With special thanks to Juan Carlos Jimenez Fuentes and Thorsten Bandtel
How do I track the recovery posture of the Applications that make up the minimum viable company at scale?
Well, folks that have seen me recently know that I have an addiction to F1 racing. There, I’ve said it. Admitting it is a first step. That being said, the idea of ‘upgrades’ really intrigues me when I’m planning out a Cyber Resiliency solution. So just like a race team might bring ‘upgrades’ to the car throughout the season, I look at phases of a project that I can bring upgrades to for my Cyber Resiliency posture.
How do I expand what I can do with the IBM FlashSystem? Well, we’ve already looked at Safeguarded Copy, IBM Storage Sentinel to validate those copies, and how to improve the overall resiliency posture of the FlashSystem.
So, what’s the next upgrade I can bring to the season? IBM Storage Defender Data Resiliency Service (DRS). Some of you may know why I’m on a race theme now, feel free to add a comment below.
IBM Storage Defender Data Resiliency Service (DRS) provides application dependency mapping to create a clear view of how applications, workloads, and underlying infrastructure are interconnected. Starting with auto discovery of relationships between virtual machines DRS enables users to understand application context instead of isolated components. This insight is critical for cyber‑resiliency, as it helps identify blast radius during an incident, prioritize recovery sequences based on dependencies, and ensure that entire application stacks, not just individual assets, can be restored in a consistent, operational state.
What can I do with IBM FlashSystem when I get it working with Data Resiliency Service? That’s how I can map my minimum viable company for all my applications, govern their recovery requirements and track and produce my recovery plan for their validated recovery points (Safeguarded Copies) in one place. This is all about how I bring things into the focus of the core applications.
To set the stage, FlashSystem, Storage Insights and DRS can all integrated, which means I can see the context of the volumes and the Ransomware detection that’s built in. It also means I can integrate those alerts into DRS and help correlate those alerts. What does the integration look like?
DRS view
IBM Storage Insights view
Now, let’s take this step by step - Applications:
Here Thorsten has mapped the core applications for his company called Bandy.Air This means that he’s able to create the applications and map their dependencies from a recovery order perspective. That means I know what applications need to be recovered first, second, third etc and I can look at what makes up each application. Let’s look at Bandy.Air-CustomerIdentity Application:
This application is made up of 4 recovery groups of virtual machines, (Recovery Groups are a way I can group VMs that relate to that application – they can by manually or automatically generated). I can look at this application as a whole, see if there are threats currently. What’s a good example, I’m able to see the ransomware detection alerts from the IBM FlashSystem and Storage Insights here as well, and its able to tell me what specific VMs are affected by that alert. Correlation!!!!! That’s helps organizations react faster!
I can even go a step deeper on alerting for those virtual machines by deploying IBM Defender Sensors which also detects ransomware but at a different level. Curious? Have a read of what IBM X-Force found when they tested the Defender Sensors.
The other part that I really like; I can specify my preferred recovery points for each of my Recovery Groups and then it will produce the documentation dynamically for me.
As you can see, we’ve specified the Safeguarded Copies are the preferred recovery points for a couple of these recovery groups, that means I’m cataloging and tracking all of the supporting Safeguarded Copies from the FlashSystem for all my recovery groups. That’s right, Cyber Resiliency at scale!
Now, where it gets really interesting, IBM Data Resiliency Service integrates with IBM Storage Sentinel, so I’m able to track my automated scanning schedule results for all my defined workloads and how those then map directly into the applications that support my minimum viable company and look across threat aggregation.
Notice other thing along the way? Policies and Governance! The recovery groups are all mapped against the governance profiles I’ve defined for the enterprise and they are tracked for compliance. This means I’m going to be to know at a glance, if my application meet my governance requirements or I need to assign out tasks to adjust my protection policies to bring them into compliance.
Oh, and by the way, I can also see the recovery posture for my backups from the same place, but I’ll let you read more about that from the IBM Storage Defender blog series, or the updated redpaper.
What does all this mean?
- I can plan the recovery of my applications that make up my minimum viable company from either my IBM FlashSystem recovery points, or by backups or both
- I can orchestrate further testing or recovery of those workloads from 1 place.
- I can apply governance and alerting to ensure those applications are meeting the business requirements I’ve set out
- I can track and correlate threats to my applications from my IBM FlashSystem include the FlashCore Module alerts, alerts from IBM Defender Sentinel and from IBM Defender Sensors as well as a few other sources.
By the way, there’s some new upgrades for IBM Defender Data Resiliency Service;
There is also an IBM Defender Sentinel and FlashSystem webinar that you can check out as well. Interested more in what Storage Sentinel can do, have a look at Resiliency 360.