Archive for the ‘Gartner’ Category

Findings: Evaluate Limitations of Log Management as a Service Offering

|
Comments Off
Log management services can provide essential functions to meet compliance requirements for log collection, retention and review. However, security and compliance directors should evaluate offerings for additional capabilities that will support additional investigation, analysis and reporting uses.

How to Decide Where Security Operational Functions Should Report

|
Comments Off
There is no "right" answer to the question of how an enterprise should structure its security operations organization. A clear understanding of a set of key factors will enable chief information security information officers to make the best decisions for their specific enterprises.

Best Practices for Removing End-User Administrator Rights on Windows

|
Comments Off
Removing administrator rights from end users is one of the single most-effective ways to improve overall security posture, but it must be well-planned to avoid common pitfalls and a failed project.

Enterprise Options for Federated Single Sign-On to the Cloud

|
Comments Off
Client interest in leveraging enterprise authentication for single sign-on to the cloud is rising. There are several options to choose from. The right one could cost almost nothing.

Evaluating Vulnerability Assessment Capabilities

|
Comments Off
Many vulnerability assessment products provide active scanning and the option of passive monitoring or agent-based scanning to enable comprehensive vulnerability detection. Our analysis of additional capabilities for these products guides buyers who are looking beyond basic assessment features.

Gartner Authentication Method Evaluation Scorecards, 2011: Overview

|
Comments Off
Many enterprises worldwide are adopting new authentication methods in a variety of use cases to meet multiple requirements. However, enterprises often lack a formal way of evaluating different methods and products, and this can lead to inappropriate choices.

Gartner Authentication Method Evaluation Scorecards, 2011: Total Cost of Ownership

|
Comments Off
Many enterprises worldwide are adopting new authentication methods in a variety of use cases to meet multiple risk management requirements. However, poorly understood TCO undermines many selection decisions.

Cloud IaaS: Security Considerations

|
Comments Off
Security and compliance are key requirements when purchasing infrastructure as a service in the cloud. Carefully evaluate the claims of service providers.

Authentication: Ten Myths and Misconceptions Debunked

|
Comments Off
Authentication is a keystone of the trust relationship between the enterprise and its users, yet many efforts to improve its effectiveness are undermined by well-entrenched myths and misconceptions. This research debunks 10 of these.

Information Security and Risk Governance: Functions and Processes

|
Comments Off
Information security and risk governance consist of the functions and processes that ensure the requisite actions are taken to protect the organization's information resources, in the most appropriate and efficient manner, in pursuit of its business goals.