About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Derek serves Enterprise Architecture Professionals. He is an internationally recognized expert in business process management (BPM) and organizational transformation. He has worked in this area for more than 20 years, dealing with major brands, governmental organizations, and nongovernmental organizations (NGOs). Derek's research focuses on the methods, approaches, frameworks, tools, techniques, and technologies of business architecture; BPM; business process improvement; business transformation; and organizational change. He places special emphasis on an outcome-based, customer-focused approach.
Derek is a well-known keynote speaker and chair of major EA conferences. As co-chair of BPMI.org, he helped merge the organization with the Object Management Group (OMG).
Derek completed the Early Growth Program at London Business School.
Strategic Plan: The Governance, Risk, And Compliance Playbook
Governance, risk management, and compliance (GRC) are far too often positions of emergency response. What's worse, as you constantly rush to respond to new mandates, enforce policies, or pull...

Estimating Levels Of Risk Exposure To Help Guide Informed Decisions
Opposition to adopting formal risk management tends to use the process of risk measurement as its attack target — it's too subjective, it's too complicated, or it's too much investment just to...
Business Case: The Governance, Risk, And Compliance Playbook
As the governance, risk, and compliance (GRC) platform market matures, product vendors struggle to point to credible return on investment figures, and potential buyers similarly struggle when asked...

As Leaders, BWise, MetricStream, IBM OpenPages, And RSA Archer Continue To Push The Envelope
What is the size of the governance, risk, and compliance (GRC) market, and what is the market growth rate in India? Who are the major GRC vendors in India, and what are the areas of opportunity?
Road Map: The Governance, Risk, And Compliance Playbook
The governance, risk management, and compliance (GRC) technology market is one of fluctuation, confusion, and contention. Many technologies relevant for governance, risk management, and compliance...

Assessment Framework: The S&R Practice Playbook
This report outlines the assessment framework associated with Forrester's solution for security and risk (S&R) executives. The report is designed to help CISOs as they continue working their way...

In the cyclical nature of increasing and decreasing industry regulations, we are clearly on an upswing. Regulators that have faced public scorn for lax oversight are reacting with newfound...
Rarely does vendor consolidation reflect such fragmentation of a market. Picking up on the recent acquisition trend of independent market leaders, IBM today announced plans to acquire long-time GRC...
Processes: The Governance, Risk, And Compliance Playbook
As a risk professional, you are currently in a position to exert more influence on your organization and increase the value you and your team can offer. Many of you will feel pressure to develop...

Last week saw news that yet another top GRC software vendor has been acquired, following in the footsteps of Paisley, Archer, OpenPages, among others. BWise has always been an impressive vendor in...
There has been an interesting PR battle in Washington over the last few weeks about the number of massive regulations still on the administration's agenda. House Minority Leader John Boehner...
The Forrester Information Security Maturity Model is a framework that consists of four main security domains (oversight, technology, process, and people) with 25 functions and 123 low-level...

After an in-depth survey of IT security and risk professionals, as well as our ongoing work with leaders in this field, Forrester recognized the need for a detailed, practical way to measure the...
An Overwhelmingly Diverse Market Struggles For Definition, While Few Leaders Emerge
Failure of corporations to comply with regulations and to manage risks puts customers, employees, communities, and shareholders at risk on a daily basis. Global backlash pressures risk and compliance...
My colleague Boris Evelson, who covers business intelligence for Forrester and serves business process professionals, recently wrote a great post about the use of spreadsheets for business...
Have you been having trouble getting your board of directors to care about information security? This weekend’s news that Nasdaq’s Directors Desk web application was...
Practical Steps To Start Uncovering And Treating The Hidden Risks In Third-Party Relationships
The growing reliance on third-party providers is an increasingly uncomfortable trend for security and risk professionals. Financial pressures and efficient delivery models create great incentives for...
RSA Archer, Agiliance, Rsam, Symantec, and Modulo Are All Leaders For Very Different Reasons
IT governance, risk, and compliance (GRC) vendors continue to show strong technical and strategic advances, while the market itself still struggles to define its direction. A small set of vendors...
We're looking for software that assists with the management and auditing of gifts that our employees receive from customers and suppliers.
This week we published the first in a series of reports I'll be writing to help clients calculate the return on investment of GRC technologies. This report, How To Measure The ROI Of A GRC...
Making Sure Today's Compliance Dollars Tackle Tomorrow's Compliance Challenges
As long as the general population suffers as a result of corporate malfeasance and missteps, government oversight will continue to grow. If compliance is one of your responsibilities, the near future...