For Security & Risk Professionals (Length: 7 pages)
This document includes Business Data

January 5, 2009

Data-Centric Security Requires Devolution, Not A Revolution

CISOs Must Revisit The Need To Centrally Control Data Security

by Andrew Jaquith

with Khalid Kark, Stephanie Balaouras, Rachel A. Dines


Executive Summary (This is a document excerpt)

Despite years of investments in technology and processes, protecting enterprise-wide data remains a maddeningly elusive goal for chief information security officers (CISOs). Software-as-a-service (SaaS), Web 2.0 technologies, and consumerized hardware increase the number of escape routes for sensitive information. Regulations, statutes, and contractual expectations drown CISOs in audit requests and ratchet up the pressure to do something about the problem. Meanwhile, hordes of vendors confuse CISOs with innumerable sales pitches. Forrester believes there is a better way to secure corporate data — stop trying so hard. Instead, devolve responsibility to the business, keeping controls closest to the people who use the data. IT security should be primarily responsible only for deploying data protection technologies that require minimal or no customization.

Buy Risk-Free

Download and print PDF immediately. Price: US $499

Our Money-Back Guarantee: If you are not completely satisfied, return it for a full refund within three weeks of your online purchase.

Already a Forrester Client?
Log in to read this document.

Add to cart

Find Documents In Related Categories

This document falls under the following categories. Click on a link below to find similar documents.

Analyst: Andrew Jaquith
Technology: Information Protection, Security & Risk
Geography: Asia Pacific, Europe, North America

Archived Teleconference:
corner border corner
Ratings and Comments
Rating: 5 out of 10
based on 4 ratings across all roles.
corner border corner