IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
  • 1.  QRadar Multi-tenancy

    Posted 11/04/19 08:51 PM
    Is multi tenancy capability for QRadar or QRoC likely to be developed in the near future? 

    Given that many other vendors have already developed techniques along these lines:
    Federation - A Modern Approach To Multi-Tenancy
    Alienvault remove preview
    Federation - A Modern Approach To Multi-Tenancy
    In the world of Managed Security Services, Multi-Tenancy is often the default approach to managing the security of multiple subscribers. However, like most things in IT, the default approach is rarely the right choice. Multi-Tenancy has a number of technology disadvantages as well as creating an unpredictable business model for most MSSPs.
    View this on Alienvault >

    LogRhythm apparently has their own version as well apparently too.

    Or is there better alternatives?  Perhaps multi-tenanted microservices segmented within IBM Cloud within a controlled space?

    ------------------------------
    John Martin
    Senior Security Architect
    30 Gaunt Street
    Auckland
    006421744012
    ------------------------------


  • 2.  RE: QRadar Multi-tenancy

    Posted 11/05/19 08:45 AM
    Hi

    See attached link for MT in QRadar

    https://www.ibm.com/support/knowledgecenter/SS42VS_7.3.0/com.ibm.qradar.doc/c_qradar_adm_tenant_mgmt_overview.html

    Regards

    ------------------------------
    SHANE LUNDY
    ------------------------------



  • 3.  RE: QRadar Multi-tenancy

    Posted 11/05/19 02:21 PM
    Hi Shane and group, I have be in touch with the IBM MSS Global Architect and related team on the same subject; the general consensus is there are limitations, and there are associated risks even with very good management of other clients seeing others events etc.  QRadar by default is not designed for multi-tenancy purposes.  Without very careful setup and management, it will be difficult to provide full separation and segregation for an MSSP.  The risks would certainly be reduced, if it was a worldwide distributed organisation, where the organisation owned the domains themselves.  Unfortunately other architectures based around other vendors like AlienVault or LogRhythm lend themselves towards a multi-tenancy architecture.  There appears to be no alternative at the present time, for small to medium business, who just want the basics or have to migrate from ILM, ISM and MSIEM, but don't want to pay for the minimum overheads that come with XFTM or the lowest level XFTD - which they find too costly to consume.    Perhaps, a federated identity architecture would reduce the risks, and overheads, some vendors are offering this feature.  Alternatively a centralised Hybrid Cloud and Micro-Services architecture, with it being centrally managed by the MSSP would have potential at scale.

    I have also looked at a Multi-tenancy with QRoC, but once again ideally each client would have their own Data Gateway to maintain segregation and once again management and design factors come into the equation. 

    Other ideas within the community?

    ------------------------------
    John Martin
    Senior Security Architect
    30 Gaunt Street
    Auckland
    006421744012
    ------------------------------