

Qualys Policy Compliance and RSA Archer compete in IT policy management and compliance. RSA Archer leads in feature sets, though some prefer Qualys' pricing and support, appealing to budget-conscious buyers.
Features: RSA Archer allows customizable risk management and compliance frameworks, offers advanced integration, and features comprehensive dashboards for risk visibility. Qualys Policy Compliance focuses on automated compliance checks, continuous monitoring, and efficient adherence to standards.
Room for Improvement: RSA Archer could benefit from simplified deployment processes, additional user training resources, and improved usability feedback mechanisms. Qualys Policy Compliance might enhance its feature sets to match the needs of larger enterprises, enhance dashboard capabilities, and provide more integration options.
Ease of Deployment and Customer Service: Qualys Policy Compliance is known for a swift cloud-based deployment and intuitive setup, while RSA Archer offers detailed guidance though its deployment can be complex due to its comprehensive nature. Both provide effective customer service, with Qualys ensuring fast onboarding and RSA Archer providing extensive support.
Pricing and ROI: Qualys Policy Compliance typically offers a lower setup cost, appealing for cost-effective compliance solutions and provides faster ROI in budget-sensitive scenarios. RSA Archer may require a higher initial investment but promises broader functionality and potential long-term ROI in complex environments.
It relates to the effectiveness of employees and the time taken to complete tasks manually versus using the RSA system.
They understood the scope, and we were ready to jump into the implementation phase in a day or two.
Qualys Policy Compliance customer support is very good.
The response time from RSA Archer's support team is not an issue; usually, there's no problem getting a timely response, but there could be more knowledgeable agents available.
They are responsive and perform well in technical support.
In terms of scalability with Qualys Policy Compliance, we did not face any issues. It was scalable.
Scalability depends on the number of servers, including web and service servers.
The level of scalability depends on customization and how skillful our customization team is.
Once everything is set and done with Qualys Policy Compliance, we did not face any performance issues or issues in terms of it being resource-friendly or utilizing any machine resources.
It is very rare to encounter performance issues, about 0.1 to 0.01%.
The tool has stability, and it allows me to automate whatever process I have.
Performance issues arise mainly since it is not a core service for most organizations, so the resources provided are fewer.
If there were some sort of reporting that fulfills auditor's requirements, particularly if there is an external audit and they ask us for any historical data like how long we have been compliant to the PCI framework, that would be valuable.
They need to improve the reporting part of the CI/CD pipelines and the ability to download scans from pods.
While the AI features are emerging and the cost is comparatively low, it's not yet up to the market standard.
A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client.
Dashboards are usually effective, but while visibility from the dashboard level is good, drill-down details may be difficult to access, as they don't seem to have direct support for this drill-down.
after comparing it with other products in the market, I would rate it around six or seven out of ten, as the price is relative.
In Qualys Policy Compliance, the best feature is that they keep their vulnerability database updated.
From the Qualys Policy Compliance, the best feature is that they have predefined templates for compliances, allowing easy application of compliance requirements against our products and providing clear reports on whether assets are compliant or not.
In the banking sector, Archer has been used to automate processes such as business continuity management, transitioning from manual processes to automated systems.
The helpful features of RSA Archer include providing an integrated overview of the landscape in the company, which leads the user to use the same inventory and other components, sharing the same set of references and objects we are working on.
This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.
| Product | Mindshare (%) |
|---|---|
| RSA Archer | 21.5% |
| Qualys Policy Compliance | 3.9% |
| Other | 74.6% |
| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 2 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 6 |
| Large Enterprise | 25 |
Qualys Policy Compliance offers seamless compliance management featuring real-time threat detection, policy customization, and integration with SIEM and ticketing tools. It supports both on-premises and cloud assets, ensuring comprehensive security management.
Qualys Policy Compliance provides a streamlined approach to compliance through its predefined templates and frequent vulnerability updates, supporting the compliance needs of organizations managing diverse infrastructures. Its interface allows effective management of security policies and straightforward compliance verification. Users benefit from enhanced security management with its automation features and asset scanning capabilities. Integration with cloud infrastructure and seamless policy management across platforms like Windows, Linux, and networking appliances make it indispensable for enterprises seeking minimal vulnerabilities.
What are the key features of Qualys Policy Compliance?Banks and organizations utilize Qualys Policy Compliance for server hardening and security configuration verification. Loading it with security policies, they ensure PCI compliance and effective vulnerability management. It's particularly effective across Windows, Linux, and networking appliances with basic scans for compliance checks.
RSA Archer provides robust risk management, compliance, and vendor management with intuitive features for customizable and streamlined governance tasks.
RSA Archer delivers integrated solutions supporting risk management and compliance tasks. Its adaptive interface and customizable options enhance workflows, making it valuable for organizations requiring automation, advanced workflows, and easy integration capabilities. While offering flexibility and configuration power, users note potential enhancements for integration, reporting, and interface updates.
What are the key features of RSA Archer?In the finance, public, and IT sectors, RSA Archer is utilized for managing risk and compliance. Organizations leverage its capabilities for third-party risk, policy management, and security assessments, providing tailored solutions for regulatory compliance and operational risk management. Integration with platforms like ServiceNow enhances its utility within enterprise environments.
We monitor all IT Governance reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.