About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Derek serves Enterprise Architecture Professionals. He is an internationally recognized expert in business process management (BPM) and organizational transformation. He has worked in this area for more than 20 years, dealing with major brands, governmental organizations, and nongovernmental organizations (NGOs). Derek's research focuses on the methods, approaches, frameworks, tools, techniques, and technologies of business architecture; BPM; business process improvement; business transformation; and organizational change. He places special emphasis on an outcome-based, customer-focused approach.
Derek is a well-known keynote speaker and chair of major EA conferences. As co-chair of BPMI.org, he helped merge the organization with the Object Management Group (OMG).
Derek completed the Early Growth Program at London Business School.
The Forrester Information Security Maturity Model is a framework that consists of four main security domains (oversight, technology, process, and people) with 25 functions and 123 low-level...

Organizations continue to face risk for security breaches. Normally, we talk about the risk of security breaches being fines and other costs around loss of PII, per California Senate Bill 1386 and...
Many organizations today get caught up in what I call the “social media binary,” where there are only two options to social media control: 1) Allow unrestricted access to social networks,...

Predictive And Behavioral Analysis Finds Its Way Into Identity And Access Management
Identity and access management (IAM) professionals need to protect information and prevent unauthorized users from accessing business-critical systems in an increasingly complex IT environment. They...

Is it possible to use an intrusion prevention system (IPS) instead of using the full capabilities of a web security gateway (WSG)? What could an IPS provide for the web traffic beyond the WSG?
Enterprises of all sizes are interested in evaluating products for detecting and preventing the transmission and storage of PII, PHI and sensitive corporate secrets. By the end of 2010, Forrester...
The Information Security Metrics 3R Dashboard should be used as a template to present information security metrics organized across three dimensions: Readiness, Response, and Recovery. Forrester...

Even though it is not specific to security, this idea came to me while attending Dell’s Annual Analyst Conference (DAAC) in Austin, Texas two weeks ago. One of the hot topics discussed at...
What changes in emergency notification tactics do you foresee? More specifically, it seems as if SMS messaging and email will replace telephone voice-to-voice communications. Will SMS messaging and...
Determine The Right Practices For Your Organization's BYOD Stipends
In this age of the empowered, tech-savvy worker, more and more employees are bringing their unsecured devices to work and using them for work activities. To prepare for this tide of devices,...

Seven Tenets Of Effectively Combating Fraud Costs
Fraud causes companies to lose money in many ways: They face losses due to chargebacks, unrecoverable transfers, and unnecessary shipping costs; and spend extensive time and resources investigating...
Security professionals increasingly must respond to the needs of business owners exploring web application programming interfaces (APIs) as a new channel for recognizing business value. APIs can...
How Mergers And Acquisitions Will Impact Your eDiscovery Strategies
Organizations struggle to keep up with eDiscovery demands and are burdened by a proliferation of point products. Navigating the eDiscovery marketplace isn't trivial, and many enterprises report...
Companies often demand to know what their peers in a particular vertical market are doing within the realm of information security before making new decisions. “We’re in retail” or...
Executive Overview: The S&R Practice Playbook
Today, business leaders expect the CISO to not only protect the organization from run-of-the-mill hackers but to also protect its brand and competitive advantage in the marketplace — all while...

A Mature Space, IPS Is Still The Bulwark Of Network Security
An intrusion prevention system (IPS) complements traditional firewalls by inspecting the entire network packet looking for malicious traffic that is often invisible to Layer 3 firewalls. While...
We hear a lot about cloud IAM vendors offering metadirectories or user repositories in the cloud. We predict that in 1-2 years we'll see AD being moved from on-premises installations into cloud...
In a recent Forrester/DRJ joint survey on BC preparedness, of organizations that have invoked a BC plan in the last five years, 37% said that their BC plans had not adequately addressed...
How do retailer websites handle login expiration? Is it session-based, login-persisted, 30-day cookie, and so on? What is the norm or best practice?
Manage Mobile Complexity Through A Corporate App Store
Today, many employees use their personally owned smartphones and tablets for work to access a variety of mobile applications. Some companies are also proactively deploying mobile applications to...

Greetings everyone. My name is Andrew Jaquith, and I serve security and risk professionals. Normally I blog over on the S&R analyst team blog. But because Forrester has been receiving so many...