About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

John serves Security & Risk Professionals. He is a leading expert on wireless security, network security, security information management, and PCI data security.
John is a 25-year veteran of the high-tech world. He holds numerous industry certifications, including CISSP, CEH, QSA, and CCNA. Prior to joining Forrester, John was the senior security architect with security consultancy Vigilar, and he started the security practice for a Cisco Gold VAR, Flair Data Systems, where he was a principal security consultant. He has particular expertise in the areas of wireless security, intrusion detection and prevention, and voice over IP hacking. He has been interviewed and published in numerous magazines, including Hospitality Technology Magazine, SecurityFocus.com, and Techtarget.com. John has spoken at many security conferences and events, including ToorCon, ShmoCon, and InfoSec World.
John has a Bachelor of Arts degree in communications from the University of Iowa.
We are currently exploring all remote access options, particularly SSL functionality. What kind of trends are you are seeing in these areas?
Are there certain vendors/solutions/configurations that are considered best practices for jump servers? Are organizations relying entirely on authentication and authorization controls, without having...
What vendors compete in the enterprise key management market?
Are there any standard PCI report templates for providing information to my QSA?
We are in the process of selecting unified threat management (UTM) vendors. We have completed a decision analysis based on a technical needs assessment, but we need help narrowing down our vendors....
When it comes to selecting a logging consolidation tool for an enterprise, what are some tips for developing a request for proposal? Based on your experience, what would you single out as the most...
Is it possible to use an intrusion prevention system (IPS) instead of using the full capabilities of a web security gateway (WSG)? What could an IPS provide for the web traffic beyond the WSG?
We are looking for a solution to centrally manage USB drives for all of our desktops. More specifically, we would want to ensure that data on the USB drive is encrypted. Does Forrester have any...
Tokenization: Is it the right technology to encrypt cardholder (saving and debit cards) data? What is the usage level of this product and of similar technologies on the market? What is the level of...
A Payment Card Industry (PCI) certified environment requires patching within 30 days of the patch's release, but what is common practice in a PCI shop?
We would like to understand some best practices in the field of log management. More specifically: 1. Is it a best practice to correlate, aggregate, and monitor all logs for business risk and...
Can you provide us with definitions on the following types of security certificates: 1) SSL; 2) EFS; 3) device certificates; 4) user certificates; 5) code certificates; 6) signed and unsigned...