Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

MARS and Qualys vulnerability scanning integration

What does adding Qualys vulnerability scan data to MARS allow MARS, help MARS to do?

Does it help MARS identify an alert as a false positive in the context of a host which Qualys says isn't vulnerable OR does it do something else like when the Qualys data is retrieved simply listing each vulnerability as an incident?

3 REPLIES
Community Member

Re: MARS and Qualys vulnerability scanning integration

My understanding was the Qualys would inform MARS if a system was really vulnerable or not based on it's (the qualys box) information of the situation.

http://www.cisco.com/en/US/docs/security/security_management/cs-mars/6.0/device/configuration/guide/cfgVulAs.html

Erric

Community Member

Re: MARS and Qualys vulnerability scanning integration

I just made the configuration to day, it seems to work corectly, but I am wondering something. Does anyone has really estimated the real benefits of using qualysquard with Csmars ?

Community Member

Re: MARS and Qualys vulnerability scanning integration

I haven't been able to set this up yet. If MARS is able to mark alerts which don't apply to a device as false positives or something like that it could be valuable because it would save the staff time hunting down false positives.

238
Views
0
Helpful
3
Replies
CreatePlease to create content