About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.
The Forrester Information Security Maturity Model is a framework that consists of four main security domains (oversight, technology, process, and people) with 25 functions and 123 low-level...


Effective Onboarding Can Affect Product Retention And Cross-Selling Goals
Increased government regulations and a tough economy have combined to create significant challenges for financial services firms. Consumer product strategy professionals are leading the charge to...

Predictive And Behavioral Analysis Finds Its Way Into Identity And Access Management
Identity and access management (IAM) professionals need to protect information and prevent unauthorized users from accessing business-critical systems in an increasingly complex IT environment. They...

Is it possible to use an intrusion prevention system (IPS) instead of using the full capabilities of a web security gateway (WSG)? What could an IPS provide for the web traffic beyond the WSG?
Enterprises of all sizes are interested in evaluating products for detecting and preventing the transmission and storage of PII, PHI and sensitive corporate secrets. By the end of 2010, Forrester...
Seven Tenets Of Effectively Combating Fraud Costs
Fraud causes companies to lose money in many ways: They face losses due to chargebacks, unrecoverable transfers, and unnecessary shipping costs; and spend extensive time and resources investigating...
Security professionals increasingly must respond to the needs of business owners exploring web application programming interfaces (APIs) as a new channel for recognizing business value. APIs can...
Executive Overview: The S&R Practice Playbook
Today, business leaders expect the CISO to not only protect the organization from run-of-the-mill hackers but to also protect its brand and competitive advantage in the marketplace — all while...

A Mature Space, IPS Is Still The Bulwark Of Network Security
An intrusion prevention system (IPS) complements traditional firewalls by inspecting the entire network packet looking for malicious traffic that is often invisible to Layer 3 firewalls. While...
How do retailer websites handle login expiration? Is it session-based, login-persisted, 30-day cookie, and so on? What is the norm or best practice?
Organization: The Personal Identity Management Playbook
In anticipation of the increasing adoption of personal identity management (PIDM) tools and services, customer intelligence (CI) leaders will be held increasingly accountable for their organizations'...

Extend Assurance Downstream To Customers And Upstream To Suppliers
The extended enterprise is here, but current security architectures are ill-suited for the task of securing the extended ecosystem. Security and risk professionals must adopt a new mindset for...

Assessment Framework: The Mobile Security And Operations Playbook
This report provides the maturity assessment of Forrester's solution for security and risk (S&R) and infrastructure and operations (I&O) executives looking to build their mobile security and...

Ernst & Young, Deloitte, IBM, Accenture, PwC, And KPMG Lead, With Wipro Following Close Behind
The information security consulting market is growing explosively because security and risk professionals often lack the skill and bandwidth to accomplish their increasingly difficult mission. To...

As a consequence of increasing global commerce, security and risk (S&R) professionals face the complexity of navigating data privacy regulations from around the world. Forrester clients frequently...