About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Derek serves Enterprise Architecture Professionals. He is an internationally recognized expert in business process management (BPM) and organizational transformation. He has worked in this area for more than 20 years, dealing with major brands, governmental organizations, and nongovernmental organizations (NGOs). Derek's research focuses on the methods, approaches, frameworks, tools, techniques, and technologies of business architecture; BPM; business process improvement; business transformation; and organizational change. He places special emphasis on an outcome-based, customer-focused approach.
Derek is a well-known keynote speaker and chair of major EA conferences. As co-chair of BPMI.org, he helped merge the organization with the Object Management Group (OMG).
Derek completed the Early Growth Program at London Business School.
By 2012, OAuth Will Be The Incumbent Cloud API Security Solution
Enterprises face a tension between the cloud-friendly software environment promoted by the Web, with its easy-to-use REST interface style and proliferation of lightweight services, and the security...
Back in July, I wrote about a new RESTful API that cloud providers and provisioning vendors are working on for doing identity provisioning and synching: Simple Cloud Identity Management, or SCIM...
The rapid adoption of mobile devices and cloud services together with a multitude of new partnerships and customer-facing applications has extended the identity boundary of today’s enterprise....

Future Look: The Identity And Access Management Playbook
This report outlines the future look of Forrester's solution for security and risk (S&R) executives working on building an identity and access management strategy for the extended enterprise. We...

From frantic security operations problems to the changing threat landscape, CISOs, senior security leaders, and other IT risk management leaders consistently have trouble keeping up with key trends...

Stakeholder Needs: The Identity And Access Management Playbook
This report outlines the stakeholder needs of the Identity And Access Management playbook. Forrester has identified lack of IT executive buy-in and attention as a chronic issue in projects related to...
How do retailer websites handle login expiration? Is it session-based, login-persisted, 30-day cookie, and so on? What is the norm or best practice?
My organization is just beginning to externally expose services for our first native mobile application. We currently have a single sign-on (SSO) security infrastructure for our web applications....
For a new extranet portal, we're looking for the best way to authenticate strongly 5,000 users all around the world. What is the best way at this time? What way is the easiest to manage?
To help security and risk professionals navigate the complex landscape of privacy laws around the world, Forrester created a data privacy heat map that highlights the data protection guidelines and...
Many IT security pros are moving toward disruptive new authentication and authorization practices to integrate securely with cloud apps at scale. If you’re considering such a move yourself,...
I just love the theme of our upcoming Forrester Security Forum (Las Vegas in May, and Paris in June -- check out Laura Koetzle's definitive blog post). Leapfrog Your Global Competition. Rethink...
Why Firms Need To Share Data To Become Customer-Obsessed
Enterprises seeking to better understand their customers, market, and competitive landscape can't afford to limit their insights to only what they already know — the data they generate...
Prepare For Cloud Security Improvements, Along With A Tincture Of Disruption
Security professionals responsible for diverse types of access management across cloud services, devices, and populations have to pull off a neat trick: control access requests that routinely cross...
Do you have any thoughts on using voice-as-PIN and retinal security, from a security perspective as well as an end user customer-experience perspective?
Executive Overview: The Identity And Access Management Playbook
The rapid adoption of mobile devices and cloud services, together with a multitude of new partnerships and customer-facing applications, has "extended" the identity boundary of today's enterprise....
We're looking for secure access solutions for a web interface that will enable some sort of strong authentication but doesn't use a two-factor password token. We're thinking of solutions that allow a...
With The SCIM Specifications, User Provisioning Goes "Zero Trust"
Business owners are jumping on SaaS services to get quicker wins, and CIOs are finding these services attractive for cutting costs as well. Since it's relatively quick and easy to hook up these...
Cloud providers and many federated IAM practitioners are excited about OAuth, a new(ish) security technology on the scene. I’ve written about OAuth in Protecting Enterprise APIs With A Light...
Andras Cser probed a sore spot in IAM last week with his post, “XACML Is Dead.” It’s a necessary conversation (though I did see a glint in his eye at the Forrester BT Forum after he...
A Review Of Budgets, Spending Intentions, Technology Adoption, And Key Trends
To help Forrester clients with their identity and access management (IAM) strategy for 2011, Forrester predicted four significant trends. So how'd we do? We got two right and two half right. Heading...

Portable Identity Gives New Options To Companies, Consumers, And Clouds
Fast-moving cloud and consumer identity trends are driving shifts in how IT professionals control user access and provide personalized service to networked applications. As IT professionals move to...
It has finally become hip not just to predict the demise of passwords, but to call for their elimination. The recent Wired article makes an eloquent case about the vulnerabilities that even...
Two years ago, the OAuth API protection mechanism was a fairly well-kept secret. It actually won an award at the 2009 European Identity Conference for "best new/improved standard," but most people...