Issue Papers
Nemertes Issue Papers
Nemertes Issue Papers deliver our groundbreaking research and actionable recommendations on emerging IT topics.
Clients may click on any of the links below to access Issue Papers.
Non-clients: Please contact us for information on obtaining access to Nemertes Issue Papers.
Click on the titles below to read the complete Issue Paper
- e-Discovery + ESI = e-Challenges - Fall 2008
- Ensuring Customer Loyalty -Fall 2008
- The 10 Commandments of Data Center Design - September 2008
- The Business of Reselling IP Telephony - September 2008
- The Three-Tiered WAN Architecture - August 2008
- Green IT: Saving Money, Saving the World-or Both? - July 2008
- Defining the "U" in UTM: Unified, Ubiquitous or Useless? - June 2008
- Hijacking the Enterprise Services Bus - June 2008
- Security as a Process - May 2008
- New Suit of Armor: Securing the New Data Center - April 2008
- The Center is Everywhere - April 2008
- The Path to Continuous Compliance Management - April 2008
- Not an End in Itself: Information Protection and Return on Risk - April 2008
- Information Risk Management in the Enterprise - April 2008
- Virtualization Risk Analysis - February 2008
- Virtualization Best Practices - February 2008
- Next-Generation Unified Messaging - January 2008
- Reaching Out to Protect Within: Comparing and Contrasting ISO and NIST Information Security Standards - 2008
- VOIP Security - December 2007
- Chief Risk Officer - Balancing Risk & Reward - December 2007
- Next Generation Computing Strategies - December 2007
- The ROI of IP Telephony Management - December 2007
- Managing the Virtual Workplace - November 2007
- Virtual Insecurity - November 2007
- Implementing Mobility for your Business - October 2007
- Empowering Branch & Virtual Workers - October 2007
- Branch Office Best Practices - September 2007
- The Business Case for Collaboration - September 2007
- VOIP Trends and Directions - August 2007
- Network Services and The New DataCenter - August 2007
- Leveraging Convergence for Collaboration - July 2007
- The Cost of Communications - July 2007
- Unified Communications - July 2007
- Data Center I/O Consolidation - June 2007
- VOIP Business Case - May 2007
- Unified Communications - Real-Time Communications Concepts and Business Applications - April 2007
- Web Optimization: Improving Application Performance from Within the Data Center - April 2007
- Hard and Fast Rules - Firewall Appliances and the Data Center - April 2007
- Securing Virtualized Infrastructure - March 2007
- Unified Communications In The Contact Center - December 2006
- Peer-to-Peer and Grid Next-Generation Architecture - December 2006
- The Business Case For Management - December 2006
- Open Source VOIP - December 2006
- Extreme Availability - December 2006
- Securing Critical Applications and Databases: A Layered Approach - September 2006
- IP Address Management And Securing The IP Infrastructure - August 2006
- Successfully Managing Mergers and Acquisitions - August 2006
- MPLS: What, Where, Who, Why? - August 2006
- Turning Technology Into Value - May 2006
- Collaborative Tools: Enabling Real-World Productivity Gains - May 2006
- Hosted VOIP: Rx For Branch Offices - April 2006
- Making the Most of Your VoIP Deployment: Organizational Best Practices - April 2006
- Remote Offices And The Rise Of The Virtual Worker - April 2006
- Hijacking The Enterprise Service Bus - March 2006
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: e-Discovery + ESI = e-Challenges
Overview:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Brief: Building the Nimble SMB
Overview:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: Ensuring Customer Loyalty
Overview:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Brief: Operating VOIP Effectively
Overview:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Brief: Top VOIP Picks for Small Businesses
Overview:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Brief: SMB Mobility Trends
Overview:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Brief: UCC Professional Service Trends for SMBs
Overview:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Brief: Leveraging Unified Communications for Fun and Profit
Overview:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Brief: SOA, SaaS and SMBs
Overview:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: Building the SMB WAN
Overview:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: SOA Business Case for SMBs
Overview:
The shift to service-oriented architectures (SOA)—loosely coupled constellations of collaborating software components—is under way, with most enterprises in Nemertes’ Service Oriented Architectures and Applications benchmark already deploying at least a pilot SOA, and a few running full-blown SOA implementations.
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: The 10 Commandments of Data Center Design
Overview:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: The Business of Reselling IP Telephony
Overview:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: The Three-Tiered WAN Architecture
The Issue:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: Green IT: Saving Money, Saving the World-or Both?
The Issue:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: Defining the “U” in UTM: Unified, Ubiquitous or Useless?
The Issue:
The challenge today is that IT is accelerating, putting the CSO
between a rock and a hard place. On the one hand he or she must uphold
corporate policies and manage security and compliance. On the other
hand, the CSO cannot be seen as business prevention; security cannot be
the big red stop button on the IT assembly line. Simultaneous with IT
acceleration, an evolution is occurring in the security realm, defined
by unified threat management (UTM). Sitting at the confluence of
security and networking, UTM is evolving from a simple consolidation
value proposition to a ubiquitous solution that holds the potential to
provide the CSO with the tools to meet the corporate risk tolerance
while fully supporting the agility goals of the business.
Threat Management Must Evolve
From Nemertes’ conversations with IT executives, we know that
security can be both business enablement and business prevention. For
example, two-thirds of organizations that participated in Nemertes’
Security and Information Protection (Sec-IP) benchmark have avoided a
new technology because of security concerns. Our research also
indicates that CSOs are mostly successful in implementing security:
nearly 95% of participants in Security and Information Protection
(Sec-IP) consider their security efforts successful. (Please see Figure
1: Rating of Security Success, Page 2). Yet at the same time, nearly
35% of participants have had a security breach in the past year. This
tells us that security, and threat management in particular, still
leaves much room for improvement.
Read this Issue Paper:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: Hijacking the Enterprise Services Bus
The Issue:
Network vendors have, for some years, been surveying the landscape,
looking for new worlds to conquer as supplying connectivity per se has become
more and more a commodity game. First they built core network‐related
functionality, such as IP‐address assignment and DNS service, into their gear
(although many, if not most, shops still use servers for these functions). Then
they offered security functionality, first filling in gaps that server and desktop
vendors left between their own security functionality; year by year offering more
and moving gradually to supplant or compete with server and desktop security
functions. They began to offer bandwidth optimization, followed some years
later by application acceleration, most recently incarnated as the specific
acceleration for file sharing known as WAFS (wide‐area file services). They
branched into voice and video over IP, and then into collaborative applications
with voice and video built in.
Now, Cisco specifically is moving further “up the stack” and into the
realm of enterprise messaging, specifically into the business of managing XML
message traffic among nodes – not just speeding up XML traffic (which many
vendors do) through compression and the like, but actually taking on the
message routing and transformation functions of traditional messaging
middleware. Others network vendors may follow Cisco’s lead, as they often
have in the past – and some non‐network companies, like IBM and Intel, have
ventured into the converged space via acquisition of messaging appliance
companies (DataPower and Sarvega, respectively). But how should network
vendors approach this market, now that they are competing against major
software vendors and outside the traditional network space?
Clients: Read this issue Paper
Non Clients: Nemertes Issue Papers are available to clients only.
If you're not a client and would like to receive a copy of the Issue Paper, please contact us.
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: Security as a Process
The Issue:
IIT security staff, faced with the challenge of securing the inevitable flux in
their infrastructure, are usually stuck in reactive mode. They react – to systems
upgrades, mergers, and acquisitions; to the re-centralization of most IT function
into data centers and the consolidation of data centers; and to the spread of all
sizes and kinds of organizations over ever more space as a result of the
continuing 9 to 11% growth in the number of branch offices. Proactive security –
helping plan and execute security changes to enable adoption of new tools and
technologies – falls by the wayside.
IT security is set up to prevent and react to security problems, not to set
acceptable levels of risk. Significant increases in risk are traditionally viewed as
automatically “bad”. Given the difficulty of securing the complex interfaces
among different architectures, silos, and generations of technology, optional
changes and elective complexity are resisted if not simple to secure. How then
can IT security shift from a reactive to a proactive position?
One action security teams and IT are increasingly performing to reduce
risk and manage complexity is set policies to guide ongoing operations. By
defining policy, one can lay out more secure operational modes for everyone and
make dealing with complex infrastructures less a matter of individual memory,
capacity, and preference, and more a matter of documented practice.
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: New Suit of Armor: Securing the Data Center
The Issue:
Major tectonic shifts in the way enterprises work with and provision their
core applications are forcing changes in the way the enterprise has to think about
securing them.
One shift is the continuing opening of the enterprise, with the gradual
federation and interpenetration of IT systems between an enterprise and its
partners, customers, and suppliers. The figurative walls of the data center are
being filled with doors, windows, and access ducts, and now serve more as a
framework for structuring the flow of information than as a barrier to it.
Another shift is the rise of service-oriented architectures (SOAs).
Enterprises are looking to SOA to provide an integration method for their
applications, a development methodology and framework, and an overall
architecture and philosophy for deploying new functionality. As enterprise
applications gain services interfaces, and sometimes are actually atomized and
turned into constellations of loosely-coupled services, each service creates on the
network a new set of access points; perhaps tens or hundreds of times as many as
there were before. Things that used to happen within an application, on a single
server, become network traffic among servers and even among data centers.
Some formerly internal functions even become invocations across the Internet of
software-as-a-service (SaaS) packages, or services in partner or supplier data
centers. Moreover, components in a SOA can scale independently of each other:
new instances of an application running on a Java application server might be
created to handle peak loads, and then destroyed as the load subsides.
Read this Issue Paper:
Clients:New Suit of Armor: Securing the Data Center
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: The Center is Everywhere
The Issue:
The very essence of “work” is changing. All across the world, but even
more so in the U.S., society is changing the definitions of “work” and “office”. As
communications and connectivity become more powerful and ever more widely
available, work has become less and less a place and more an activity which takes
place anywhere. In the last 4 years Nemertes Research has tracked the number of
employees working away from their company headquarters. That number has
gradually trended up, exceeding 90% in 2006. Today, branch office and mobile
workers dominate, and knowledge workers are increasingly mobile, operating out
of home offices, hotel rooms, airport lounges, coffee shops and taxis. As their
work habits have changed through enabling communications technologies, they
have in turn pushed adoption of those technologies by their companies: laptops,
wireless Ethernet, smart phones, and web applications.
Large companies have gradually shifted more and more of their critical
applications to the web. Through a web browser, the same application can be
delivered to a desktop, a laptop, a phone, regardless of location, operating system
or (mostly) browser. This “webification” of applications has become a catalyst for
further mobility and fluidity of the workforce.
Read this Issue Paper:
Clients - The Center is Everywhere
Non clients: Nemertes Issue Papers are available to clients only. If you're not a
client and would like to receive a copy of the Issue Paper, please
contact us.
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: The Path to Continuous Compliance Management
The Issue:
As the role of the CSO shifts from technical security expert to risk
mediator, manager and advisor, compliance is rapidly becoming the domain of
the CSO. In this role, the CSO is faced with the continual tug-of-war in the
corporation between legal, business and IT. To make matters worse, the CSO –
as Chief Risk Officer – is put in the position of keeping the company out of
trouble, without having any control over the direction or the company, or the
actions of IT, business and legal. The only way that the CSO can affect risk and
manage risk is through implementation of a strong compliance management
process. Compliance management is the heart of governance and risk
management and as such, it’s the main tool in the CSO tool box.
Compliance is a complex issue and it requires a unique combination of
technical, legal, business and management skills. Compliance itself requires
solving the equivalent of a multi-variable equation: regulations, control
frameworks and change. To achieve continuous compliance management, CSOs
must implement tools and processes that automate and streamline the
compliance management process. The first step is implementation of logging,
eventually culminating in the establishment of a continuous compliance
management solution that not only reports on what has happened, but
implements triggers, monitors and controls to prevent what is going to happen.
Read this Issue Paper:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: The Path to Continuous Compliance Management
The Issue:
As the role of the CSO shifts from technical security expert to risk
mediator, manager and advisor, compliance is rapidly becoming the domain of
the CSO. In this role, the CSO is faced with the continual tug-of-war in the
corporation between legal, business and IT. To make matters worse, the CSO –
as Chief Risk Officer – is put in the position of keeping the company out of
trouble, without having any control over the direction or the company, or the
actions of IT, business and legal. The only way that the CSO can affect risk and
manage risk is through implementation of a strong compliance management
process. Compliance management is the heart of governance and risk
management and as such, it’s the main tool in the CSO tool box.
Compliance is a complex issue and it requires a unique combination of
technical, legal, business and management skills. Compliance itself requires
solving the equivalent of a multi-variable equation: regulations, control
frameworks and change. To achieve continuous compliance management, CSOs
must implement tools and processes that automate and streamline the
compliance management process. The first step is implementation of logging,
eventually culminating in the establishment of a continuous compliance
management solution that not only reports on what has happened, but
implements triggers, monitors and controls to prevent what is going to happen.
Read this Issue Paper: The Path to Continuous Compliance Management
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: Not an End In Itself: Information Protection and Return on Risk
The Issue:
Information protection is one of the core disciplines of Information
Stewardship, alongside business continuity, information lifecycle management,
data quality management, and compliance. The purpose of Information
Stewardship is to enhance the value of information and reduce the risk to
information within the context of the business value. In other words, Information
Protection is only relevant in the context of the broader value of information.
Maximizing information protection must always be balanced against
maximizing the business value of information. The business value of information
is derived from the processing, transformation, sharing and dissemination of
information – the very activities that create risk! It is crucial to look at
information protection as one axis in a broader picture of investment and
innovation decisions: you cannot focus only on maximizing information
protection (maximizing security). After all, the best way to maximize the
protection of information is to lock it up and throw away the key – which of
course means that the information is then no longer available to the business.
Being a good steward of the information requires using security to enable
business functions but to minimize the risk of them as far as necessary.
Read this Issue Paper: Not an End In Itself: Information Protection and Return on Risk
This Issue Paper is available to registered users. Registration is free - please register for access.
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: Not an End In Itself: Information Protection and Return on Risk
The Issue:
Information protection is one of the core disciplines of Information
Stewardship, alongside business continuity, information lifecycle management,
data quality management, and compliance. The purpose of Information
Stewardship is to enhance the value of information and reduce the risk to
information within the context of the business value. In other words, Information
Protection is only relevant in the context of the broader value of information.
Maximizing information protection must always be balanced against
maximizing the business value of information. The business value of information
is derived from the processing, transformation, sharing and dissemination of
information – the very activities that create risk! It is crucial to look at
information protection as one axis in a broader picture of investment and
innovation decisions: you cannot focus only on maximizing information
protection (maximizing security). After all, the best way to maximize the
protection of information is to lock it up and throw away the key – which of
course means that the information is then no longer available to the business.
Being a good steward of the information requires using security to enable
business functions but to minimize the risk of them as far as necessary.
Read this Issue Paper: Not an End in Itself: Information Protection and Return on Risk
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: Information Risk Management in the Enterprise
The Issue:
Enterprise IT security is being pulled steadily towards a risk-based view of
the world. Companies need to understand their tolerance for risk, and embrace
technologies and practices that allow them to meet, but not exceed, that
tolerance. The disciplines of information stewardship provide a lens through
which the enterprise can focus its actions in information risk management. By
focusing on the discipline of information protection, it can choose where and how
to apply technologies, such as encryption, to maximize the return on risks of
information leak or theft. Focusing on data quality management can minimize
both the operational risks from inconsistent or incorrect data, and the legal risks
from lapses in compliance, inadvertent disclosure, or unintentional failure to
disclose information in court. Focusing on continuity mitigates risk from data
being unavailable due to natural disaster, systems break down, or attack.
Read this Issue Paper:
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: Information Risk Management in the Enterprise
The Issue:
Enterprise IT security is being pulled steadily towards a risk-based view of
the world. Companies need to understand their tolerance for risk, and embrace
technologies and practices that allow them to meet, but not exceed, that
tolerance. The disciplines of information stewardship provide a lens through
which the enterprise can focus its actions in information risk management. By
focusing on the discipline of information protection, it can choose where and how
to apply technologies, such as encryption, to maximize the return on risks of
information leak or theft. Focusing on data quality management can minimize
both the operational risks from inconsistent or incorrect data, and the legal risks
from lapses in compliance, inadvertent disclosure, or unintentional failure to
disclose information in court. Focusing on continuity mitigates risk from data
being unavailable due to natural disaster, systems break down, or attack.
Read this Issue Paper: Information Risk Management in the Enterprise
Delicious
|
Digg
|
Reddit
|
Technorati
Nemertes Issue Paper: Virtualization Best Practices
The Issue:
Server virtualization is one of the most-discussed technologies of the past
few years. We find that although some organizations are already generating
substantial savings with virtualization in their production environments, the
majority of participants in Nemertes’ Security and Information Protection
benchmark research are not yet using virtual servers in production. They plan to,
however, looking for the increased resource utilization, broader platform
standardization, and deeper management automation that server virtualization
enables.
As virtual servers move into production, IT needs to address security and
compliance issues. Unfortunately, most participants in the benchmark, when
asked how they secure their virtual servers, say they treat them like physical
servers as much as possible! Sensibly, they use host-based security such as antivirus
and anti-malware agents. However, they also use network tools to protect
virtual servers exactly as if they were simply very thin, very densely stacked rackmount
boxes.
