About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.
During the past three years, cloud-based identity and access management (IAM) solutions have become a viable and cost-effective alternative to on-premises, commercial off-the-shelf (COTS), or...

Today we see two basic flavors of cloud IAM. One archetype is the model offered by Covisint, VMware Horizon, Symplified, Okta, OneLogin, etc.: these vendors provide relatively tight integration, but...
We regularly get inquiries from companies that feel the need to restructure their access controls to support extended enterprise user populations: firms have to support employees, contractors,...

With only 4 stack players in Identity and Access Management, it is always welcoming news to see a new company joining the space. Quest Software is on a shopping spree: it acquired e-DMZ (privileged...
We are kicking off research on security and identity intelligence, which is about understanding risk and detecting abnormal behavior. One thing is clear: companies don't even *know* what...
Many IT end-user companies deployed hard tokens at a time when intermediate-risk choices were thinner on the ground, and some of these companies would have benefited from a more granular approach...
Can you please provide the top reasons that justify investing in and using identity and access management?
We are currently looking at implementing identity management for our external customers with a cloud-based solution. What are the risks associated with allowing write access to our Active Directory...
I'm working on a proposal for an enhanced security standard for the employees who work on matters of particular sensitivity. This would be a standard that could be "turned on" or "off" depending on...
Assessment Framework: The Identity And Access Management Playbook
An identity and access management (IAM) maturity model is necessary for assessing your current state against industry best practices, understanding your performance relative to that of your peers,...
I'd like to better understand whether we are using current best practices around limiting administrative access to production systems. We currently use jump servers as gateways for administrators...
Traditional Methods Start To Sag, While Mobile-Fueled Methods Surge
The strong authentication landscape has undergone tremendous churn in recent years as new mobile-fueled technologies have come online and as RSA, the premier vendor of hardware one-time password...
Strategy Deep Dive: The Mobile Security And Operations Playbook
Mobile devices are everywhere: at work, in the hands of your customers, and with employees. Security and risk (S&R) professionals need to provide users with secure and seamless mobile access to...

We have three stores where we store user credentials. We're looking for a solution to synchronize them, and we want to avoid having to write our own programs to do this. Are there commercial...
Requirements For Data Security, Mobile Devices, And Cloud-Based Services Will Forge Ahead
For 2011, Forrester predicts that IT administration efficiency and business agility will become the main drivers for using identity and access management (IAM). A bevy of acquisitions during the past...
We will be conducting research to look into how big data can be used for better fraud management. We define big data as data of Volume, Velocity and Variety. Our premise is that more and more...
We are looking at strengthening our processes around access management, access control, monitoring, and auditing. We have four questions: 1) what are the adoption rates for privileged account...
After RSA's acquisition of SilverTail, things are heating up in mobile application level behavioral detection. We see fraud management vendors increasingly looking at mobile application...
Insurers Must Catch Up To The Sophistication Of Today's Fraudsters
Fraud costs the US insurance industry upward of $40 billion, which the industry then passes on to policyholders in the form of higher premiums. Financial crime is on the rise as fraudsters become...
Business Impact: The Identity And Access Management Playbook
Security and risk (S&R) executives responsible for identity and access management (IAM) must manage access to sensitive applications and data because of security and compliance requirements -- and...
Desktop or enterprise single sign-on (E-SSO) is a relatively easy way to provide end user convenience and to get started in identity and access management (IAM). The end user benefits of E-SSO are...
Mobile authentication is nothing new. SiteMinder, a prominent web access management tool, has been able to handle mobile browsers and sessions for at least 7-8 years. Some users complained of...