Best IT Documents.com Blog


Sample Word – Student Parent – Laptop Use Policy

Posted in Business (600),Compliances (1300),Policies - Standards (600) by Guest on the April 25th, 2015

Free MS Word Document download

StudentĀ  Parent – Laptop Use Policy

Comments Off on Sample Word – Student Parent – Laptop Use Policy

IT Security Guideline Maintenance of Record of Access Authorizations (Access Controls and Password Use)

Procedure

User Access Requests will be tracked as follows:

ISM Management System for IT administered systems / applications

For Non-IT administered applications, emails are sent to the application administrators, who are then responsible for retaining the requests.

  1. HealthStream
  2. ChartMaxx
  3. Radiology PACS
  4. Cardiology PACS
  5. Medical Necessity
  6. Omnicell
Comments Off on IT Security Guideline Maintenance of Record of Access Authorizations (Access Controls and Password Use)

Sample Visio – PowerPivot Client Server Architecture

Posted in Data Center - SOC - NOC,Visio Samples - Stencils (457) by Guest on the April 19th, 2015

Free Visio document download

PowerPivot Client Server Architecture

Comments Off on Sample Visio – PowerPivot Client Server Architecture

Sample Word – Sample Active Directory LDAP Redesign document

Posted in Information Rights Management (100),O S (375) by Guest on the April 18th, 2015

Free Word document download

Sample LDAP Redesign

Comments Off on Sample Word – Sample Active Directory LDAP Redesign document

Sample Excel – Active Directory Testing

Posted in O S (375),Sample - IT Spreadsheets - PowerPoints (251) by Guest on the April 16th, 2015

Free Sample Excel document download

Active Directory Testing

 

Comments Off on Sample Excel – Active Directory Testing

Sample Excel – Windows OS Test Plan

Posted in O S (375),Sample - IT Spreadsheets - PowerPoints (251) by Guest on the April 15th, 2015

Free Excel document download

Windows OS Test Plan

 

Comments Off on Sample Excel – Windows OS Test Plan

Sample Excel – Server Migration Checklist

Posted in O S (375),Sample - IT Spreadsheets - PowerPoints (251) by Guest on the April 14th, 2015

Free Excel document download

Server Migration Checklist

 

Comments Off on Sample Excel – Server Migration Checklist

Sample Word – Test Active Directory GUI

Posted in Information Rights Management (100),O S (375) by Guest on the April 13th, 2015

Word document download

Test Active Directory GUI

 

Comments Off on Sample Word – Test Active Directory GUI

Sample Word – Sample Identity Management Request for Proposal

Posted in Compliances (1300),Information Rights Management (100) by Guest on the April 12th, 2015

Free Word document downlaod

Sample Identity Management Request for Proposal

 

Comments Off on Sample Word – Sample Identity Management Request for Proposal

Sample Excel – CMDB Hardware Tracking Spreadsheet 2

Posted in O S (375),Sample - IT Spreadsheets - PowerPoints (251) by Guest on the April 9th, 2015

Free Excel document download

Hardware Tracking 2

Comments Off on Sample Excel – CMDB Hardware Tracking Spreadsheet 2

QualysGuard Assigning Asset Owners

Posted in Compliances (1300),Security (1500) by Guest on the April 8th, 2015

All assets must have an owner assigned that is responsible for remediating any vulnerabilities found on the system. In most cases, the owner information is tracked by IPControl.

To assign asset owners, click on the Host Assets button in the Tools Pane on the left of the QualysGuard application. Each of the assets can be edited to assign an owner. See the screenshot below:

Clicking on the edit icon will bring up the next screen:

You could also add a location tag and a function tag. There is room for comments as well for special instructions or escalation phone list or other information.

Standard Remediation Policy

The default remediation policy is to open a ticket for all level 4 and 5 vulnerabilities detected. Additional policies can be created for business units that want more granularity. The remediation policy can be viewed by clicking on Remediation Policy under the tools section.

Update Qualys Asset Groups

You may wish to group assets that are all owned by a single user into a single asset group. You can use the asset search function to look for assets by IP address. Clicking on the checkboxes and selecting add to asset group in the dropdown list will allow you to create a new asset group or add the hosts to an existing group.

Business Units

It is advisable to organize remediation teams into business units. A business unit can be a group of IT persons grouped together by region, such as APAC, or by function, such as UnixOps. To create a business unit, click the item under the tools pane and you can edit an existing business unit or create a new one.

You can add assets to the business unit and also assign users to the business unit. The advantage of using business units is that Business Unit managers can manage their own scans and remediation efforts.

Account Management

New Users will need to be added to Qualys as they are identified as asset owners so they will need to be given guidelines on how to handle tickets assigned to them. Be sure to setup these users with the option to be notified daily of tickets in their QualysGuard queue.

Also make sure you assign the new users just those asset groups that belong to them.

Typical End User Workflow:

A user will receive an email from QualysGuard stating that a vulnerability has been found on an asset assigned to him.

User will login to Qualys to review vulnerability. If the vulnerability is actionable, he can create a ticket. If it is a false positive, he can close the ticket with an explanation.

If a ticket is created, he should create a corresponding Remedy Ticket to track his time working on the remediation. The remedy ticket should contain the Qualys ticket number and the Qualys ticket should contain the corresponding Remedy ticket.

If ticket must be reassigned, it can be routed within Qualys.

When the remediation is completed, the ticket should be closed, along with the Remedy ticket.

 

Comments Off on QualysGuard Assigning Asset Owners