About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.
This is the second in a series of reports providing guidance and new methods for the financial management of information security. The CISO's role is rapidly changing. A few years ago the CISO for...

In conjunction with Forrester's update to our information security metrics and best practices report, Forrester has developed a model to help you assess the maturity of your security metrics program.
Ernst & Young, Deloitte, IBM, Accenture, PwC, And KPMG Lead, With Wipro Following Close Behind
The information security consulting market is growing explosively because security and risk professionals often lack the skill and bandwidth to accomplish their increasingly difficult mission. To...

Security And Risk Professionals Must Prepare To Phase Out SAS 70 Today
Developed by the American Institute of CPAs (AICPA), the Statements on Auditing Standards 70 (SAS 70) has been around since 1992. When the Sarbanes-Oxley Act (SOX) of 2002 passed, SAS 70 gained new...
Performance Management: The S&R Practice Playbook
This report outlines the benchmarks for Forrester's solution for security and risk (S&R) professionals looking to build a high-performance security program and organization. We designed this report...
Performance Management: The Security Architecture And Operations Playbook
Information security programs have struggled with legitimacy with senior leaders for a long time. There are many reasons for this, but they all can be traced back to the historical inability of chief...

Ten Emerging Service Providers That Have The Chops To Be Your Managed Security Service Provider
In Forrester's 15-criteria evaluation of the emerging managed security services provider (MSSP) market, we identified the 10 most significant providers in this category — Alert Logic; CompuCom;...

The Nine Service Providers That Matter Most And How They Stack Up
In Forrester's 60-criteria evaluation of the North American managed security services market, we identified the nine significant service providers in this category — AT&T, CSC, Dell...

Build/Buy Capabilities: The S&R Practice Playbook
This report outlines a sourcing strategy and Forrester's decision support solution for security and risk (S&R) executives working to build a high-performance security program and organization. We...

The Information Security Metrics 3R Dashboard should be used as a template to present information security metrics organized across three dimensions: Readiness, Response, and Recovery. Forrester...

Business Impact: The S&R Practice Playbook
This report outlines Forrester's approach to helping you financially model information security. In today's seemingly never-ending cycle of new technologies, cyberthreats, and regulations, it's...
Performance Management: The Data Security And Privacy Playbook
Privacy is one of the most important and emotional issues in information security. Privacy, or the lack thereof, affects a company's management, employees, and most importantly, customers. With the...

Seven Critical Executive-Level Metrics For CISOs And The Business
The ability to communicate effectively has always been a core competency for any business executive, and today's chief information security officer (CISO) is fast becoming a business executive. The...