Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

IBM anoints Q1 Labs technology as centerpiece of security portfolio

IBM intends to make the security information and event management (SIEM) technology gained through the acquisition of Q1 Labs, which was officially closed yesterday, the centerpiece of IBM's broad security product portfolio.

The Q1 Labs SIEM called QRadar -- the brand name could change as IBM brings Q1 into the IBM fold -- will play a central role in the IBM Security Systems portfolio, said Marc van Zadelhoff, vice president of strategy and product management at the division. "Q1 will be the central dashboard for IBM products," he said. Yesterday, IBM named Brendan Hannigan, Q1 Labs CEO, as general manager of IBM's newly formed Security Systems Division.

MORE ON IBM: IBM turns up Watson-like natural language healthcare analytics

The IBM security products to work with the Q1 SIEM include Guardium database monitoring, BigFix for software patching, AppScan vulnerability-assessment tools, the IBM Rational products and the IBM Identity Manager and Access Manager products. (IBM is dropping the "Tivoli" name from the Identity and Access Management suite, although the longtime Tivoli brand name is expected to continue with Tivoli NetView network management.)

The intent is to have the Q1 Labs SIEM become the central place to correlate real-time security-event information related to IBM products and present a situational analysis for enterprise users. IBM envisions this could work in cloud-based environments as well.

The Q1 SIEM, like other products of its type, already can collect information from a wide variety of network security sources, such as firewall or intrusion-prevention systems. But IBM wants to take this capability further and is proceeding with integrating the IBM identity management products into the Q1 SIEM, which is expected to be completed within the next few months.

The advantage is doing this identity management integration work is that it would allow the SIEM to track real-time user network activity in a more detailed way to understand the security consequences, says van Zadelhoff. This integration work with Q1 at the center follows through on ideas shared by IBM executives earlier this year at the IBM Innovate Conference.

IBM is also intent on integrating business analytics into the SIEM by drawing from the IBM portfolio that includes Cognos business intelligence, the IBM InfoSphere Stream data analysis tool and IBM SPSS, the predictive analysis software that can be used for fraud control. "These are toolkits we can extend to this," said van Zadelhoff.

He noted that IBM already is involved in capturing 12 billion events a day related to security and log management for 4 million customers around the world. The Q1 acquisition, now complete, lays the foundation for how that can be done going forward.

Read more about wide area network in Network World's Wide Area Network section.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: BigFix, Cognos, Cognos, IBM, IBM Australia, LAN, Security Systems, SPSS, Tivoli
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Access control and authentication, BigFix, Guardium, IBM, Q1 Labs, security, SIEM
Latest Blog Posts
Whitepapers
  • Removing BPM Silos to Unleash Process Power - 15 Best Practices for Enterprise BPM
    You are about to get a lot smarter about Enterprise Business Process Management (BPM ). T his article is the first in a series of our soon-to-be-published book, “The Intelligent Guide to Enterprise BPM .” So consider this first article your all-important primer.
    Learn more »
  • Teleworking made simple—and secure—with desktop virtualisation technology
    Businesses of all sizes are increasingly focused on creating flexible work environments and offering telework options for employees. By administering policies and providing the technical capability for employees to work remotely, these companies can improve job satisfaction and worker attraction and retention. This paper explores the implementation of teleworking based on a foundation of desktop and server virtualisation.
    Learn more »
  • Managing IBM License Complexity
    IBM provides thousands of products in its portfolio and uses a variety of license models, contract terms and conditions. These license models can be very complex, causing frequent confusion for organisations trying to grasp the concepts while maintaining license compliance. While at first IBM licensing may seem incomprehensible, some education on the license models and licensing scenarios will help minimise the confusion. In addition, a more automated approach to managing licenses enables organisations to gain control, reduce ongoing software costs and minimise license liability risks. Read on.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments