Securing IBM Spectrum Scale with QRadar and IBM Cloud Pak for Security Securing IBM Spectrum Scale with QRadar and IBM Cloud Pak for Security

Securing IBM Spectrum Scale with QRadar and IBM Cloud Pak for Security

Publisher Description

Cyberattacks are likely to remain a significant risk for the foreseeable future. Attacks on organizations can be external and internal. Investing in technology and processes to prevent these cyberattacks is the highest priority for these organizations. Organizations need well-designed procedures and processes to recover from attacks.

The focus of this document is to demonstrate how the IBM® Unified Data Foundation (UDF) infrastructure plays an important role in delivering the persistence storage (PV) to containerized applications, such as IBM Cloud® Pak for Security (CP4S), with IBM Spectrum® Scale Container Native Storage Access (CNSA) that is deployed with IBM Spectrum scale CSI driver and IBM FlashSystem® storage with IBM Block storage driver with CSI driver. Also demonstrated is how this UDF infrastructure can be used as a preferred storage class to create back-end persistent storage for CP4S deployments.

We also highlight how the file I/O events are captured in IBM QRadar® and offenses are generated based on predefined rules. After the offenses are generated, we show how the cases are automatically generated in IBM Cloud Pak® for Security by using the IBM QRadar SOAR Plugin, with a manually automated method to log a case in IBM Cloud Pak for Security.

This document also describes the processes that are required for the configuration and integration of the components in this solution, such as:

Integration of IBM Spectrum Scale with QRadar
QRadar integration with IBM Cloud Pak for Security
Integration of the IBM QRadar SOAR Plugin to generate automated cases in CP4S.

Finally, this document shows the use of IBM Spectrum Scale CNSA and IBM FlashSystem storage that uses IBM block CSI driver to provision persistent volumes for CP4S deployment. All models of IBM FlashSystem family are supported by this document, including:

FlashSystem 9100 and 9200
FlashSystem 7200 and FlashSystem 5000 models
FlashSystem 5200
IBM SAN Volume Controller
All storage that is running IBM Spectrum Virtualize software

GENRE
Computers & Internet
RELEASED
2021
December 20
LANGUAGE
EN
English
LENGTH
48
Pages
PUBLISHER
IBM Redbooks
SELLER
International Business Machines Corp
SIZE
2.7
MB
Securing Data on Threat Detection by Using IBM Spectrum Scale and IBM QRadar: An Enhanced Cyber Resiliency Solution Securing Data on Threat Detection by Using IBM Spectrum Scale and IBM QRadar: An Enhanced Cyber Resiliency Solution
2021
Enhanced Cyber Resilience Threat Detection with IBM FlashSystem Safeguarded Copy and IBM QRadar Enhanced Cyber Resilience Threat Detection with IBM FlashSystem Safeguarded Copy and IBM QRadar
2021
Cyber Resiliency with IBM QRadar and IBM Spectrum Virtualize for Public Cloud on Azure with IBM Copy Services Manager for Safeguarded Copy Cyber Resiliency with IBM QRadar and IBM Spectrum Virtualize for Public Cloud on Azure with IBM Copy Services Manager for Safeguarded Copy
2022
Hybrid Multicloud Business Continuity for OpenShift Workloads with IBM Spectrum Virtualize in AWS Hybrid Multicloud Business Continuity for OpenShift Workloads with IBM Spectrum Virtualize in AWS
2020
Red Hat OpenShift on Public Cloud with IBM Block Storage Red Hat OpenShift on Public Cloud with IBM Block Storage
2020
Proactive Early Threat Detection and Securing SQL Database With IBM QRadar and IBM Spectrum Copy Data Management Using IBM FlashSystem Safeguarded Copy Proactive Early Threat Detection and Securing SQL Database With IBM QRadar and IBM Spectrum Copy Data Management Using IBM FlashSystem Safeguarded Copy
2022
IBM Solutions for Hybrid Cloud Networking Configuration Version 1 Release1 IBM Solutions for Hybrid Cloud Networking Configuration Version 1 Release1
2019
Multicloud Solution for Business Continuity using IBM Spectrum Virtualize for Public Cloud on AWS Version 1 Release 1 Multicloud Solution for Business Continuity using IBM Spectrum Virtualize for Public Cloud on AWS Version 1 Release 1
2020
Red Hat OpenShift on Public Cloud with IBM Block Storage Red Hat OpenShift on Public Cloud with IBM Block Storage
2020
IBM Storage for Red Hat OpenShift Container Platform V3.11 Blueprint Version 1 Release 1 IBM Storage for Red Hat OpenShift Container Platform V3.11 Blueprint Version 1 Release 1
2019
IBM Storage Solutions for Splunk Enterprise IBM Storage Solutions for Splunk Enterprise
2019
Hybrid Multicloud Business Continuity for OpenShift Workloads with IBM Spectrum Virtualize in AWS Hybrid Multicloud Business Continuity for OpenShift Workloads with IBM Spectrum Virtualize in AWS
2020
Using the IBM Block Storage CSI Driver in a Red Hat OpenShift Environment Using the IBM Block Storage CSI Driver in a Red Hat OpenShift Environment
2021
Enhanced Cyber Resilience Solution by Threat Detection using IBM Cloud Object Storage System and IBM QRadar SIEM Enhanced Cyber Resilience Solution by Threat Detection using IBM Cloud Object Storage System and IBM QRadar SIEM
2021
A Hybrid Cloud Cyber Security Solution using IBM Spectrum Virtualize for Public Cloud on Azure and IBM Spectrum Virtualize Safeguarded Copy A Hybrid Cloud Cyber Security Solution using IBM Spectrum Virtualize for Public Cloud on Azure and IBM Spectrum Virtualize Safeguarded Copy
2022
Business Process Management Design Guide: Using IBM Business Process Manager Business Process Management Design Guide: Using IBM Business Process Manager
2015