Book description
This IBM® blueprint publication focuses on early threat detection within a database environment by using IBM QRadar®. It also highlights how to proactively start a cyber resilience workflow in response to a cyberattack or potential malicious user actions.
The workflow that is presented here uses IBM Spectrum® Copy Data Management as orchestration software to start IBM FlashSystem® Safeguarded Copy functions. The Safeguarded Copy creates an immutable copy of the data in an air-gapped form on the same IBM FlashSystem for isolation and eventual quick recovery.
This document describes how to enable and forward SQL database user activities to IBM QRadar.
This document also describes how to create various rules to determine a threat, and configure and start a suitable response to the detected threat in IBM QRadar.
Finally, this document outlines the steps that are involved to create a Scheduled Job by using IBM Spectrum® Copy Data Management with various actions.
Table of contents
Product information
- Title: Proactive Early Threat Detection and Securing SQL Database With IBM QRadar and IBM Spectrum Copy Data Management Using IBM FlashSystem Safeguarded Copy
- Author(s):
- Release date: October 2022
- Publisher(s): IBM Redbooks
- ISBN: 9780738460857
You might also like
book
Proactive Early Threat Detection and Securing Oracle Database with IBM QRadar, IBM Security Guardium Database Protection, and IBM Copy Services Manager by using IBM FlashSystem Safeguarded Copy
This IBM® blueprint publication focuses on early threat detection within a database environment by using IBM …
book
IBM Cloud Object Storage System Product Guide (For on-premises IBM Cloud Object Storage installations)
Object storage is the primary storage solution that is used in the cloud and on-premises solutions …
book
IBM Z Functional Matrix
This IBM® Redpaper™ publication provides a list of features and functions that are supported on IBM …
book
IBM Elastic Storage System Introduction Guide
This IBM® Redpaper Redbookspublication provides an overview of the IBM Elastic Storage® Server (IBM ESS) and …