About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.
Essential Functionality For The Zero Trust Model Of Information Security
In today's threat environment, the network perimeter has disappeared. Insiders are as insidious a threat as outsiders. In the past, the "trust but verify" model did not facilitate insight into...
To effectively deal with the broad and complex requirements of Payment Card Industry (PCI) data security, you need to break the elements apart to provide enhanced clarity. We've designed the PCI...
I’ll be in Austin, TX this weekend to participate in South-by-Southwest Interactive. My panel “Big Data Smackdown on Cybersecurity” will be held Sunday, March 11 from 12:30PM -...
From frantic security operations problems to the changing threat landscape, CISOs, senior security leaders, and other IT risk management leaders consistently have trouble keeping up with key trends...

Forrester's Data Security And Control Framework
Forrester segments the problem of securing and controlling data into three areas: 1) defining the data; 2) dissecting and analyzing the data; and 3) defending and protecting the data. We refer to...

At Forrester's Security Forum 2011 in Miami, November 9-10, we will be reprising the wildly successful "Hackers Vs. Executives" track session. There will be two leading security...
Tokenization: Is it the right technology to encrypt cardholder (saving and debit cards) data? What is the usage level of this product and of similar technologies on the market? What is the level of...
Forrester continues to receive many customer inquiries related to effective patch management of servers and endpoints. Balancing the urgency of patching with the need to minimize employee downtime...
Executive Overview: The Security Architecture And Operations Playbook
We've all heard about the "evolving threat landscape." In biology, evolution is a process that takes millions of years to occur as a result of small changes in successive generations. Mutations, on...
The legendary British Prime Minister Benjamin Disraeli is said to have noted that “There are lies, damn lies, and statistics.” Much of the technology world is focused on statistics and...
Strategic Plan: The Data Security And Privacy Playbook
As cybercriminals have become more skillful and sophisticated, they have eroded the effectiveness of our traditional perimeter-based security controls. The constantly mutating threat landscape...
Rethinking Data Discovery And Classification For Data Security
Defining data via data discovery and classification is an often overlooked, yet critical, component of data security and control. Security and risk (S&R) pros can't expect to adequately protect data...

Business Case: The Security Architecture And Operations Playbook
We may look back on 2011 and 2012 as the golden age of hacking. In 2011, we saw well-publicized and devastating attacks such as the one that brought down the Sony PlayStation Network (PSN). In 2012,...
Assessment Framework: The Data Security And Privacy Playbook
Data loss prevention or protection (DLP) — depending upon your usage — is both one of the hottest topics and most difficult challenges among information security professionals today. In...

Policy And Procedures US Government Spotlight: The Security Architecture And Operations Playbook
US federal law, specifically the Federal Information Security Management Act (FISMA), requires US federal government agencies to adhere to National Institute of Standards and Technology (NIST)...
To effectively deal with the broad and complex requirements of Payment Card Industry (PCI) data security, you need to break the elements apart to provide enhanced clarity. We've designed the PCI...
We are in the process of selecting unified threat management (UTM) vendors. We have completed a decision analysis based on a technical needs assessment, but we need help narrowing down our vendors....
Future Look: The Data Security And Privacy Playbook
This report outlines the future look of Forrester's solution for security and risk (S&R) executives seeking to develop a holistic strategy to protect and manage sensitive data. In the...

Today EMC’s security division RSA announced the acquisition of NAV (Network Analysis and Visibility) vendor NetWitness. Some pundits have suggested that this is a direct...
Are there certain vendors/solutions/configurations that are considered best practices for jump servers? Are organizations relying entirely on authentication and authorization controls, without having...
FLASH TRAFFIC: This just in! The Washington Post is reporting a new wrinkle in cyberwarfare. In the article Defense official discloses cyberattack, the Post reports that “malicious code placed...
We would like to understand some best practices in the field of log management. More specifically: 1. Is it a best practice to correlate, aggregate, and monitor all logs for business risk and...
To effectively deal with the broad and complex requirements of Payment Card Industry (PCI) data security, you need to break the elements apart to provide enhanced clarity. We've designed the PCI...
We are currently exploring all remote access options, particularly SSL functionality. What kind of trends are you are seeing in these areas?