STIG for QRadar installations

This Security Technical Implementation Guide (STIG) provides the configuration standards and steps that are required for IBM QRadar deployments to achieve the level of security that is required to operate in US Department of Defense (DoD) computer networks.

IBM QRadar is a security appliance that is built on Linux, and is designed to resist attacks. QRadar is not intended as a multi-user, general-purpose server. It is designed and developed specifically to support its intended functions. The operating system and the services are designed for secure operation. QRadar has a built-in firewall, and allows administrative access only through a secure connection that requires encrypted and authenticated access, and provides controlled upgrades and updates.

This STIG implementation follows IBM secure engineering practices.

What systems can you run STIG scripts on?

The following table lists the appliances that are supported by STIG and the version of QRadar required.

Table 1. STIG supported appliance status
Appliance Status
QRadar 31xx Supported as of QRadar 750 UP5
QRadar 15xx Supported as of QRadar 750 UP5
QRadar16xx Supported as of QRadar 750 UP5
QRadar 17xx Supported as of QRadar 750 UP5
QRadar 18xx Supported as of QRadar 750 UP5
QRadar Network Insights (6200) Supported as of QRadar 750 UP7
QRadar App Host Supported as of QRadar 750 UP5
QRadar Data Node (14xx) Supported as of QRadar 750 UP5
QRadar Vulnerability Manager Supported as of QRadar 750 UP5
QRadar Risk Manager Supported as of QRadar 750 UP5
QRadarFlow Collector (1100/1200/1300) Supported as of QRadar 750 UP5
QRadar Incident Forensics (6100) Supported as of QRadar 750 UP7
QRadar500 high-availability (HA) Supported as of QRadar 750 UP7