About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.
Assessment: The Security Architecture And Operations Playbook
Given the continued metastasizing of the threat landscape, it comes as no surprise that enterprises should possess mature incident response capabilities that are built on staff, augmented by...

Performance Management: The Security Architecture And Operations Playbook
Information security programs have struggled with legitimacy with senior leaders for a long time. There are many reasons for this, but they all can be traced back to the historical inability of chief...

Strategic Plan: The Security Architecture And Operations Playbook
One of our goals with Zero Trust is to optimize the security architectures and technologies for future flexibility. As we move toward a data-centric world with shifting threats and perimeters, we...

Executive Overview: The Security Architecture And Operations Playbook
We've all heard about the "evolving threat landscape." In biology, evolution is a process that takes millions of years to occur as a result of small changes in successive generations. Mutations, on...
Organization: The Security Architecture And Operations Playbook
This report outlines the organizational implications of Forrester's solution for security and risk (S&R) executives working to rethink their security architecture and improve the effectiveness of...
Skills And Staffing: The Identity And Access Management Playbook
This report outlines the skills and staffing requirements for security and risk (S&R) executives working on building an identity and access management strategy for the extended enterprise. Identity...
Future Look: The Identity And Access Management Playbook
This report outlines the future look of Forrester's solution for security and risk (S&R) executives working on building an identity and access management strategy for the extended enterprise. We...

Prepare For Cloud Security Improvements, Along With A Tincture Of Disruption
Security professionals responsible for diverse types of access management across cloud services, devices, and populations have to pull off a neat trick: control access requests that routinely cross...
An Empowered Report: Run At The Threat, Shape The Future Of Your Company
Employees are provisioning themselves with consumer and cloud technology. Forrester's study of US information workers reveals that 37% are doing something with technology without permission. And not...
Rethinking And Redesigning B2B Security Architecture For Today's Tech Innovations
Many security and risk professionals seek to implement fine-grained security controls that span traditional boundaries and perimeters for their organizations. Businesses today have global operations...
The PCI Unleashed Framework is designed to logically organize the PCI requirements so that it is easy to understand and extend. The framework shows that there is an overall security organization and...
The EA team of 2009 reports high into the IT organization (either to the CIO or senior planning roles beneath the CIO), has broad acceptance and support, and spends about half its time on strategic...
In September 2009, Forrester hosted a two-day event designed to help security and risk professionals understand the top three shifts impacting their job heading. This document summarizes the key...
In September 2009, Forrester hosted a two-day event designed to help security and risk professionals understand the top three shifts impacting their job heading. This document summarizes the key...
In September 2009, Forrester hosted a two-day event designed to help security and risk professionals understand the top three shifts impacting their job heading. This document summarizes the key...
To effectively deal with the broad and complex requirements of Payment Card Industry (PCI) data security, you need to break the elements apart to provide enhanced clarity. We've designed the PCI...
The big news for the IT security market in 2009 is that it will fare relatively well. Cost and justification pressures are exerting themselves, but through increasing business-level visibility led by...
To effectively deal with the broad and complex requirements of Payment Card Industry (PCI) data security, you need to break the elements apart to provide enhanced clarity. We've designed the PCI...
Tightly coupling data sources with applications has been a common approach for applications that need to access enterprise data, but with increasing data volume and data complexity along with the...
The Promise Of Improved Security Or The Risk Of New Attack Vectors
Next-generation information architectures such as data federation and information services are gaining increased adoption, so security professionals must ensure their protection from all relevant...
Companies are adopting a more data-centric approach to security, but they're finding that some protection still needs to reside in the infrastructure. Infrastructure-centric measures ease the...
Electricity Distributors Get Security Mandates and Standards
As digital industrial control systems (ICS) become increasingly interconnected both with each other and with enterprise information technology infrastructures, the risks of unauthorized access to and...
CISOs have been striving to evolve their security programs and focus more on addressing business risk issues than on responding to tactical security events. In 2008, we will see executives and...
The integration of enterprise physical security controls and management regimes with enterprise IT security architectures is a nascent trend that has been forecast as imminent for several years. But...
Many CISOs and security managers want to take a more strategic approach to security, but don¿t have the time or the resources to put together a framework and the necessary tools to map out what their...