About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Derek serves Enterprise Architecture Professionals. He is an internationally recognized expert in business process management (BPM) and organizational transformation. He has worked in this area for more than 20 years, dealing with major brands, governmental organizations, and nongovernmental organizations (NGOs). Derek's research focuses on the methods, approaches, frameworks, tools, techniques, and technologies of business architecture; BPM; business process improvement; business transformation; and organizational change. He places special emphasis on an outcome-based, customer-focused approach.
Derek is a well-known keynote speaker and chair of major EA conferences. As co-chair of BPMI.org, he helped merge the organization with the Object Management Group (OMG).
Derek completed the Early Growth Program at London Business School.
Security And Risk Professionals Must Prepare To Phase Out SAS 70 Today
Developed by the American Institute of CPAs (AICPA), the Statements on Auditing Standards 70 (SAS 70) has been around since 1992. When the Sarbanes-Oxley Act (SOX) of 2002 passed, SAS 70 gained new...
This month I published a new report on information security metrics, best practices as well as a maturity model to measure your maturity in the reporting process. This report outlines the...
In conjunction with Forrester's update to our information security metrics and best practices report, Forrester has developed a model to help you assess the maturity of your security metrics program.

Seven Critical Executive-Level Metrics For CISOs And The Business
The ability to communicate effectively has always been a core competency for any business executive, and today's chief information security officer (CISO) is fast becoming a business executive. The...
Everyone knows that in business you need to do two things: Increase top-line revenue growth and reduce bottom line cost. Doing both of these is how companies grow profitably. It really is that...
What are the pros and cons of security reporting within IT versus a non-IT department?
I always have been interested in Enterprise Architecture. Enterprise Architecture is one of those terms that security professionals hear about but do not always know how it can benefit what...
Build/Buy Capabilities: The S&R Practice Playbook
This report outlines a sourcing strategy and Forrester's decision support solution for security and risk (S&R) executives working to build a high-performance security program and organization. We...

Are organizations in the financial services sector still using war dialing as a control to identify potential insecure modems or telephony applications? Is it still a best practice to engage in this...
Performance Management: The Security Architecture And Operations Playbook
Information security programs have struggled with legitimacy with senior leaders for a long time. There are many reasons for this, but they all can be traced back to the historical inability of chief...

Ten Emerging Service Providers That Have The Chops To Be Your Managed Security Service Provider
In Forrester's 15-criteria evaluation of the emerging managed security services provider (MSSP) market, we identified the 10 most significant providers in this category — Alert Logic; CompuCom;...

I just wrote a paper on the value of information security. Please see the paper here. It is something I have thought about for a long time. Information security as a technical discipline...
This is the second in a series of reports providing guidance and new methods for the financial management of information security. The CISO's role is rapidly changing. A few years ago the CISO for...

After months of diligent vendor evaluations, last week we officially published The Forrester Wave: Managed Security Services: North America, Q1 2012. This report features our detailed analysis on...
There are many types of criminals. These include thrill-seeking hackers, politically motivated hackers, organized criminals after financial gain, and state-sponsored groups after financial gain and...
While you are at the Forrester Security IT Forum in Miami, you might also want to attend my session on Managed Security Services Providers. In my role as an analyst, I speak to many security...
Ernst & Young, Deloitte, IBM, Accenture, PwC, And KPMG Lead, With Wipro Following Close Behind
The information security consulting market is growing explosively because security and risk professionals often lack the skill and bandwidth to accomplish their increasingly difficult mission. To...

Business Impact: The S&R Practice Playbook
This report outlines Forrester's approach to helping you financially model information security. In today's seemingly never-ending cycle of new technologies, cyberthreats, and regulations, it's...
I just finished a final draft of a presentation on information security executive reporting that I and some colleagues will present at the upcoming Forrester IT Forum in Las Vegas. For those of...
Guest Post From Researcher Chris Sherman Last month, Ed and I spent a couple days in Paris with Orange's management team for their annual analyst event. Overall I was impressed with...