IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
  • 1.  How to choose a stable patch

    Posted 01/29/20 06:57 AM
    Hi

    I am facing issues with applying QRadar patches.
    Because it takes time for customer approval, it cannot always be kept up to date.
    Last year, we updated to 7.3.2 Patch4, but there were bugs in the system notification and reporting functions.

    I want to select a stable patch and apply it to keep it to the minimum update. Is there a way to check it?

    I am referring
    https://www.ibm.com/support/pages/qradar-master-software-version-list-release-note-list-updated

    Thank you

    ------------------------------
    -------------------------
    Masao
    -------------------------
    ------------------------------


  • 2.  RE: How to choose a stable patch

    Posted 01/29/20 08:40 PM
    I'm sorry, it was a continuous throw.
    Does anyone know how to delete a thread?

    ------------------------------
    -------------------------
    Masao
    -------------------------
    ------------------------------



  • 3.  RE: How to choose a stable patch

    Posted 01/30/20 05:45 AM
    Hi Masao,

    This is a good thing to ask so don't feel like you need to delete the thread.

    The honest answer is that "it depends​". It depends on your setup, appetite to risk, ability to validate and criticality of what is in the patch.

    Approaches by organisation will vary based on the above. What my organisation does is review each patch contents and decide if the cost of implementing the patch (cost including risk of failure and the cost of CVEs resolved) is worth it. If it is, we test it first.

    If it helps, any method you currently have for selecting and applying any other software patches will be suitable.

    What I strongly advise is not apply any patch to "production" without having performed a dry-run on a "development" environment. Experience with QRadar in the past few years (being honest), is that you get some good fixes but some more broken things.

    I hope this helps.

    ------------------------------
    Darren H.
    ------------------------------



  • 4.  RE: How to choose a stable patch

    Posted 01/30/20 05:55 AM
    ... One last thing.

    A simple rule of thumb my organisation uses is as follows ... do not promote (or use) any patch for a month after it has been released in "production".​ Wait a month. Any important issues usually get sorted in that one month period.

    By all means test in "development" or "staging".

    ------------------------------
    Darren H.
    ------------------------------



  • 5.  RE: How to choose a stable patch

    Posted 01/31/20 02:42 AM
    Hi, Darren H.

    Thank you for very useful information.

    My organization hadn't patched it since build until last year's support for 7.2.8. I had no experience with continuous maintenance and was in trouble.

    > The honest answer is that "it depends". It depends on your setup, appetite to risk, ability to validate and criticality of what is in the patch.

    > Approaches by organisation will vary based on the above.What my organization does is review each patch contents and decide if the cost of implementing the patch (cost including risk of failure and the cost of CVEs resolved) is worth it.If it is, we test it first.

    Apparently, we need to change our validation items
    I will consider it based on the opinion I got


    > A simple rule of thumb my organization uses is as follows ... do not promote (or use) any patch for a month after it has been released in "production" .Wait a month.Any important issues usually get sorted in that one month period.

    This is surprising. Almost matches the contents of the release list.

    Thank you!

    ------------------------------
    Masao
    ------------------------------