IBM收购Q1 Labs可以看作是其在SIEM领域,甚至是在广义的集中安全管理领域的有一次大的动作,是对HP的回应,也是对安全发展大势的一次确认。比较引人注目的是这次IBM没有将Q1整合到无所不包的Tivoli里面去,正如以前他对其他收购来的SIEM类产品那样,而是为Q1打造了一个新的部门:安全系统部(Security Systems Division)。

那么,这个安全系统部将如何运作?将包括哪些产品?仅仅就是Q1的产品吗?IBM肯定知道,SIEM与DAM产品、IAM产品具有天然的融合性。而IBM已经拿下Guardium,自己早就整合出了IAM产品,是不是这些产品部门也将与这个安全系统部进行某种整合?值得注意的是,有媒体报道IBM正在将IAM从Tivoli产品线中拿出来。

更加,NetworkWorld更加畅想/提议,鉴于SIEM正在朝安全智能方面发展,IBM应该将其BI技术应用于SIEM领域,也许cognos/sass等等可以在安全领域有所作为。包括处理大数据的InfoSphere新品。不过我想,如果正是要集成起来,那将是多么重的方案啊?以至于太沉重了?呵呵。

正如双方在并购申明中写道的那样:

New IBM Security Division Delivers the World's Most Comprehensive Security Offerings, Expertise

IBM's new Security Systems division integrates IBM's Tivoli, Rational and Information Management security software, appliances, lab offerings and services. IBM plans to apply Q1 Labs' analytics to drive greater security intelligence capabilities across its security products and services such as identity and access management, database security, application security, enterprise risk management, intrusion prevention, endpoint management and network security. In fact, IBM Managed Security Services today is making available to clients a cloud-based service of Q1 Labs' security information and event management offering.

Q1 Labs technology will also create a common security platform for IBM's software, hardware, services and research offerings. Clients will benefit from more tightly integrated products, a unified roadmap and accelerated time-to-value on investments to build more intelligent security systems.

 

系统安全部的负责战略与产品管理的副总Marc van Zadelhoff说到:"Q1 will be the central dashboard for IBM products。"

蓝图不错。让我们边走边看吧。

【参考】

IBM收购Q1 Labs