STIG for QRadar installations
This Security Technical Implementation Guide (STIG) provides the configuration standards
and steps that are required for IBM
QRadar deployments to achieve
the level of security that is required to operate in US Department of Defense (DoD) computer
networks.
IBM QRadar is a security appliance that is built on Linux, and is designed to resist attacks. QRadar is not intended as a multi-user, general-purpose server. It is designed and developed specifically to support its intended functions. The operating system and the services are designed for secure operation. QRadar has a built-in firewall, and allows administrative access only through a secure connection that requires encrypted and authenticated access, and provides controlled upgrades and updates.
This STIG implementation follows IBM secure engineering practices.
What systems can you run STIG scripts on?
The following table lists the appliances that are supported by STIG and the version of QRadar required.
| Appliance | Status |
|---|---|
| QRadar 31xx | Supported as of QRadar 750 UP5 |
| QRadar 15xx | Supported as of QRadar 750 UP5 |
| QRadar16xx | Supported as of QRadar 750 UP5 |
| QRadar 17xx | Supported as of QRadar 750 UP5 |
| QRadar 18xx | Supported as of QRadar 750 UP5 |
| QRadar Network Insights (6200) | Supported as of QRadar 750 UP7 |
| QRadar App Host | Supported as of QRadar 750 UP5 |
| QRadar Data Node (14xx) | Supported as of QRadar 750 UP5 |
| QRadar Vulnerability Manager | Supported as of QRadar 750 UP5 |
| QRadar Risk Manager | Supported as of QRadar 750 UP5 |
| QRadarFlow Collector (1100/1200/1300) | Supported as of QRadar 750 UP5 |
| QRadar Incident Forensics (6100) | Supported as of QRadar 750 UP7 |
| QRadar500 high-availability (HA) | Supported as of QRadar 750 UP7 |