What is our primary use case?
I was first introduced to BMC AMI Security in 2020, and I had a chance to be a part of a trial run since it is primarily related to mainframes.
My main use case for BMC AMI Security is mainframe security, which is what I had access to it for with IBM related mainframes during that trial run.
I do have more to add about how I used BMC AMI Security and my main use case.
What is most valuable?
For threat detection and behavior analytics with BMC AMI Security, you would use it with the enterprise security manager to check logs and the analytics. You would be able to quickly get a view with the use of AI, and it also could be used for AI powered attacks or preparing you to resist them as that is a thing now. This aligns it with BMC data streams.
The best features BMC AMI Security offers include the detection of anomalies and anything strange that may show up, particularly with the z/OS or applications. You could look at the z/OS and the behavior of the system. Additionally, insider threat identification and credentials are valuable features, and I would say accelerated onboarding and triage are as well. Other important features include real-time events, unified SOC visibility, and compliance and audit readiness, which is one of the biggest things, particularly with mainframes.
BMC AMI Security has positively impacted my organization and my clients by allowing for accelerated onboarding and bridging a mainframe skills gap. You have to have a specialized set of skills to be able to work with mainframes, so if you are a system admin, it helps a bit. Having the generative AI and natural language assistance allows you to cross train staff. Unified enterprise visibility catches threats pretty early on as well.
Specific outcomes or metrics I have seen with BMC AMI Security include faster onboarding times and improved compliance audit results. With the security operations and threat metrics, you have mean time to detect, which means things are quickly flagged if you have any misuse or anomalous behavior. It tracks speed from initial alert to containment, and you can automate runbook integration and AI assisted triage, which is great for false positive reduction. One of the most important things is the audit and compliance prep that measures dropped in hours and weeks, so you do not have to spend as much time gathering evidence, checking configurations, and generating all sorts of reports for frameworks including DORA, PCI, or GDPR.
What needs improvement?
Regarding how BMC AMI Security can be improved, I think it is a good question. BMC recently had a model context protocol, which would allow AI assistance to interface with live production workflows. That is a great addition. You also have automated digital certificate management that has come in. They have been keeping an eye on the product since it only came out about six years ago, so when I worked with it, those features were not there. They have improved by keeping abreast of things, and there is an expanded knowledge hub for its capabilities including expert chat features and advanced context-aware analytics, which transitions from basic threshold alerts to behavioral AI models that parse historical patterns.
I believe I have covered everything regarding the needed improvements that I know they have done. Those features were not available when BMC AMI Security was released around 2020 or 2021. Knowing about those particular features with mainframes, and given that I worked with mainframes in the past 15 years of my career, those are huge pluses. I think they will continue making developments as the cyber threat world is constantly evolving.
For how long have I used the solution?
I was first introduced to BMC AMI Security in 2020, and I had a chance to be a part of a trial run since it is primarily related to mainframes.
What do I think about the stability of the solution?
BMC AMI Security is stable. You have to make sure something of this nature is stable when working with mainframes. It is very reliable and predictable, and the risk reduction measures are built into the mainframe tools, allowing for staged and streamlined deployments that minimize production risk. The human in the loop governance is huge, which adds to stability. Rather than giving complete autonomy to AI agents unmonitored, you have explicit human approval gates before operation or security postures are changed, which definitely increases the reliability and stability of this particular tool.
What do I think about the scalability of the solution?
BMC AMI Security's scalability is quite remarkable, as it has high volume event processing and data scaling, meaning that it handles massive throughput and elastic streaming with platforms including Splunk and QRadar. You also have the multi LPAR, since this is an IBM mainframe, allowing multi-LPAR and parallel sysplex growth, which means it can span multiple LPARs and interconnect with parallel sysplex clusters. This means BMC AMI Security scales horizontally across these environments.
How are customer service and support?
Customer support for BMC AMI Security is pretty good. I did not have any problems with it. You have your online portals and self-service with BMC and the BMC communities that help, and of course the direct telephone support.
Which solution did I use previously and why did I switch?
I did not previously use a different solution before BMC AMI Security.
How was the initial setup?
The way it is done with BMC AMI Security involves host z/OS deployment and resident servers, so the software is delivered through a standard distribution method by binary or uploaded via FTP.
What was our ROI?
I would say that would be something the business could tell, but as far as security-specific operational returns with BMC AMI Security, we see faster forensic investigations, streamline audit readiness, risk mitigation, and downtime prevention. It has cut outages in half.
What's my experience with pricing, setup cost, and licensing?
I was not directly involved with the pricing, setup cost, and licensing of BMC AMI Security, but I can tell you some of the key factors in pricing include mainframe capacity, deployment footprint, subsystems, and the integration of layers.
Which other solutions did I evaluate?
Before choosing BMC AMI Security, I looked at other options, including IBM Security zSecure and Broadcom.
What other advice do I have?
My advice to others looking into using BMC AMI Security is to integrate and not bypass. Always route security rules and hooks through the z/OS system. I would say prioritize offloading for heavy analytics and definitely tune the AI baselines gradually to prevent alert fatigue.
I only have one additional thought about BMC AMI Security before we wrap up: I would say to all who use it or if you are bringing it in to make sure you enforce human in the loop governance for AI, as you do not want AI doing what it wants without checking in first. I would rate this product an eight out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
IBM