About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Derek serves Enterprise Architecture Professionals. He is an internationally recognized expert in business process management (BPM) and organizational transformation. He has worked in this area for more than 20 years, dealing with major brands, governmental organizations, and nongovernmental organizations (NGOs). Derek's research focuses on the methods, approaches, frameworks, tools, techniques, and technologies of business architecture; BPM; business process improvement; business transformation; and organizational change. He places special emphasis on an outcome-based, customer-focused approach.
Derek is a well-known keynote speaker and chair of major EA conferences. As co-chair of BPMI.org, he helped merge the organization with the Object Management Group (OMG).
Derek completed the Early Growth Program at London Business School.
Policy And Procedures US Government Spotlight: The Security Architecture And Operations Playbook
US federal law, specifically the Federal Information Security Management Act (FISMA), requires US federal government agencies to adhere to National Institute of Standards and Technology (NIST)...
I’ll be in Austin, TX this weekend to participate in South-by-Southwest Interactive. My panel “Big Data Smackdown on Cybersecurity” will be held Sunday, March 11 from 12:30PM -...
Essential Functionality For The Zero Trust Model Of Information Security
In today's threat environment, the network perimeter has disappeared. Insiders are as insidious a threat as outsiders. In the past, the "trust but verify" model did not facilitate insight into...
When it comes to selecting a logging consolidation tool for an enterprise, what are some tips for developing a request for proposal? Based on your experience, what would you single out as the most...
Forrester continues to receive many customer inquiries related to effective patch management of servers and endpoints. Balancing the urgency of patching with the need to minimize employee downtime...
Executive Overview: The Data Security And Privacy Playbook
Data is the lifeblood of today's digital businesses, and for economic and even political gain, highly skilled cybercriminals are determined to steal it. Meanwhile, customers around the globe have...

This checklist is provided as a concise and comprehensive workbook to help organizations deal with the different types of assessments and tests that security and risk professionals must perform to...
Assessment Framework: The Data Security And Privacy Playbook
Data loss prevention or protection (DLP) — depending upon your usage — is both one of the hottest topics and most difficult challenges among information security professionals today. In...

Can you provide us with definitions on the following types of security certificates: 1) SSL; 2) EFS; 3) device certificates; 4) user certificates; 5) code certificates; 6) signed and unsigned...
What vendors compete in the enterprise key management market?
Policy And Procedures: The Data Security And Privacy Playbook
Data defense is the fundamental purpose of information security. To defend your data, there are only four levers you can pull — controlling access, inspecting data usage patterns for abuse,...

The legendary British Prime Minister Benjamin Disraeli is said to have noted that “There are lies, damn lies, and statistics.” Much of the technology world is focused on statistics and...
This is a workbook that supplements the PCI X-Ray: Application Security Document
Tokenization: Is it the right technology to encrypt cardholder (saving and debit cards) data? What is the usage level of this product and of similar technologies on the market? What is the level of...
The PCI Security Standards Council released the summary of changes for the new version of PCI — 2.0. Merchants, you can quit holding your breath as this document is a yawner...
A Mature Space, IPS Is Still The Bulwark Of Network Security
An intrusion prevention system (IPS) complements traditional firewalls by inspecting the entire network packet looking for malicious traffic that is often invisible to Layer 3 firewalls. While...
Future Look: The Data Security And Privacy Playbook
This report outlines the future look of Forrester's solution for security and risk (S&R) executives seeking to develop a holistic strategy to protect and manage sensitive data. In the...

Are there any standard PCI report templates for providing information to my QSA?
Companies often demand to know what their peers in a particular vertical market are doing within the realm of information security before making new decisions. “We’re in retail” or...
FLASH TRAFFIC: This just in! The Washington Post is reporting a new wrinkle in cyberwarfare. In the article Defense official discloses cyberattack, the Post reports that “malicious code placed...
To effectively deal with the broad and complex requirements of Payment Card Industry (PCI) data security, you need to break the elements apart to provide enhanced clarity. We've designed the PCI...
An Empowered Report: Understanding The Threats To Unified Communication And VoIP Deployments
In many companies, the worlds of data networking and telecommunications have merged, and voice and video traffic travels with other enterprise data on the same corporate network. Often known...
Business Case: The Security Architecture And Operations Playbook
We may look back on 2011 and 2012 as the golden age of hacking. In 2011, we saw well-publicized and devastating attacks such as the one that brought down the Sony PlayStation Network (PSN). In 2012,...
At Forrester's Security Forum 2011 in Miami, November 9-10, we will be reprising the wildly successful "Hackers Vs. Executives" track session. There will be two leading security...
A Payment Card Industry (PCI) certified environment requires patching within 30 days of the patch's release, but what is common practice in a PCI shop?