Hi Shane and group, I have be in touch with the IBM MSS Global Architect and related team on the same subject; the general consensus is there are limitations, and there are associated risks even with very good management of other clients seeing others events etc. QRadar by default is not designed for multi-tenancy purposes. Without very careful setup and management, it will be difficult to provide full separation and segregation for an MSSP. The risks would certainly be reduced, if it was a worldwide distributed organisation, where the organisation owned the domains themselves. Unfortunately other architectures based around other vendors like AlienVault or LogRhythm lend themselves towards a multi-tenancy architecture. There appears to be no alternative at the present time, for small to medium business, who just want the basics or have to migrate from ILM, ISM and MSIEM, but don't want to pay for the minimum overheads that come with XFTM or the lowest level XFTD - which they find too costly to consume. Perhaps, a federated identity architecture would reduce the risks, and overheads, some vendors are offering this feature. Alternatively a centralised Hybrid Cloud and Micro-Services architecture, with it being centrally managed by the MSSP would have potential at scale.
I have also looked at a Multi-tenancy with QRoC, but once again ideally each client would have their own Data Gateway to maintain segregation and once again management and design factors come into the equation.
Other ideas within the community?
------------------------------
John Martin
Senior Security Architect
30 Gaunt Street
Auckland
006421744012
------------------------------
Original Message:
Sent: Tue November 05, 2019 08:44 AM
From: SHANE LUNDY
Subject: QRadar Multi-tenancy
Hi
See attached link for MT in QRadar
https://www.ibm.com/support/knowledgecenter/SS42VS_7.3.0/com.ibm.qradar.doc/c_qradar_adm_tenant_mgmt_overview.html
Regards
------------------------------
SHANE LUNDY
------------------------------