Global Security Forum

Security Global Forum

Our mission is to provide clients with an online user community of industry peers and IBM experts, to exchange tips and tricks, best practices, and product knowledge. We hope the information you find here helps you maximize the value of your IBM Security solutions.

 View Only
  • 1.  IBM Security Verify (SaaS) - FedRAMP Moderate Certified

    Posted Tue April 18, 2023 09:04 AM

    We are planning to replace IBM Security on prem solution(ISIM/ISAM) with IBM security Verify(SaaS). Since all our projects are US govt projects. Do we have any way that we can have fedramp Moderate certified Platform provided by IBM?



    ------------------------------
    Dhanasekaran S
    ------------------------------


  • 2.  RE: IBM Security Verify (SaaS) - FedRAMP Moderate Certified

    Posted Wed April 19, 2023 01:40 AM

    We do have Fedramp certified datacenter for Verify SaaS in US region. Please reachout to offering management or Milan Patel for details.



    ------------------------------
    Nilesh Atal
    ------------------------------



  • 3.  RE: IBM Security Verify (SaaS) - FedRAMP Moderate Certified

    Posted Wed April 19, 2023 09:49 AM

    @Nilesh Atal  I'm curious about this.  When I search the FedRamp marketplace, I only see the IBM Cloud for Government authorized as high, and the IBM Federal HR Cloud in process for moderate.  The HR cloud is listed as SaaS, whereas the cloud as IaaS/PaaS.

    Is the Verify SaaS riding on one of these previous authorizations?  If I search the FedRamp marketplace for "identity", there are other vendors that are listed as SaaS that are authorized with their product name.

    @Dhanasekaran S I am curious, as you move these projects from on-prem to SaaS, are you still utilizing the web reverse proxy feature in front of the web applications?  Or have these customer's architecture's changed where the applications are going to be utilizing SAML/OIDC token authentication?  Or are you using IAG?

    Thanks for the input!



    ------------------------------
    Matt Jenkins
    ------------------------------



  • 4.  RE: IBM Security Verify (SaaS) - FedRAMP Moderate Certified

    Posted Mon April 24, 2023 08:21 AM

    @Matt Jenkins 

    We are planning to have the application support SAML/OIDC protocols, whereas in the meantime looking forward to have a hybrid approach by keeping RP/IAG in place for supporting header bases SSO.



    ------------------------------
    Dhanasekaran S
    ------------------------------