Blog post
Explore the IBM Security Software Portfolio on AWS
Securing clouds by designArchive date: 2024-06-04
This content is no longer being updated or maintained. The content is provided “as is.” Given the rapid evolution of technology, some content, steps, or illustrations may have changed.This blog post provides an overview of IBM Security software on Amazon Web Services (AWS), and highlights our product portfolio and AWS Service integrations reviewed at AWS re:Invent 2022.
Importance of cloud and hybrid cloud security
Security is the foundation of an enterprise architecture. Establishing this foundation when adopting cloud technologies is critical to organizations across all industries. According to IDC in Trusted Cloud Vendors: Features and Criteria Most Important to Buyers, “Security leads as the most important criteria for selecting a cloud vendor” for buyers. These surveyed buyers indicated their most important security area as threat detection and response, followed by skilled cloud cybersecurity staff and leadership, and backup and disaster recovery.
With the aftermath of the COVID-19 pandemic, cloud adoption is growing at an astronomical rate. Within cloud computing, according to an IDC survey titled COVID-19’s Impact on Enterprise Cloud Spending, “38 percent of companies expect to have spent 5 percent more on cloud in 2021 than was originally budgeted for. Thirty-one percent of these directly blame the pandemic, while almost 20 percent blamed complexity.”
In addition, the 2022 IBM Cloud Threat Landscape Report cites a “28-percent increase in new cloud vulnerabilities over the past year, and an increase in their severity, vulnerability exploitation was the most prominent cause of cloud compromises.”
To accommodate the disruption across all industries and market segments because of the COVID-19 pandemic, organizations need to drive digital transformations within the cloud to innovate on behalf of their customers and remain competitive. As a result, we are seeing considerable innovation in the cloud at a drastic pace, and while evolutions historically have led to new technology mapped to business strategies, such as development security operations (DevSecOps), the reality is that achieving a secure posture is astronomically more complex as you start to deploy across multiple public and private clouds, data centers, and edge-based environments.
“Security must coexist in a multicloud world," according to Forrester Research in the Forrester Analytics Business Technographics Infrastructure Survey, 2020. "Seventy-six percent of global infrastructure decision-makers whose firms are adopting cloud platforms said they would describe their cloud strategy as hybrid,” which is IBM’s strategy.
IBM Security on AWS
IBM Security provides customers with software, software-as-a-service, and consulting services. IBM QRadar Security Incident and Event Management (SIEM) was named a leader in the 2022 Gartner Magic Quadrant for Security Information and Event Management (SIEM) for the 13th consecutive year. IBM Security’s strategy is focused on making clouds secure by design. To achieve this, we secure our clients across hybrid cloud environments -- from public to private to on-premises to co-location to edge-based environments.
As customers continue to innovate with cloud, they are increasing their adoption of public cloud providers, including Amazon Web Services (AWS). IBM Security and AWS have been partnering closely together for years across security services and technology.
Today at AWS re:Invent, we are excited to review the breadth and depth of our IBM Security Software Portfolio on AWS and explore key aspects around how to help you make your clouds secure by design in a hybrid cloud environment.
IBM Security provides a broad and deep portfolio of software products that are deployed on AWS, integrated with AWS, built on AWS, and offered as software-as-a-service (SaaS) on AWS. Software products deployed within an AWS account are available on the AWS Marketplace to procure, or through a bring-your-own-license model (BYOL). BYOL models allow you to purchase directly through IBM, accelerate deployment of IBM Security software products on AWS, and rapidly deploy on AWS infrastructure through the AWS Marketplace. SaaS offerings are fully managed by IBM and provide a robust set of capabilities at enterprise scale, enabling you to achieve security management across their hybrid cloud environments.
Within the IBM Security software portfolio, we offer a myriad of categories and software. To abbreviate the content represented, we will highlight a few of the offerings representative of what we shared at AWS re:Invent 2022:
- Extended detection and response (XDR) -- Helps predict, prevent, and respond to modern threats, and collect incidents
- Data security and compliance -- Helps protect data across AWS and hybrid cloud environments
- Identity and access management (IAM) -- Helps secure remote workers and consumers
Extended detection and response
IBM Security QRadar SIEM
IBM QRadar SIEM enables you to centralize visibility and insights into the most critical threats across AWS and hybrid environments. Obtain insights across environments and gain centralized visibility across AWS and hybrid cloud environments with a single pane of glass. You also can obtain comprehensive insights through deep integrations with the AWS services to ingest a broad spectrum of AWS logs and flows into QRadar SIEM for rapid and accurate threat detection. You can also leverage real-time security analytics to correlated data across users, networks, and AWS native services to gain deep insights into key threats, including cloud misconfigurations, policy changes, and suspicious user activity. Finally, threats can be prioritized by connecting related events to ensure that streams only receive a single alert to mitigate false-positive incidents, such as a suspicious AWS logins and multiple EC2 instances. And you can leverage IBM QRadar SIEM event collectors to drive data ingestion, as represented below.

IBM Security QRadar SIEM can be leveraged to span a comprehensive set of AWS security, networking, and observability solutions, with IBM QRadar SIEM integrated into the AWS Security Hub, as shown below.

IBM Security QRadar SOAR
IBM QRadar Security Operation and Response (SOAR) helps streamline security operations centers with automated and intelligent response in AWS cloud and hybrid environments. You can accelerate incident response by automating manual tasks to enable teams to focus on high-value investigations. This helps reduce response time for remediating a complex cyber-threat by automating incident response processes. It also allows for dynamic response through the creation and use of dynamic playbooks to help teams understand and resolve threats with agility.
With IBM Security QRadar SOAR, you can simplify automation processes to enable teams to focus on high-level investigations by reducing repetitive tasks. Orchestration and automation allows you to understand and keep pace with current malware trends and security threats. Finally, you can streamline and automate manual and repetitive tasks, such as incident enrichment, by leveraging a wide array of threat intelligence integrations.
How it works
Watch this demo to see how QRadar integrates with AWS:
IBM Security ReaQta
IBM Security ReaQta is a fully IBM-managed SaaS solution that enables you to predict, prevent, and respond to modern threats and help prevent ransomware with improved speed and greater visibility. It is undetectable by design with its proprietary Nano operating system (NanoOS) agent running in the hypervisor layer of the endpoint for deep process and application visibility. It enables customized threat-hunting strategies tailor-made to address unique compliance and company-specific requirements without rebooting the endpoint. It can help reduce false-positives for threats identified through its endpoint protection capabilities by more than 80 percent with Cyber assistant, IBM’s one-shot learning system. IBM Security ReaQta leverages Amazon S3 for object storage; ingests log data from Amazon VPCs; creates observability through log, metric, and event capture from Amazon CloudWatch; creates automatic vulnerability scans for AWS workloads for software vulnerabilities and network exposure; and processes, exposes, and responds to threats using with Amazon GuardDuty.
Data security and compliance
IBM Security Guardium Data Protection
IBM Security Guardium Data Protection provides data protection by improving your visibility and compliance, and accelerating response time when data threats and risks are identified. Capabilities include:
- Real-time policy enforcement
- Threat detection and response with external S-TAP
- Centralized activity monitoring for auditing using Amazon Kinesis Data Streams and with Guardium universal connector using Amazon CloudWatch and AWS CloudTrail
- Uncovering data source-level security vulnerabilities, such as default accounts and misconfigurations that may lead to increased exposure
- Monitoring AWS and other data sources using automated password provisioning with the secrets manager
IBM Security Guardium Data Protection supports a wide set of integration based on the use cases above. Just a few of these AWS service integrations include Amazon Aurora MySQL and PostgreSQL, Amazon RDS for Oracle, Amazon DynamoDB, Amazon Redshift, AWS Fargate, Amazon ElastiCache for Redis, and Amazon S3.
There are a variety of capabilities that IBM Security Guardium Data Protection supports, as represented above. See the following digram to learn how to achieve policy enforcement with Guardium external S-TAP with Amazon Aurora.

The following diagram shows a more detailed look at how to support real-time database activity monitoring with Amazon Aurora PostgreSQL.

IBM Security Guardium Insights
IBM Security Guardium Insights enables customers to achieve zero-trust data security across AWS, ISV, and hybrid cloud environments. IBM Security Guardium Insights provides customers with accelerated compliance to reduce time preparing for audits. It enables centralized visibility by monitoring and analyzing activity in context from disparate AWS sources and across the hybrid cloud through the IBM Security Guardium Data Protection collector. It provides flexible deployment at scale and adapts to accommodate cloud sources and other security industry solutions, such as Splunk and ServiceNow. Finally, it allows you to use a risk engine to reduce noise and exclude non-critical assets from your reports. These advanced analytics allow you to understand the broader story, identify data risks and threat patterns, and enable immediate actions while keeping stakeholders informed.
Identity and access management
IBM Security Verify SaaS
IBM Security Verify SaaS provides an authentication and authorization solution that's fully managed by IBM on AWS. IBM Security Verify SaaS provides single sign-on across all applications, including AWS resources, a cloud user directory for managing users and groups; governance, insights, and lifecycle management for users; multi-factor authentication; and adaptive scoring to balance security risk to access and a user’s experience.
The following image outlines how to leverage IBM Security Verify SaaS to achieve single-sign-on for your AWS accounts through AWS organizations wide access.

Next steps
To learn more about our offerings:
- Visit AWS Marketplace.
- Contact your IBM representative to get a product overview, demo, or a deep dive.
- And check out the IBM Developer Amazon Web Services (AWS) hub to learn more about IBM and AWS.
About the IBM AWS partnership
For companies looking to enable and accelerate their customers' hybrid cloud journey by leveraging AWS’ cloud platform, IBM brings leading-edge technologies and expertise on AWS through a unique combination of IBM Consulting, Software, and as-a-service capabilities. From concept to scale, our end-to-end solutions and proven methods help companies modernize their applications and infrastructure with speed and consistency so businesses stay ahead of the curve.
