Transformative cloud service for conducting business process control assessments among your external and internal parties
Questionnaire is easy to use and to customize. Having it delivered via the cloud allows us to easily assess third parties.
Randy Barr VP & CISO at Saba
Qualys SAQ Highlights
Quickly design and build your security questionnaires
Qualys SAQ streamlines your third-party and internal risk assessment processes right from the questionnaire creation phase. With Qualys SAQ, you easily design in-depth surveys to make business-process control assessments of security policies and practices of third parties and internal staff, and their compliance with industry standards, regulations and internal requirements.
-
Let Qualys SAQ’s wizard walk you through the creation of campaigns, including assigning deadlines and configuring notifications
-
Create questionnaires with Qualys SAQ’s drag-and-drop UI, or tap Qualys SAQ’s template library of surveys for regulations like HIPAA, Basel 3 and SOX, and industry standards like PCI
-
Require that respondents attach evidence files for certain answers
-
Form questions with various types of answer formats, such as multiple-choice check boxes, drop-down menus and open-ended text boxes
-
Configure questions to be dynamically shown or hidden based on a prior response
-
Design campaigns with different workflows: Accept surveys once they’ve been completed by respondents, or require extra steps, such as supervisor reviews and approvals
-
Assign criticality levels to questions, and a score for answer options in the questionnaire templates. The question criticality scale is customizable with labels and answer weights
-
Allow respondents to delegate questions to peers that are better able to answer them
Launch and track campaigns from Qualys SAQ’s central console
The traditional way of conducting these risk assessment surveys – emailing questionnaires and tracking responses on a spreadsheet – no longer cuts it. Qualys SAQ automates these audit campaigns and makes the process agile, accurate, comprehensive, centralized, scalable and uniform across your organization.
-
Enter respondent emails in the Qualys SAQ web console and Qualys SAQ auto-provisions the surveys, sending out links to the web-based questionnaires
-
Centrally manage and track the progress of all of your campaigns
-
Monitor response activity in dashboards updated in real time, and literally watch as questions are answered
-
Let supervisors review the format and content of questionnaires before they’re launched and even while a campaign is in progress
-
Set up recurring campaigns that need to be run with a specific frequency
-
Support a wide variety of risk assessment use cases within your organization and externally with your vendors, contractors, partners and consultants, including:
- Auditing current vendors to make sure they remain compliant
- Evaluating vendors bidding for your business
- Assessing for the first time a key supplier you just signed up
- Conducting a “postmortem” assessment of a slip-up by one of your third parties
- Verifying your employees understand IT security and compliance policies and procedures
Simplify the process of responding to questionnaires
If the process of filling out a risk assessment questionnaire is cumbersome, this will affect the quality and thoroughness of answers provided by respondent, as well as their timeliness for completing the surveys. Qualys SAQ makes the task intuitive with a raft of convenient features designed to make life easier for respondents, including.
-
Quickly and efficiently completing questionnaires from any browser at any time
-
Securely attaching evidence files with drag-and-drop convenience
-
Delegating questions to other users or user groups based on their role
-
Receiving reminder emails regarding due dates and completion status
Document, visualize and share campaign results
The goal of these campaigns is to quickly and precisely identify IT security and compliance gaps among your network of third parties, and within your organization, so you can take appropriate action. Qualys SAQ gives you all the tools for displaying, understanding, analyzing and acting on the collected data.
-
Provide high-level dashboards for executives and detailed views for internal auditors and compliance officers
-
When generating reports, filter data by question criticality and answer scores to derive an overall risk score or identify high risk areas
-
Create custom dashboards designed to reflect the risk and compliance postures of specific third parties
-
Slice and dice campaign results using a variety of criteria, such as by vendor, respondent or specific questions
-
Generate proof of compliance with detailed reports
Streamline GDPR procedural risk assessments
The EU’s GDPR compliance process requires organizations to perform procedural risk assessments, which Qualys SAQ can assist you with. Its GDPR-specific questionnaire templates break down requirements and help assess business readiness for compliance. Using these out-of-the-box questionnaires will save you time, effort and resources as you assess GDPR procedural compliance and generate reports based on responses. Qualys SAQ’s GDPR questionnaire templates include:
-
GDPR Business Readiness Self-Assessment
Designed to identify key areas where operational changes will be required and to assist the organization in prioritizing efforts for the GDPR compliance. -
GDPR Data Inventory and Mapping
Helps in assessing the process to identify, locate, classify and map the flow of GDPR-protected data. -
GDPR Accountability and Responsibility Assessment
Helps in assessing the process of accountability and responsibility in terms of data governance as per GDPR requirements. -
GDPR Data Privacy Assessment in Operations
Focuses on assessing the appropriate technical and organizational measures to protect EU residents’ personal data from loss or unauthorized access or disclosure.
-
GDPR Third-Party Vendor Assessment
Helps to identify and assess the requirements of the third-party vendors you share personal data of EU residents with. -
GDPR Data Incident and Breach Notification Assessment
Helps in the assessment of GDPR’s data breach notification and communication requirements. -
GDPR Data Protection and Privacy Impact Assessment
Helps organizations in the assessment of the privacy risks and data protection safeguards of new projects.
See for yourself. Try Qualys for free.
Start your free trial today. No software to download or install. Email us or call us at 1 (800) 745-4355.