About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Stephanie serves Security & Risk Professionals. She leads a team of analysts who provide research and advisory services on topics like IT security frameworks; governance, risk, and compliance (GRC); identity and access management (IAM); application security; data security; and IT infrastructure security. She also provides Forrester's coverage of specific risk topics including business continuity (BC), IT continuity/disaster recovery (DR), and backup and recovery.
Stephanie has more than 12 years of experience in BC/DR, backup and recovery, and information storage industries. Prior to joining the security and risk team, Stephanie was a principal analyst on Forrester's infrastructure and operations team, where she was instrumental in the development of Forrester's research and offerings in continuity, availability, and information storage and protection. Prior to joining Forrester, Stephanie was a senior analyst with Yankee Group, where she provided insight on technology trends to key system, storage, and information protection vendors and consultative advice on strategic and tactical initiatives. Before Yankee Group, Stephanie worked at EMC, first as a technical architect and then as a senior education and productivity consultant. As a technical architect, she articulated EMC's value to partners and customers and designed solutions to meet customer and new market opportunities. As an education and productivity consultant, she managed and supported complex technical training programs for business and practice managers in EMC's Technology Solutions Group. Prior to EMC, Stephanie worked at Accenture as a consultant, focusing on the implementation of business applications (SAP, PeopleSoft) for global businesses.
Stephanie holds a bachelor's degree in business administration and finance and investments from Babson College.
Executive Overview: The Data Security And Privacy Playbook
Data is the lifeblood of today's digital businesses, and for economic and even political gain, highly skilled cybercriminals are determined to steal it. Meanwhile, customers around the globe have...

Tokenization: Is it the right technology to encrypt cardholder (saving and debit cards) data? What is the usage level of this product and of similar technologies on the market? What is the level of...
Executive Overview: The Security Architecture And Operations Playbook
We've all heard about the "evolving threat landscape." In biology, evolution is a process that takes millions of years to occur as a result of small changes in successive generations. Mutations, on...
Policy And Procedures: The Data Security And Privacy Playbook
Data defense is the fundamental purpose of information security. To defend your data, there are only four levers you can pull — controlling access, inspecting data usage patterns for abuse,...

An Empowered Report: Understanding The Threats To Unified Communication And VoIP Deployments
In many companies, the worlds of data networking and telecommunications have merged, and voice and video traffic travels with other enterprise data on the same corporate network. Often known...
Last year the country of Japan suffered a devastating disaster of unspeakable proportions. A massive earthquake on the eastern coast of the country triggered a deadly tsunami that caused the flooding...
This checklist is provided as a concise and comprehensive workbook to help organizations deal with the different types of assessments and tests that security and risk professionals must perform to...
Road Map: The Security Architecture And Operations Playbook
This report outlines Forrester's solution to help security and risk (S&R) leaders develop their road map for Zero Trust network threat mitigation technologies using Forrester's TechRadar™...

To effectively deal with the broad and complex requirements of Payment Card Industry (PCI) data security, you need to break the elements apart to provide enhanced clarity. We've designed the PCI...
Policy And Procedures US Government Spotlight: The Security Architecture And Operations Playbook
US federal law, specifically the Federal Information Security Management Act (FISMA), requires US federal government agencies to adhere to National Institute of Standards and Technology (NIST)...
Strategic Plan: The Security Architecture And Operations Playbook
One of our goals with Zero Trust is to optimize the security architectures and technologies for future flexibility. As we move toward a data-centric world with shifting threats and perimeters, we...

A Mature Space, IPS Is Still The Bulwark Of Network Security
An intrusion prevention system (IPS) complements traditional firewalls by inspecting the entire network packet looking for malicious traffic that is often invisible to Layer 3 firewalls. While...
Are there certain vendors/solutions/configurations that are considered best practices for jump servers? Are organizations relying entirely on authentication and authorization controls, without having...
Vision: The Security Architecture And Operations Playbook
There's an old saying in information security: "We want our network to be like an M&M, with a hard crunchy outside and a soft chewy center." For a generation of information security...
This is a workbook that supplements the PCI X-Ray: Application Security Document
At Forrester's Security Forum 2011 in Miami, November 9-10, we will be reprising the wildly successful "Hackers Vs. Executives" track session. There will be two leading security...
Are there any standard PCI report templates for providing information to my QSA?
Forrester continues to receive many customer inquiries related to effective patch management of servers and endpoints. Balancing the urgency of patching with the need to minimize employee downtime...
Yesterday, WikiLeaks released emails taken in the highly-publicized Stratfor data breach. While many of the emails are innocuous, such as accusations regarding a stolen lunch from the company...
Can you provide us with definitions on the following types of security certificates: 1) SSL; 2) EFS; 3) device certificates; 4) user certificates; 5) code certificates; 6) signed and unsigned...
A Payment Card Industry (PCI) certified environment requires patching within 30 days of the patch's release, but what is common practice in a PCI shop?
To effectively deal with the broad and complex requirements of Payment Card Industry (PCI) data security, you need to break the elements apart to provide enhanced clarity. We've designed the PCI...
We are in the process of selecting unified threat management (UTM) vendors. We have completed a decision analysis based on a technical needs assessment, but we need help narrowing down our vendors....
Future Look: The Data Security And Privacy Playbook
This report outlines the future look of Forrester's solution for security and risk (S&R) executives seeking to develop a holistic strategy to protect and manage sensitive data. In the...
