About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Connie is a member of Forrester's Business Technology Futures team, which serves CIOs and their business partners by predicting the long-term business impact of information technology. Her research focus is on smart computing and analytics.
Connie came to Forrester through its acquisition of Giga Information Group in 2003. She has more than 25 years of experience in the IT industry and has been an analyst for 19 years. Most of her research focuses on business process management and business optimization. Prior to joining Giga, Connie managed BIS Strategic Decisions' European IT consulting group, headquartered in the UK. Before then, Connie was vice president of product marketing at TDC (now part of BancTec), a manufacturer of high-end document capture systems. She was also a manager with Andersen Consulting (now Accenture), specializing in document management, document imaging, and end user computing. Earlier, Connie was with Wang Laboratories, where she managed Wang's technical support resources for the US Department of Defense and intelligence agencies. She began her career in IT and management at Mathematica Policy Research.
Connie was the co-champion of Forrester's 2009 Business Technology Forum, with its theme of "Lean: The New Business Technology Imperative." Connie also co-championed Forrester's 2007 Technology Leadership Forum, with the theme of "Design for People, Build for Change," and Forrester's 2008 Technology Leadership Forum, themed as "Embrace Technology Chaos, Deliver Business Results." Connie is a widely sought speaker. She has keynoted at many industry events, chaired 10 business process and workflow conferences in Europe and the US, and co-chaired Giga's "Leveraging Knowledge" conference. Connie also served as a director of AIIM International, the premier association for the content management industry, and is a member of the Association of Business Process Management Professionals.
Connie attended the University of North Carolina at Chapel Hill and holds a B.A. in political science and history from East Carolina University and an M.B.A. in information systems from George Washington University.
How do retailer websites handle login expiration? Is it session-based, login-persisted, 30-day cookie, and so on? What is the norm or best practice?
How To Protect Your Email Data
In facing security woes such as the Epsilon breach, email marketing professionals have received a wake-up call: Security failures can cost a lot — not just a lot of money but also goodwill with...
We're looking for secure access solutions for a web interface that will enable some sort of strong authentication but doesn't use a two-factor password token. We're thinking of solutions that allow a...

Many IT security pros are moving toward disruptive new authentication and authorization practices to integrate securely with cloud apps at scale. If you’re considering such a move yourself,...
Our employees are being asked to electronically sign documents from outside our organization. We want to educate these employees on various aspects of the e-signature process. One area is...
Two years ago, the OAuth API protection mechanism was a fairly well-kept secret. It actually won an award at the 2009 European Identity Conference for "best new/improved standard," but most people...
Future Look: The Identity And Access Management Playbook
This report outlines the future look of Forrester's solution for security and risk (S&R) executives working on building an identity and access management strategy for the extended enterprise. We...

A couple of months back, I advocated killing your password policies and applying some other techniques instead to make existing use of passwords more effective (including my hobby horse: take...
Cloud providers and many federated IAM practitioners are excited about OAuth, a new(ish) security technology on the scene. I’ve written about OAuth in Protecting Enterprise APIs With A Light...
Road Map: The Identity And Access Management Playbook
This report outlines Forrester's solution to help security and risk (S&R) leaders develop their road map of IAM processes using Forrester's TechRadar™ methodology. The extended enterprise...

With The SCIM Specifications, User Provisioning Goes "Zero Trust"
Business owners are jumping on SaaS services to get quicker wins, and CIOs are finding these services attractive for cutting costs as well. Since it's relatively quick and easy to hook up these...
Back in July, I wrote about a new RESTful API that cloud providers and provisioning vendors are working on for doing identity provisioning and synching: Simple Cloud Identity Management, or SCIM...
Doing access management with the help of cloud-based services is a pretty comfortable proposition by now. For more than a decade, we've been doing federated single sign-on to and from apps...
It has finally become hip not just to predict the demise of passwords, but to call for their elimination. The recent Wired article makes an eloquent case about the vulnerabilities that even...
Stakeholder Needs: The Identity And Access Management Playbook
This report outlines the stakeholder needs of the Identity And Access Management playbook. Forrester has identified lack of IT executive buy-in and attention as a chronic issue in projects related to...
Portable Identity Gives New Options To Companies, Consumers, And Clouds
Fast-moving cloud and consumer identity trends are driving shifts in how IT professionals control user access and provide personalized service to networked applications. As IT professionals move to...
Microsoft announced during last week's RSA conference that it would not be shipping Windows CardSpace 2.0. A lot of design imperatives weighed on that one deliverable: security, privacy,...
If you're in the habit of checking out only the Security & Risk Professionals blog, you might have missed Jonathan's takeaways over on the Vendor Strategy side: What The New White House...
We would like to discuss single sign-on and OAuth (like Facebook Connect) for an eCommerce site that has a public user base of roughly 10 million. What are the pros and cons of out-of-box solutions...
To help security and risk professionals navigate the complex landscape of privacy laws around the world, Forrester created a data privacy heat map that highlights the data protection guidelines and...

Layer 7 And WSO2 Lead This Emerging Field
In Forrester's 15-criteria evaluation of application programming interface (API) management platform vendors, Layer 7 and WSO2 — and their solutions — rose to the top, followed by Intel,...

Security professionals increasingly must respond to the needs of business owners exploring web application programming interfaces (APIs) as a new channel for recognizing business value. APIs can...
Executive Overview: The Identity And Access Management Playbook
The rapid adoption of mobile devices and cloud services, together with a multitude of new partnerships and customer-facing applications, has "extended" the identity boundary of today's enterprise....