Saturday, November 19, 2022

Vulnerability Management - Policy Compliance (Evaluation Date, Last Updated Date, Policy Last Evaluated Date) (Qualys)

1) Last Updated (Last Scan Date)

This is the date of the latest scan when data for control is collected. Thus, every time data is collected for control, this value gets updated


2) Evaluation Date

This is the date a control gets evaluated; control evaluation happens as a part of policy evaluation. Hence, this value will be lower (or the same) than the "Policy last evaluated" date.


3) Policy Last Evaluated

This is the date when the policy evaluation is complete. This value gets updated every time policy evaluation is triggered for a host.


Now that we know about the types of dates in PC, let's discuss about a situation where you test a control in a policy for an IP address and the control is passing. However it is failing while you are generating the report. What should you do now ? You should evaluate the policy again.


Typically, policy evaluation is triggered right after scan data is collected; however, sometimes due to processing overload, there could be some delay.


If a report is generated for targets before policy evaluation is complete, the "Last updated" value will exceed the "Evaluation date". In such a scenario, users should wait for it to be complete. List of pending processing tasks can be accessed as "PC > Scan > PC Scans > Filters > Processing Tasks...".


Users could trigger the policy evaluation manually as follows:


 "PC > Policies > Edit Policy > (Check "Evaluate now" if not already) Save"


 OR


 "PC > Policies > Policy Data-list > click Quick Actions > Evaluate for a policy"  


Please refer the below link for more information:

https://success.qualys.com/support/s/article/000006635


Happy Learning !!

No comments:

Post a Comment

Vulnerability Management - Understanding vulnerability posture

Understanding the vulnerability posture of an organisation at a basic level helps you drive remediation efforts. So, I don't know what t...