About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.
One of my clients is implementing a bring-your-own-device (BYOD) program and would like to understand if there is a way to divide personal and corporate information. Is that possible? If one of my...
I'm looking for an industry-standard definition of an "intrusion," including examples, scope, and scale if applicable. We have reporting obligations to the FBI and DSS for cyber intrusions.
We are currently looking at implementing identity management for our external customers with a cloud-based solution. What are the risks associated with allowing write access to our Active Directory...
We are currently exploring all remote access options, particularly SSL functionality. What kind of trends are you are seeing in these areas?
Can you please provide the top reasons that justify investing in and using identity and access management?
What is the future of web access management (WAM) technology? What are the advantages and disadvantages of the different WAM products, focusing on the pros and cons of agent-based versus proxy...
What is the future of the enterprise directory for authentication and authorization? Are changes in technology, such as faster hardware and improvements in databases, going to support moving...
Could you provide information on data leak prevention (DLP) versus information rights management (IRM) solutions? Do you recommend one or the other or both? What vendors play in this space?
We are looking at strengthening our processes around access management, access control, monitoring, and auditing. We have four questions: 1) what are the adoption rates for privileged account...
Are there certain vendors/solutions/configurations that are considered best practices for jump servers? Are organizations relying entirely on authentication and authorization controls, without having...
Can you confirm or deny the following suppositions: 1) Machine certificates distributed from an internal MS CA are the best method for Windows device authentication. 2) There is no "magic...
We are interested in understanding more about biometric signatures. What is your view of these technologies?
Do you have any thoughts on using voice-as-PIN and retinal security, from a security perspective as well as an end user customer-experience perspective?
We would like to know how hospitals are protecting themselves against clinical devices infecting their networks. We have many third-party-owned or -maintained devices, such as PACS, medical devices,...
What vendors compete in the enterprise key management market?
How are banking companies using biometric technologies today? How urgent is the need to deploy such technologies?
Do you have any advice on the balance between deploying a web application firewall (WAF) in active mode versus passive mode?
Which apps require more security versus less security?
I'd like to better understand whether we are using current best practices around limiting administrative access to production systems. We currently use jump servers as gateways for administrators...
My organization is just beginning to externally expose services for our first native mobile application. We currently have a single sign-on (SSO) security infrastructure for our web applications....
We would like to know the current outlook of malware on smartphones and tablets. Should we recommend antivirus software for corporate-owned devices? Are organizations enforcing antivirus protection...
Does Forrester still recommend the following for securing virtual environments? Enforce zone boundaries with separate hardware; hypervisor hosts should not take on network security functions such as...
What standards — if any — exist as to file types to block? Are zip files still viewed as a significant security risk, and if so, how do organizations balance the business need to access...
We would like to know the costs and duration of active directory consolidation activities in large enterprises. We would also like to know hear about any real-life experience with active directory...