigFix Insights for Vulnerability Remediation Integration with Qualys Highlights • Dramatically reduce the gap between Security and IT operations, reducing time required to close discovered vulnerabilities • Automatically correlates vulnerabilities discovered by Qualys with the recommended remediation Fixlets using BigFix supersedence engine • Shrinks attack surfaces and closes the loop between vulnerability detection and remediation • Requires no additional agents or relays and has no impact on the endpoint or network performance Today, it can take days or weeks for IT Operations to remediate vulnerabilities found by IT Security, exposing organizations to potential attacks. As a result, mitigating the risk of cyberattacks continues to top CIO and CISO lists of concerns. Companies who detect vulnerabilities using Qualys® are focused on seeking out vulnerabilities across the organization. IT operations teams using BigFix® systematically find and deploy the right patch for each unique vulnerability identified by Qualys. In many cases, there is a communication gap between these two teams, resulting in excessive manual effort, spreadsheet errors and long windows of vulnerability. In fact, studies show that up to one-third of all detected vulnerabilities remain open after a year, and over one-quarter are never remediated. BigFix Insights for Vulnerability Remediation can reduce the time it takes for IT Operations to remediate vulnerabilities found by IT Security from days or weeks to minutes or hours. BigFix Insights for Vulnerability Remediation automatically correlates vulnerabilities discovered by Qualys with the most appropriate patch and configuration settings enabling organizations to quickly prioritize and deploy remediation actions, reducing the enterprise attack surface. Unlike other solutions. BigFix leverages the broadest set of remediation capabilities, both in terms of supported OS platforms and out of-the-box, certified remediations. BigFix Insights for Vulnerability Remediation is designed specifically for organizations who use BigFix Lifecycle, BigFix Compliance, or BigFix Remediate and who also use Qualys for vulnerability management. BigFix Remediate can resolve vulnerabilities faster... up to 96% faster!
  • 2. Speed Remediation of Vulnerabilities - How it works BigFix Insights for Vulnerability Remediation speeds remediation by automating manual processes that are commonly seen in organizations. Automated correlation of vulnerability scan data from Qualys with available Fixlets along with simple, prioritized deployment workflows from BigFix speeds remediation of endpoint vulnerabilities across the enterprise. The operational flow is: 1. A Security Operator performs a scan using Qualys to identify the vulnerabilities across the enterprise. 2. The vulnerabilities or Common Vulnerabilities and Exposures (CVE®) identified by Qualys are automatically correlated with BigFix’s comprehensive patch data using the BigFix Advanced Patch Correlation Engine. The correlation engine: a) Correlating the asset between Qualys and BigFix. b) Correlating the asset vulnerabilities between Qualys and BigFix using CVEs. c) Identifying the BigFix Fixlet that mitigates the discovered vulnerability. 3. After correlation, staff can examine the information and take action. a) Data or Security Analysts can leverage Business Intelligence Reports, drilling down into the details to better understand the vulnerabilities and potential remediations. b) BigFix Operators can leverage the Vulnerability Remediation Dashboard to see vulnerabilities that can be remediated using available BigFix Fixlets, and more importantly, immediately target and deploy remediations. Using this operational workflow, organizations using Qualys can leverage BigFix Insights for Vulnerability Remediation to dramatically reduce the remediation time, manual errors and the attack surface. HCL BigFix hcl-software.com
  • 3. A Case Study of BigFix for Insights Vulnerability Remediation Typically, an IT operations or Security specialist will spend 2-3 minutes researching the right remediation for each vulnerability. With potentially hundreds or thousands, that is a lot of time spent. BigFix Insights for Vulnerability Remediation automates this process with the Advanced Patch Correlation Engine which: What does this mean in business terms? An organization with 1,000 running vulnerabilities will spend up to 50 person-hours per assessment cycle researching and correlating available fixes to the correct assets. With BigFix Insights for Vulnerability Remediation, this time can be reduced to less than two hours by automating manual processes and reducing errors and associated rework. That is 96% less effort! IT organization can also quickly implement fixes and effectively prove compliance to auditors and executive stakeholders. With BigFix Insights for Vulnerability Remediation, IT Security and IT Operation teams can collaborate effectively to quickly remediate vulnerabilities discovered in a prioritized manner, providing significant operational and organizational value to the CIO and CISO. BigFix Insights for Vulnerability Remediation delivers signification business value by: • Aligning Security and Operations teams with intelligent automation • Compressing security vulnerability remediation times by an order of magnitude • Implementing fixes and proving compliance to all stakeholders • Reducing enterprise security risk, helping prevent cyberattacks BigFix Insights for Vulnerability Remediation Application The BigFix Insights for Vulnerability Remediation Application for Qualys provides actionable views of the correlated data from Qualys and BigFix. Each view helps IT and Security operators understand the magnitude and severity of the vulnerabilities in different ways to enable effective prioritization of remediation actions. Operators can leverage the interactive visualizations to filter and drill down to more detail associated with the correlated vulnerabilities and devices. Three Granular Views (1) Graphical overview/summary - Comprises three graphs or charts for a high-level visual overview to enable very quick prioritization across multiple contexts. The three graphs are shown in the top half of the image below and depicts: Top 10 Critical Exposures by CVE/Qualys ID - The first chart depicts the top ten critical exposures by either CVE or Qualys ID to help you quickly identify critical vulnerabilities with high exposures that can be remediated by BigFix. Vulnerabilities by Severity - The second chart depicts vulnerabilities with available Fixlets by Qualys severity score or by CVSS. Qualys’s severity score enables prioritization of vulnerabilities and the CVSS (Common Vulnerability Scoring System) is an industry standard for assessing the severity of vulnerabilities. Vulnerabilities by Date Published and Severity - The third chart augments the details provided in the Vulnerabilities by Severity chart. Specifically, this graph adds the date published (i.e. the date the vulnerability record was first added to the CVE List) for the top 10 vulnerabilities (2) Data view - Depicts vulnerabilities with available Fixlets, along with the number of affected devices in a tabular format. The data view provides the ability to search each column for a specific value, filter, or sort the values in column. The data view is shown in the bottom half of the image below. (3) Vulnerability view - From the Data view, select a specific vulnerability to view more detail including vulnerability metadata, available Fixlet content for remediation, applicable devices, and deployment statuses. hcl-software.com
  • 4. About HCLSoftware    HCLSoftware is a division of HCLTech (HCL) that operates its primary software business. It develops, markets, sells, and supports over 30 product families in the areas of Digital Transformation, Data Analytics & Insights, Al and Automation, and Enterprise Security. HCLSoftware has offices and labs around the world to serve thousands of customers. Its mission is to drive ultimate customer success with their IT investments through relentless innovation of its products. © Copyright 2023 HCL All product names, trademarks and registered trademarks are property of their respective owners hcl-software.com