About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.
Start Small And Keep An Eye On The Breadth Of Your Future Mobile Scenarios
User authentication is a key foundation of security for mobile apps — as it is for application security in general. Determining which authentication approach to use for your mobile solution...

Security professionals increasingly must respond to the needs of business owners exploring web application programming interfaces (APIs) as a new channel for recognizing business value. APIs can...
Road Map: The Identity And Access Management Playbook
This report outlines Forrester's solution to help security and risk (S&R) leaders develop their road map of IAM processes using Forrester's TechRadar™ methodology. The extended enterprise...

It's no mystery that antivirus (AV) technologies are fighting a losing battle against an increasingly sophisticated malware threat landscape. Attackers often penetrate user endpoints with new malware...

Road Map: The Security Architecture And Operations Playbook
This report outlines Forrester's solution to help security and risk (S&R) leaders develop their road map for Zero Trust network threat mitigation technologies using Forrester's TechRadar™...

Extend Assurance Downstream To Customers And Upstream To Suppliers
The extended enterprise is here, but current security architectures are ill-suited for the task of securing the extended ecosystem. Security and risk professionals must adopt a new mindset for...

By 2012, OAuth Will Be The Incumbent Cloud API Security Solution
Enterprises face a tension between the cloud-friendly software environment promoted by the Web, with its easy-to-use REST interface style and proliferation of lightweight services, and the security...
Best Practices You Must Enforce With App Developers
As consumer devices such as iPhones and iPads proliferate in the enterprise and among consumers, the number of organizations interested in custom development of mobile applications is steadily on the...
IBM, Imperva, And Sentrigo Lead, With Application Security, Oracle, And Fortinet Close Behind
In Forrester's 147-criteria evaluation of database auditing and real-time protection vendors, we found that the market is rife with mature products. IBM, Imperva, and Sentrigo lead the pack because...
Organizations Remain Tentative In Application Security Investment
Application security is an essential tool for managing risks in today's increasingly dynamic and capable threat landscape. Yet the market for application security remains small, and organizations are...
Forrester's security and risk (S&R) team fields hundreds of inquiries every month. We often gauge the interest in various topics and plan our future research agenda based on this barometer. Many of...
Cybersecurity And Services Fuel The Next Phase Of Market Growth
In Q3 2010, Forrester surveyed 2,058 IT security decision-makers at North American and European small businesses and enterprises to gauge the current state and identify the key trends and future...
To Deliver Extraordinary Software, Design To Balance These Seven Qualities
Great software applications seldom happen by accident: Wise design decisions are the key. Yet many application development teams only design for one, two, or three of these qualities, and others have...
This is a workbook that supplements the PCI X-Ray: Application Security Document
To effectively deal with the broad and complex requirements of Payment Card Industry (PCI) data security, you need to break the elements apart to provide enhanced clarity. We've designed the PCI...
Governance, Maturity, And Analytics Are The Major Themes For 2011
Every winter Forrester outlines 12 important recommendations for your security strategy for the coming year. We base these recommendations on hundreds of client inquiries, numerous consulting...
Looking At The Opportunity Beyond The Obstacle
Concerns about security are the most prominent reasons that organizations cite for not adopting cloud services. Therefore, creating more comprehensive security capabilities is a prerequisite for...

Rethinking And Redesigning B2B Security Architecture For Today's Tech Innovations
Many security and risk professionals seek to implement fine-grained security controls that span traditional boundaries and perimeters for their organizations. Businesses today have global operations...
WAF+ Finds Its Place In Firms' Network Infrastructure
Having been thrust into the spotlight by payment card industry (PCI) data security standard (DSS) requirements three years ago, Web application firewall (WAF) — a technology that detects and...
Business Data Services North America And Europe
Security spending for small and medium-size businesses (SMBs) has been faring relatively well through the economic downturn, and budgets appear to be strengthening, most notably in the area of new...
Business Data Services North America And Europe
IT security investment has been faring relatively well through the economic downturn, and budgets appear to be strengthening, most notably in the area of new product purchases. Data security and...
Many companies, besieged by audit findings and application vulnerabilities, recognize the benefits of eliminating security vulnerabilities early in the software life cycle. For this reason, static...
Oracle, CA, And IBM Lead, With Novell And Sun Microsystems Close Behind
In Forrester's 79-criteria evaluation of identity and access management (IAM) vendors, we found that Oracle, CA, and IBM lead the pack because of a rich IAM portfolio (both organically developed and...
A Two-Dimensional Continuum For Diverse SOA Security Solutions
Architects crafting their organization's strategy and architecture for service-oriented architecture (SOA) security have a wide diversity of security requirements, business scenarios, and application...
Selecting Standards, Specifications, And Products For SOA Security
As enterprise architects set their organization's strategy for service-oriented architecture (SOA) security, they will have to filter through a variety of standards, emerging specifications, and...