Proactive Early Threat Detection and Securing Oracle Database with IBM QRadar, IBM Security Guardium Database Protection, and IBM Copy Services Manager by using IBM FlashSystem Safeguarded Copy Proactive Early Threat Detection and Securing Oracle Database with IBM QRadar, IBM Security Guardium Database Protection, and IBM Copy Services Manager by using IBM FlashSystem Safeguarded Copy

Proactive Early Threat Detection and Securing Oracle Database with IBM QRadar, IBM Security Guardium Database Protection, and IBM Copy Services Manager by using IBM FlashSystem Safeguarded Copy

وصف الناشر

This IBM® blueprint publication focuses on early threat detection within a database environment by using IBM Security® Guardium® Data Protection and IBM QRadar® . It also highlights how to proactively start a cyber resilience workflow in response to a cyberattack or potential malicious user actions.

The workflow that is presented here uses IBM Copy Services Manager as orchestration software to start IBM FlashSystem® Safeguarded Copy functions. The Safeguarded Copy creates an immutable copy of the data in an air-gapped form on the same IBM FlashSystem for isolation and eventual quick recovery.

This document describes how to enable and forward Oracle database user activities (by using IBM Security Guardium Data Protection) and IBM FlashSystem audit logs by using IBM FlashSystem to IBM QRadar.

This document also describes how to create various rules to determine a threat, and configure and launch a suitable response to the detected threat in IBM QRadar.

The document also outlines the steps that are involved to create a Scheduled Task by using IBM Copy Services Manager with various actions.

النوع
كمبيوتر وإنترنت
تاريخ النشر
٢٠٢٣
١٠ مارس
اللغة
EN
الإنجليزية
عدد الصفحات
٤٨
الناشر
IBM Redbooks
البائع
International Business Machines Corp
الحجم
١٫٢
‫م.ب.‬
Enhanced Cyber Resilience Solution by Threat Detection using IBM Cloud Object Storage System and IBM QRadar SIEM Enhanced Cyber Resilience Solution by Threat Detection using IBM Cloud Object Storage System and IBM QRadar SIEM
٢٠٢١
Deployment Guide for InfoSphere Guardium Deployment Guide for InfoSphere Guardium
٢٠١٥
IT Security Compliance Management Design Guide with IBM Tivoli Security Information and Event Manager IT Security Compliance Management Design Guide with IBM Tivoli Security Information and Event Manager
٢٠١٠
IBM QRadar Version 7.3 Planning and Installation Guide IBM QRadar Version 7.3 Planning and Installation Guide
٢٠١٨
IBM Systems Director Navigator for i IBM Systems Director Navigator for i
٢٠٠٩
IBM i 7.2 Technical Overview with Technology Refresh Updates IBM i 7.2 Technical Overview with Technology Refresh Updates
٢٠١٦
Securing Data on Threat Detection by Using IBM Spectrum Scale and IBM QRadar: An Enhanced Cyber Resiliency Solution Securing Data on Threat Detection by Using IBM Spectrum Scale and IBM QRadar: An Enhanced Cyber Resiliency Solution
٢٠٢١
Cyber Resiliency with Splunk Enterprise and IBM FlashSystem Storage Safeguarded Copy with IBM Copy Services Manager Cyber Resiliency with Splunk Enterprise and IBM FlashSystem Storage Safeguarded Copy with IBM Copy Services Manager
٢٠٢٢
IBM FlashSystem for VMware vSphere with Tanzu Basic Edition An IBM Validated Solution Guide IBM FlashSystem for VMware vSphere with Tanzu Basic Edition An IBM Validated Solution Guide
٢٠٢١
Proactive Early Threat Detection and Securing SQL Database With IBM QRadar and IBM Spectrum Copy Data Management Using IBM FlashSystem Safeguarded Copy Proactive Early Threat Detection and Securing SQL Database With IBM QRadar and IBM Spectrum Copy Data Management Using IBM FlashSystem Safeguarded Copy
٢٠٢٢