MarketScope for IT Governance, Risk and Compliance Management, 2008

Size: px
Start display at page:

Download "MarketScope for IT Governance, Risk and Compliance Management, 2008"

Transcription

1 MarketScope for IT Governance, Risk and Compliance Management, 2008 Gartner RAS Core Research Note G , Paul E. Proctor, Mark Nicolett, French Caldwell, 11 February 2008, RA The IT GRCM market was new for 2007, but it is predicted to epand in The functions IT GRCM products provide address needs epressed by 75% of the Gartner client base. WHAT YOU NEED TO KNOW The IT governance, risk and compliance management (GRCM) market is composed of vendors that provide software products that help organizations proactively measure and manage their IT technology and process controls. The IT GRCM market became viable in 2007, with several vendors offering products, but the products are early and lack maturity on many levels. IT GRCM solutions have a repository; basic document management capabilities; good workflow, survey and reporting functions; and dashboarding, with policy content that is specific to IT controls, and support for the automated measurement and reporting of IT controls. MARKETSCOPE This document is an updated version of the document published on 11 February IT GRCM is a new market. Its products support operations risk management through functions that measure, manage, and report on IT-centric technology and process controls. Organizations can use IT GRCM products to document and assess their IT-centric technology and process controls. For more information on the definition and use of core IT GRCM functions: Controls and policy mapping Policy distribution and training attestation IT control self-assessment and measurement IT GRCM asset repository Automated general computer control (GCC) collection Remediation and eception management Basic compliance reporting IT compliance dashboards IT risk evaluation The IT GRCM market became viable in 2007, with several vendors offering products that are strong in the following areas: Policy mapping Advanced in most products, thus making it easier for organizations to document their controls and map them to their control objectives and regulatory requirements.

2 2 IT-centric perspectives and functions Support the unique needs of IT operations, security and risk management managers beyond the generic and financial-centric functions of financial GRCM vendors. Advanced computer controls collection Automated gathering of technology evidence; relatively immature in some products, but strong in others. The products in this market are early and lack maturity on many levels. In general, the products in this market suffer from the following limitations: Lack of integration between many of the core functions in a single offering. Many of the vendors offer multiple disconnected products to cover different core functions. Technology and process controls are not appropriately integrated at the assessment and reporting levels. Treating them separately reduces the effectiveness of risk measurement. Solutions are too auditor-centric. Many of the products betray their roots in support of auditors or as security configuration management technology. IT GRCM should support an organization in its audits and in proactively managing controls. Market/Market Segment Description The IT GRCM market is composed of vendors that provide software products that help organizations proactively measure and manage their IT technology and process controls. They also help: Define IT policies, processes and controls that are based on best practices. Manage policy content. Map policies to process and technical controls, as appropriate. Automate the measurement of process and technical controls. Evaluate the risk of noncompliance. Automate the auditing and regulatory reporting of these elements. IT GRCM solutions have a repository; basic document management; good workflow, survey and reporting functions; and dashboarding, with policy content that is specific to IT controls, and support for the automated measurement and reporting of IT controls. IT GRCM solutions may take input from controls automation and monitoring tools, such as configuration auditing, identity and access management, and security information and event monitoring. Inclusion and Eclusion Criteria Inclusion in the 2008 IT GRCM MarketScope is based on a software product s function in the following areas. Coverage of core IT GRCM functions. Products must be in general availability as of 1 January Products must be deployed in at least three customer production environments, with references available, as of 1 January Participants must be determined by Gartner to be significant players in the market, via market presence and/or technology innovation. Products must specifically target and market to the IT GRCM market. IT Governance Offerings of Enterprise GRCM Platform Vendors The primary reason why some buyers look to enterprise GRC (EGRC) platform vendors, rather than IT GRCM vendors, for IT governance functionality is that they are taking an enterprise approach to compliance and risk management, and want to have all business units, including the IT organization, on the same GRCM solution. Many vendors with EGRC platforms offer modest IT governance functionality. At a minimum, most EGRC vendors offer the ability to document, survey and report IT risks and controls, but lack IT-specific content. Some also provide limited support for an IT asset repository and IT policy management. Although BWise is the only EGRC vendor considered to have enough IT GRCM functionality to be rated in this MarketScope, other vendors have partial IT governance functions. In addition, some IT GRCM vendors provide solutions that can be adapted to EGRC use cases and are beginning to successfully compete in the EGRC market segment. Rating for Overall Market/Market Segment Overall Market IT GRCM products provide functions that address needs epressed by 75% of the Gartner client base. Gartner estimates that software license revenue for vendors that meet our criteria for inclusion in the IT GRCM MarketScope was $73 million for 2007, and we project a growth rate of 70% for For vendors such as NetIQ and Symantec, which have substantial revenue streams from GCC measurement point solution products, we included a percentage of that revenue based on the current adoption rates of other IT GRCM modules. Evaluation Criteria Vendor Product/Service Analysis Agiliance Agiliance is a young company that has been shipping its product (IT-GRC) since December Agiliance IT-GRC provides tightly integrated capabilities that function out of the bo, with little customization required. The highlight of this offering is its intuitive interface and its top-down approach to managing IT-related controls. Although it s not the best in all categories, Agiliance should be considered by organizations that require balanced IT GRCM functionality across all categories Gartner, Inc. and/or its Affiliates. All Rights Reserved. Reproduction and distribution of this publication in any form without prior written permission is forbidden. The information contained herein has been obtained from sources believed to be reliable. Gartner disclaims all warranties as to the accuracy, completeness or adequacy of such information. Although Gartner s research may discuss legal issues related to the information technology business, Gartner does not provide legal advice or services and its research should not be construed or used as such. Gartner shall have no liability for errors, omissions or inadequacies in the information contained herein or for interpretations thereof. The opinions epressed herein are subject to change without notice.

3 3 Table 1. Evaluation Criteria Evaluation Criteria Market Understanding Comment Ability of the vendor to understand buyers wants and needs, and to translate those into products and services. Vendors that show the highest degree of vision listen to and understand buyers wants and needs, and can shape or enhance those with their added vision. Weighting high Customer Eperience Relationships, products and services/programs that enable clients to be successful with the products evaluated. Specifically, this includes the ways customers receive technical support or account support. This can also include ancillary tools, customer support programs (and the quality thereof), the availability of user groups, service-level agreements and so on. standard Offering (Product) Strategy The vendor s approach to product development and delivery that emphasizes differentiation, functionality, methodology and feature sets as they map to current and future requirements. low Product/Service Core goods and services offered by the vendor that compete in/serve the defined market. This includes current product/service capabilities, quality, feature sets and skills, whether offered natively or through OEM agreements/partnerships as defined in the market definition and detailed in the subcriteria. high Sales Eecution/Pricing Operations The vendor s capabilities in all pre-sales activities and the structures that supports them. This includes deal management, pricing and negotiation, pre-sales support and the overall effectiveness of the sales channel. The ability of the organization to meet its goals and commitments. Factors include the quality of the organizational structure, including skills, eperiences, programs, systems and other vehicles that enable the organization to operate effectively and efficiently on an ongoing basis. low low Source: Gartner

4 4 Figure 1. MarketScope for IT Governance, Risk and Compliance Management, 2008 RATING Agiliance Archer Technologies Brabeion BWise Information Governance Modulo Security NetIQ Symantec Strong Negative Caution Promising Positive Strong Positive As of 6 February 2008 Agiliance IT-GRC has an intuitive, clean interface; and its top-down approach should ease implementation. It has good out-of-the-bo policy and assessment data; its risk assessment function is comprehensive; and it has good detail and fleibility for confidentiality, integrity and availability assessments. However, simplicity is provided at the epense of some fleibility. The Agiliance product s automated GCC data gathering is relatively weak compared with competitors such as Symantec and NetIQ, and Agiliance is a small company with limited production deployments. Archer Technologies Archer Technologies has provided IT GRCM functions since 2003, and has established a modestly sized installed base of large customers. Archer found initial success in the financial services industry segment, but it now has customers across many segments. Archer provides a suite that is composed of seven management modules (policy, incident, asset, threat, risk, vendor and Sarbanes- Oley Act [SOX] compliance) that can be integrated using the Archer Framework. Archer s offering is oriented to large companies that value the ability to customize over pre-defined functions; therefore, each module requires customization prior to deployment. Although Archer s customer base is small when compared with vendors such as Symantec and NetIQ, its customers are top down users of the technology, and the technology is optimized for risk- and compliance-oriented buyers that are not focused on automating the measurement of GCCs. Because of its design, which supports customization, Archer s offering can also be fleibly deployed. However, automated GCC measurements are not formally supported by the product and require a service engagement. The stability of the automated GCC measurement is also highly variable, depending on the source. Brabeion Brabeion is a young company that started shipping its product in March It has two products: IT Risk and Compliance Center (ITRCC) for policy management/controls mapping, and IT Risk and Compliance Manager (ITRCM) for automated GCC collection. ITRCC is a rewrite of the PricewaterhouseCoopers (PwC) ESAS product, and ITRCM is powered by integrations with the GCC collection components of NetIQ and Symantec. Licensed content from PWC is augmented with Brabeion-developed content. The two products are loosely coupled through a common Web interface. Brabeion s major differentiator is its eclusive licensing of PWC controls framework content, which makes it an obvious shortlist choice for organizations that are looking to address eternal-attest auditor requirements. This strength is also Brabeion s greatest weakness, because the company s offerings are better-suited for supporting auditors than internal teams proactively managing an enterprise risk control program. Brabeion s products offer internal and eternal auditor support, especially for organizations that use or are considering PWC for eternal services. The ITRCC product s version management for the creation of policies is a differentiator. Brabeion s risk assessment capabilities and GCC functions are not as mature as its competitors, which are best-in-class in this area. ITRCC and ITRCM are not well-integrated, even though they have a common interface. Rating: Promising Rating: Strong Positive

5 BWise BWise is the only EGRC platform vendor in this MarketScope. The BWise GRCM product suite is driven by a robust business process management (BPM) engine, which provides good workflow and even some process controls automation. BWise has some of the highest growth rates of any of the vendors in the EGRC platform market, and a large number of customers are using it for IT GRCM purposes. In evaluating BWise s offering from an IT GRCM standpoint, the company was able to demonstrate key IT GRCM elements, including an asset repository, IT-specific policy and controls content, and good policy mapping. Its inherent BPM functionality also proves useful in integrating the collection of GCC information from other vendors technical controls products, but BWise does not have a fully automated collection of GCC information. BWise is particularly strong for buyers who are looking for a crosscompany approach to GRC, rather than an IT-specific solution, but it offers less appeal to those focused specifically on IT security and configuration management controls. BWise has good reportfiltering capabilities, which provide targeted views of risks and controls. Another strength is the company s integration of IT GRC and finance GRC functionality. Information Governance Information Governance is a small company based in Europe with a primary consulting business. Using its consulting eperience and international standards, Information Governance has developed the Proteus product suite to address IT GRCM functions. Although primarily designed to support the internal audit process for international standards such as BS/ISO 27001, it provides good support for small to midsize implementations to proactively address risk management. The primary differentiators are the product s ability to track accountability, schedule, its development plan and its cost justifications for each identified control gap. This structured approach to risk management has more depth than most IT GRCM offerings, but it is less scalable than other parts of the product. Proteus is best for enterprises focused on management and compliance against the information security management system, as defined in BS/ISO Information Governance has good coverage of European standards and localization in several European languages. It has strong support capabilities for controls and audit management in enterprises adhering to international standards. Being a small company that is self-funded can be challenging. Information Governance supports an open application programming interface (API) for integration with third-party GCC collection products; however, there is only one production user for this function. The company is also challenged with integration and content development that is required in larger enterprises with broader control requirements than published BS/ISO standards. Rating: Caution Modulo Security Modulo is an established Brazilian company that provides security software and consulting services. Modulo opened an office in the U.S. to sell to the North American market. The company is large and the products are mature based on their past eperience in Brazil, which positions Modulo to do well in North America if it can develop its sales and marketing effectively. Modulo Risk Manager is primarily a self-assessment and controls management product, and was one of the most fleible products we evaluated, especially in controls mapping and policy management. However, it was not as intuitive as competitors such as Agiliance. Native GCC collection is provided and widely deployed, but it lacks some centralized management capabilities. There is also no integration with eternal ticketing systems. Modulo, however, is a strong company with mature products, and it has good auditor workflow support. Rating: Promising NetIQ The NetIQ division of Attachmate offers a loosely integrated IT GRCM product suite. The suite is comprised of three components: Secure Configuration Manager (SCM), which provides automated GCC definition and measurement, as well as an asset repository; VigilEnt Policy Center (VPC), which provides policy mapping, distribution and response, along with controls self-assessments; and Risk and Compliance Center (RCC), which provides compliance reporting and risk management functions. NetIQ is an established provider of security and operations management software, and has a large installed base for SCM. NetIQ SCM s primary competitor is Symantec. NetIQ tends to sell each component of its suite as a point solution to a specific buying center, in contrast to others that are attempting a topdown sale of broad GRCM functions to risk- and complianceoriented buying centers. NetIQ s strengths include automated GCC definition and measurement, and a loosely coupled suite that enables function acquisitions as needed. NetIQ is an established company with a large customer base and multiple revenue streams; however, its policy mapping and risk assessment functions are focused primarily on technical controls. Automated computer-controls-measurement is not an initial focus of RCM-oriented buying centers. Symantec Symantec s IT GRCM offering Control Compliance Suite (CCS) is based primarily on technology from its 2006 acquisition of BindView, but Symantec is aggressively epanding its product capabilities. IT control self-assessment capabilities are provided through technology from its more-recent acquisition of 4Front Technologies. Automated general-control-collection is provided by the CCS standards module security configuration policy compliance component. Symantec has the largest installed base of 5

6 6 security configuration policy compliance customers and GCC and measurement users spread across its Enterprise Security Manager (ESM; Symantec), CCS (Bindview) and Security Epressions (Altiris) products. It is also the largest provider of IT GRCM technology, with the potential to capitalize on a large services organization. Symantec plans to combine the automated GCC collection capabilities of its ESM and CCS products into a single solution in It is also attempting to sell its CCS suite to risk- and compliance-oriented buying centers, but automated computercontrols-measurement is not an initial focus of these buying centers. Symantec needs to continue developing its risk assessment capabilities. Vendors Added or Dropped We review and adjust our inclusion criteria for Magic Quadrants and MarketScopes as markets change. As a result of these adjustments, the mi of vendors in any Magic Quadrant or MarketScope may change over time. A vendor appearing in a Magic Quadrant or MarketScope one year and not the net does not necessarily indicate that we have changed our opinion of that vendor. This may be a reflection of a change in the market and, therefore, changed evaluation criteria, or a change of focus by a vendor. Gartner MarketScope Defined Gartner s MarketScope provides specific guidance for users who are deploying, or have deployed, products or services. A Gartner MarketScope rating does not imply that the vendor meets all, few or none of the evaluation criteria. The Gartner MarketScope evaluation is based on a weighted evaluation of a vendor s products in comparison with the evaluation criteria. Consider Gartner s criteria as they apply to your specific requirements. Contact Gartner to discuss how this evaluation may affect your specific needs. In the below table, the various ratings are defined: MarketScope Rating Framework Strong Positive Is viewed as a provider of strategic products, services or solutions: Customers: Continue with planned investments. Potential customers: Consider this vendor a strong choice for strategic investments. Positive Demonstrates strength in specific areas, but eecution in one or more areas may still be developing or inconsistent with other areas of performance: Customers: Continue planned investments. Potential customers: Consider this vendor a viable choice for strategic or tactical investments, while planning for known limitations. Promising Shows potential in specific areas; however, eecution is inconsistent: Customers: Consider the short- and long-term impact of possible changes in status. Potential customers: Plan for and be aware of issues and opportunities related to the evolution and maturity of this vendor. Caution Faces challenges in one or more areas. Customers: Understand challenges in relevant areas, and develop contingency plans based on risk tolerance and possible business impact. Potential customers: Account for the vendor s challenges as part of due diligence. Strong Negative Has difficulty responding to problems in multiple areas. Customers: Eecute risk mitigation plans and contingency options. Potential customers: Consider this vendor only for tactical investment with short-term, rapid payback.

MarketScope for IT Governance, Risk and Compliance Management, 2008

MarketScope for IT Governance, Risk and Compliance Management, 2008 Research Publication Date: 11 February 2008 ID Number: G00154941 MarketScope for IT Governance, Risk and Compliance Management, 2008 Paul E. Proctor, Mark Nicolett, French Caldwell The IT GRCM market was

More information

CDOs Should Use IT Governance and Risk Compliance Management to Advance Compliance

CDOs Should Use IT Governance and Risk Compliance Management to Advance Compliance Industry Research Publication Date: 1 May 2008 ID Number: G00156708 CDOs Should Use IT Governance and Risk Compliance Management to Advance Compliance Barry Runyon Care delivery organizations (CDOs) are

More information

Magic Quadrant for Global Enterprise Desktops and Notebooks

Magic Quadrant for Global Enterprise Desktops and Notebooks Magic Quadrant for Global Enterprise Desktops and Notebooks Gartner RAS Core Research Note G00207470, Stephen Kleynhans, 10 November 2010, R3553 11302011 In the general PC market, price is often the main

More information

Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms

Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms Gartner RAS Core Research Note G00158295, French Caldwell, Tom Eid, 30 June 2008, R2799 07092009 The market for enterprise governance,

More information

CIO Update: Gartner s IT Security Management Magic Quadrant Lacks a Leader

CIO Update: Gartner s IT Security Management Magic Quadrant Lacks a Leader IGG-04092003-04 M. Nicolett Article 9 April 2003 CIO Update: Gartner s IT Security Management Magic Quadrant Lacks a Leader Vendors in the Gartner IT Security Management Magic Quadrant for 1H03 are driven

More information

Case Study & POC & Demos Information

Case Study & POC & Demos Information Case Study & POC & Demos Information Type: Case Study Name: Multichannel Campaign Management (MCCM) Description: The IBM Company seeks, as vendor, through the multichannel campaign management (MCCM) services,

More information

2003 Desktop Software Distribution Magic Quadrant

2003 Desktop Software Distribution Magic Quadrant Markets, R. Colville Research Note 15 April 2003 2003 Desktop Software Distribution Magic Quadrant Software distribution is the critical component for desktop configuration management. Vendors in our Magic

More information

Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms

Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms Page 1 of 17 Magic Quadrant for Enterprise Governanc Risk and Compliance Platforms 30 June 2008 French Caldwell, Tom Eid Gartner RAS Core Research Note G00158295 The market for enterprise governance, risk

More information

Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms

Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms Gartner RAS Core Research Note G00206382, French Caldwell, 13 October 2010, R3481 10142011 The EGRC platform market has expanded

More information

Ability to Execute. What You Need to Know

Ability to Execute. What You Need to Know 1 of 10 11/30/2010 1:00 PM 28 July 2010 Bern Elliot, Steve Blood Gartner RAS Core Research Note G00201349 Unified communications offers the ability to improve how individuals, groups and companies interact

More information

The PC life cycle configuration management Market Overview

The PC life cycle configuration management Market Overview Magic Quadrant for PC Life Cycle Configuration Management, 2005 Gartner RAS Core Research Note G00131185, 17 October 2005, Ronni J. Colville, Michael A. Silver, R1580 05052006. The PC life cycle configuration

More information

Unlike the general notebook market, in which

Unlike the general notebook market, in which Magic Quadrant for Global Enterprise Notebook PCs, 2H05 Gartner RAS Core Research Note G00133054, Mikako Kitagawa, Brian Gammage, Leslie Fiering, 12 January 2006, R1662 07222006. Unlike the general notebook

More information

MarketScope for Managed Security Services in Europe

MarketScope for Managed Security Services in Europe Research Publication Date: 5 May 2008 ID Number: G00157248 MarketScope for Managed Security Services in Europe Carsten Casper, Tom Scholtz The managed security service market in Europe continues to grow.

More information

Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms

Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms Research G00213862 13 July 2011 Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms French Caldwell, Tom Scholtz, John Hagerty The EGRC platform market has expanded from a tactical

More information

EMEA CRM Analytics Suite Magic Quadrant Criteria 3Q02

EMEA CRM Analytics Suite Magic Quadrant Criteria 3Q02 Decision Framework, J. Radcliffe Research Note 26 September 2002 EMEA CRM Analytics Suite Magic Quadrant Criteria 3Q02 Europe, the Middle East and Africa Customer Relationship Management Analytics Suite

More information

Magic Quadrant for IT Vendor Risk Management

Magic Quadrant for IT Vendor Risk Management (http://www.gartner.com/home) LICENSED FOR DISTRIBUTION Magic Quadrant for IT Vendor Risk Management 29 October 2014 ID:G00263243 Analyst(s): Christopher Ambrose, Gayla Sullivan, Kris Doering Summary The

More information

Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms

Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms Gartner RAS Core Research Note G00213862, French Caldwell, Tom Scholtz, John Hagerty, 13 July 2011, RAV3A5 1152012 The EGRC platform

More information

The 2H05 Magic Quadrant for managed

The 2H05 Magic Quadrant for managed Magic Quadrant for MSSPs, North America, 2H05 Gartner RAS Core Research Note G00137165, Kelly M. Kavanagh, John Pescatore, 30 December 2005, R1601 01052007. The 2H05 Magic Quadrant for managed security

More information

Ability to Execute. 1 von 22 15.06.2010 17:55. What You Need to Know

Ability to Execute. 1 von 22 15.06.2010 17:55. What You Need to Know 1 von 22 15.06.2010 17:55 13 May 2010 Mark Nicolett, Kelly M. Kavanagh Gartner RAS Core Research Note G00176034 Broad adoption of SIEM technology is driven by compliance and security needs. New use cases

More information

Predicts 2004: Supplier Relationship Management

Predicts 2004: Supplier Relationship Management Strategic Planning, D. Hope-Ross Research Note 17 November 2003 Predicts 2004: Supplier Relationship Management Enterprises using technology to improve supplier relationships should pay attention to changes

More information

Welcome to Modulo Risk Manager Next Generation. Solutions for GRC

Welcome to Modulo Risk Manager Next Generation. Solutions for GRC Welcome to Modulo Risk Manager Next Generation Solutions for GRC THE COMPLETE SOLUTION FOR GRC MANAGEMENT GRC MANAGEMENT AUTOMATION EASILY IDENTIFY AND ADDRESS RISK AND COMPLIANCE GAPS INTEGRATED GRC SOLUTIONS

More information

Magic Quadrant for CRM Service Providers, North

Magic Quadrant for CRM Service Providers, North Magic Quadrant for CRM Service Providers, North America 30 August 2010 Matthew Goldman, Ed Thompson Gartner RAS Core Research Note G00205524 Demand for CRM project-based consulting and implementation services

More information

MarketScope for Wireless LAN Intrusion Prevention Systems

MarketScope for Wireless LAN Intrusion Prevention Systems MarketScope for Wireless LAN Intrusion Prevention Systems Gartner RAS Core Research Note G00159301, John Pescatore, John Girard, 9 July 2008, R2802 10022008 The WLAN intrusion prevention system market

More information

SAN Management Software Magic Quadrant

SAN Management Software Magic Quadrant Markets, C. DiCenzo, R. Paquet, N. Allen, R. Passmore Research Note 22 April 2003 SAN Management Software Magic Quadrant In the storage area network management software market, expect increased competition

More information

PLM Eclipses CPC as a Software Market

PLM Eclipses CPC as a Software Market Markets, M. Halpern, K. Brant Research Note 20 March 2003 PLM Eclipses CPC as a Software Market Gartner is retiring the Collaborative Product Commerce Magic Quadrant and introducing the Product Life Cycle

More information

Strategic Sourcing Magic Quadrant Criteria: An Explanation

Strategic Sourcing Magic Quadrant Criteria: An Explanation Markets, D. Hope-Ross, J. Woods Research Note 14 March 2003 Strategic Sourcing Magic Quadrant Criteria: An Explanation A new Gartner Magic Quadrant for strategic sourcing applications is being introduced.

More information

Magic Quadrant for Storage Professional and Support Services

Magic Quadrant for Storage Professional and Support Services Magic Quadrant for Storage Professional and Support Services Gartner RAS Core Research Note G00157182, Adam W. Couture, Robert E. Passmore, 30 July 2008 Gartner evaluates storage service providers and

More information

The Magic Quadrant Framework

The Magic Quadrant Framework Markets, B. Eisenfeld, F. Karamouzis Research Note 14 November 2002 Americas CRM ESPs: 2003 Magic Quadrant Criteria Gartner has developed high-level evaluation criteria for the 2003 Americas customer relationship

More information

Magic Quadrant for Higher Education Administrative Suites, 2005

Magic Quadrant for Higher Education Administrative Suites, 2005 Industry Research Publication Date: 21 November 2005 ID Number: G00131715 Magic Quadrant for Higher Education Administrative Suites, 2005 Marti Harris, Michael Zastrocky With Oracle's acquisition of PeopleSoft,

More information

Magic Quadrant for Application Platform Suites, 2Q03

Magic Quadrant for Application Platform Suites, 2Q03 Markets, Y. Natis, M. Pezzini, G. Phifer, C. Haight, M. Driver Research Note 5 May 2003 Magic Quadrant for Application Platform Suites, 2Q03 Application platform suites are incrementally assembled or bought

More information

The Five Competencies of MRM 'Re-' Defined

The Five Competencies of MRM 'Re-' Defined Research Publication Date: 14 March 2008 ID Number: G00155835 The Five Competencies of MRM 'Re-' Defined Kimberly Collins This research details the five key competencies of marketing resource management

More information

Magic Quadrant for Data Center Outsourcing, 4Q03

Magic Quadrant for Data Center Outsourcing, 4Q03 Markets, R. Matlus, W. Maurer, L. Scardino, B. Caldwell Research Note 12 November 2003 Magic Quadrant for Data Center Outsourcing, 4Q03 Gartner's positioning of the 14 external service providers in the

More information

MarketScope for Automated Document Factory 2.0 Software

MarketScope for Automated Document Factory 2.0 Software MarketScope for Automated Document Factory 2.0 Software Gartner RAS Core Research Note G00163260, Pete Basiliere, Ken Weilerstein, 2 December 2008, R3001 04132009 Automated Document Factory 2.0 software

More information

SIEM and IAM Technology Integration

SIEM and IAM Technology Integration SIEM and IAM Technology Integration Gartner RAS Core Research Note G00161012, Mark Nicolett, Earl Perkins, 1 September 2009, RA3 09302010 Integration of identity and access management (IAM) and security

More information

Magic Quadrant for the IT Service Desk

Magic Quadrant for the IT Service Desk Magic Quadrant for the IT Service Desk Gartner RAS Core Research Note G00160687, David M. Coyle, Kris Brittain, 4 November 2008, RA 11132009 IT service desk tools and best practices continue to be an area

More information

Magic Quadrant for Security Information and Event Management

Magic Quadrant for Security Information and Event Management Magic Quadrant for Security Information and Event Management Gartner RAS Core Research Note G00156945, Mark Nicolett, Kelly M. Kavanagh, 8 May 2008, R2725 05092009 Broad adoption of SIEM technology is

More information

Magic Quadrant for E-Mail Active Archiving

Magic Quadrant for E-Mail Active Archiving Magic Quadrant for E-Mail Active Archiving Gartner RAS Core Research Note G00157611, Carolyn DiCenzo, Kenneth Chin, 20 May 2008, RA2 05292009 E-mail active archiving products continue to add functionality

More information

MarketScope for Vulnerability Assessment

MarketScope for Vulnerability Assessment Page 1 of 9 MarketScope for Vulnerability Assessment 17 February 2010 Kelly M. Kavanagh, Mark Nicolett, John Pescatore Gartner RAS Core Research Note G00173772 The evolution of the vulnerability assessment

More information

MarketScope for Vulnerability Assessment

MarketScope for Vulnerability Assessment Page 1 of 9 MarketScope for Vulnerability Assessment 17 February 2010 Kelly M. Kavanagh, Mark Nicolett, John Pescatore Gartner RAS Core Research Note G00173772 The evolution of the vulnerability assessment

More information

Outlook for the CRM Software Market: Trends and Forecast (Executive Summary) Executive Summary

Outlook for the CRM Software Market: Trends and Forecast (Executive Summary) Executive Summary Outlook for the CRM Software Market: Trends and Forecast (Executive Summary) Executive Summary Publication Date: October 30, 2002 Authors Thomas Topolinski Chad Eschinger Pranav Kumar This document has

More information

Management Update: CRM Success Lies in Strategy and Implementation, Not Software

Management Update: CRM Success Lies in Strategy and Implementation, Not Software IGG-03122003-01 D. Hagemeyer, S. Nelson Article 12 March 2003 Management Update: CRM Success Lies in Strategy and Implementation, Not Software A customer relationship management (CRM) package doesn t ensure

More information

IT Governance, Risk and Compliance (GRC) : A Strategic Priority. Joerg Asma

IT Governance, Risk and Compliance (GRC) : A Strategic Priority. Joerg Asma IT Governance, Risk and Compliance (GRC) : A Strategic Priority Joerg Asma Agenda Introductions An Overview of IT Governance Risk & Compliance (IT-GRC) The Value Proposition Implementing an IT-GRC Program

More information

Magic Quadrant for Security Information and Event Management

Magic Quadrant for Security Information and Event Management Magic Quadrant for Security Information and Event Management Gartner RAS Core Research Note G00212454, Mark Nicolett, Kelly M. Kavanagh, 12 May 2011, RA 1-2494611471 05132012 Broad adoption of SIEM technology

More information

Strategies and Best Practices to Implement a Successful Data Loss Prevention Program Sebastian Brenner, CISSP

Strategies and Best Practices to Implement a Successful Data Loss Prevention Program Sebastian Brenner, CISSP Strategies and Best Practices to Implement a Successful Data Loss Prevention Program Sebastian Brenner, CISSP Principal Systems Engineer Symantec LAMC Agenda 1 What DLP is and its purpose 2 Challenges

More information

CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes.

CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes. TECHNOLOGY BRIEF: REDUCING COST AND COMPLEXITY WITH GLOBAL GOVERNANCE CONTROLS CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes. Table of Contents Executive

More information

Managing IT Risks During Cost-Cutting Periods

Managing IT Risks During Cost-Cutting Periods Research Publication Date: 22 October 2008 ID Number: G00162359 Managing IT Risks During Cost-Cutting Periods Mark Nicolett, Paul E. Proctor, French Caldwell To provide visibility into increased risks

More information

Management Update: Gartner s Large-Enterprise HRMS Magic Quadrant for 2002

Management Update: Gartner s Large-Enterprise HRMS Magic Quadrant for 2002 IGG-10232002-03 J. Holincheck Article 23 October 2002 Management Update: Gartner s Large-Enterprise HRMS Magic Quadrant for 2002 The market for large-enterprise human resources management system (HRMS)

More information

Defining the PLM Magic Quadrant by Criteria and Use. We provide the methodology used in developing our product life cycle management Magic Quadrant.

Defining the PLM Magic Quadrant by Criteria and Use. We provide the methodology used in developing our product life cycle management Magic Quadrant. Markets, M. Halpern Research Note 18 March 2003 Defining the PLM Magic Quadrant by Criteria and Use We provide the methodology used in developing our product life cycle management Magic Quadrant. Core

More information

Document Management Systems for Legal

Document Management Systems for Legal Document Management Systems for Legal May 2013 HYPERION GLOBAL PARTNERS THREE SUGAR CREEK CENTER, STE 100 SUGAR LAND, TEXAS 77478 www.hyperiongp.com www.hgpresearch.com A T L A N T A C H I C A G O D A

More information

By 2007, 80 percent of enterprise communications purchase decisions will require support for unified communications (0.6 probability).

By 2007, 80 percent of enterprise communications purchase decisions will require support for unified communications (0.6 probability). Page 1 of 5 Magic Quadrant for Unified Communications, 2005 14 February 2005 Bern Elliot Steve Blood Drew Kraus Source: Gartner Note Number: G00125707 Unified communications technology and applications

More information

Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms

Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms Seite 1 von 13 Magic Quadrant for Enterprise Governance, Risk and Compliance Platforms 24 September 2013 ID:G00245773 Analyst(s): French Caldwell, John A. Wheeler VIEW SUMMARY The enterprise GRC platform

More information

How to Develop an Effective Vulnerability Management Process

How to Develop an Effective Vulnerability Management Process Research Publication Date: 1 March 2005 ID Number: G00124126 How to Develop an Effective Vulnerability Management Process Mark Nicolett IT organizations should develop vulnerability management processes

More information

Magic Quadrant for Storage Services, 2Q05 25 May 2005 Adam W. Couture Robert E. Passmore

Magic Quadrant for Storage Services, 2Q05 25 May 2005 Adam W. Couture Robert E. Passmore Magic Quadrant for Storage Services, 2Q05 25 May 2005 Adam W. Couture Robert E. Passmore Source: Gartner Note Number: G00127958 Leading storage service providers in North America are executing on clear

More information

Auditing Standard 5- Effective and Efficient SOX Compliance

Auditing Standard 5- Effective and Efficient SOX Compliance Auditing Standard 5- Effective and Efficient SOX Compliance September 6, 2007 Presented to: The Dallas Chapter of the Institute of Internal Auditors These slides are incomplete without the benefit of the

More information

Magic Quadrant for Customer Data-Mining Applications

Magic Quadrant for Customer Data-Mining Applications Magic Quadrant for Customer Data-Mining Applications Gartner RAS Core Research Note G00158953, Gareth Herschel, 1 July 2008, R2800 07092009 SAS and SPSS remain the leading vendors in the customer datamining

More information

Magic Quadrant for Energy and Utilities Enterprise Asset Management Software

Magic Quadrant for Energy and Utilities Enterprise Asset Management Software Magic Quadrant for Energy and Utilities Enterprise Asset Management Software 29 September 2014 ID:G00263205 Analyst(s): Leif Eriksen, Kristian Steenstrup VIEW SUMMARY For energy and utility (including

More information

Responsible Vulnerability Disclosure: Guidance for Researchers, Vendors and End Users

Responsible Vulnerability Disclosure: Guidance for Researchers, Vendors and End Users Research Publication Date: 17 October 2006 ID Number: G00144061 Responsible Vulnerability Disclosure: Guidance for Researchers, Vendors and End Users Amrit T. Williams, John Pescatore, Paul E. Proctor

More information

Magic Quadrant for IT Service Support

Magic Quadrant for IT Service Support Page 1 of 8 Magic Quadrant for IT Service Support Management Tools 20 August 2013 ID:G00248914 Analyst(s): Jarod Greene, Jeffrey M. Brooks VIEW SUMMARY IT service support management tools go beyond traditional

More information

8 Key Requirements of an IT Governance, Risk and Compliance Solution

8 Key Requirements of an IT Governance, Risk and Compliance Solution 8 Key Requirements of an IT Governance, Risk and Compliance Solution White Paper: IT Compliance 8 Key Requirements of an IT Governance, Risk and Compliance Solution Contents Introduction............................................................................................

More information

Magic Quadrant for Content-Aware Data Loss Prevention

Magic Quadrant for Content-Aware Data Loss Prevention Magic Quadrant for Content-Aware Data Loss Prevention Gartner RAS Core Research Note G00200788, Paul E. Proctor, Eric Ouellet, 2 June 2010, V2 RA2 12062010 The enterprise content-aware data loss prevention

More information

Management Update: The Eight Building Blocks of CRM

Management Update: The Eight Building Blocks of CRM IGG-06252003-01 S. Nelson Article 25 June 2003 Management Update: The Eight Building Blocks of CRM Customer relationship management (CRM) represents the key business strategy that will determine successful

More information

Security and Identity Management Auditing Converge

Security and Identity Management Auditing Converge Research Publication Date: 12 July 2005 ID Number: G00129279 Security and Identity Management Auditing Converge Earl L. Perkins, Mark Nicolett, Ant Allan, Jay Heiser, Neil MacDonald, Amrit T. Williams,

More information

Q&A: The Many Aspects of Private Cloud Computing

Q&A: The Many Aspects of Private Cloud Computing Research Publication Date: 22 October 2009 ID Number: G00171807 Q&A: The Many Aspects of Private Cloud Computing Thomas J. Bittman Cloud computing is at the Peak of Inflated Expectations on the Gartner

More information

Business Applications and Infrastructure Entwined

Business Applications and Infrastructure Entwined Markets, S. Hayward, B. Burton, J. Comport, Y. Genovese, T. Bittman Research Note 9 July 2003 Business and Infrastructure Entwined Oracle's bid for PeopleSoft encompasses more than applications. It illustrates

More information

Key Issues for Identity and Access Management, 2008

Key Issues for Identity and Access Management, 2008 Research Publication Date: 7 April 2008 ID Number: G00157012 for Identity and Access Management, 2008 Ant Allan, Earl Perkins, Perry Carpenter, Ray Wagner Gartner identity and access management research

More information

Magic Quadrant for Integrated Document Management, 2003

Magic Quadrant for Integrated Document Management, 2003 Magic Quadrant for Integrated Document Management, 2003 Document management has moved to the forefront of many enterprises' purchasing lists. Our 2003 Magic Quadrant explains the complexities of the integrated

More information

MarketScope for Vulnerability Assessment

MarketScope for Vulnerability Assessment MarketScope for Vulnerability Assessment 5 April 2011 Kelly M. Kavanagh, Mark Nicolett Gartner Research Note G00211846 Vulnerability assessment vendors compete on price, scan and asset management, configuration

More information

Key Issues for Business Intelligence and Performance Management Initiatives, 2008

Key Issues for Business Intelligence and Performance Management Initiatives, 2008 Research Publication Date: 14 March 2008 ID Number: G00156014 Key Issues for Business Intelligence and Performance Management Initiatives, 2008 Kurt Schlegel The Business Intelligence and Performance Management

More information

SSL VPN 1H03 Magic Quadrant Evaluation Criteria

SSL VPN 1H03 Magic Quadrant Evaluation Criteria Markets, J. Girard Research Note 8 April 2003 SSL VPN 1H03 Magic Quadrant Evaluation Criteria Secure Sockets Layer virtual private networks are simple, portable and convenient alternatives to IPsec, and

More information

Leveraging a Maturity Model to Achieve Proactive Compliance

Leveraging a Maturity Model to Achieve Proactive Compliance Leveraging a Maturity Model to Achieve Proactive Compliance White Paper: Proactive Compliance Leveraging a Maturity Model to Achieve Proactive Compliance Contents Introduction............................................................................................

More information

Magic Quadrant for Enterprise Asset Management for Manufacturing

Magic Quadrant for Enterprise Asset Management for Manufacturing Magic Quadrant for Enterprise Asset Management for Manufacturing Gartner Industry Research Note G00169941, Dan Miklovic, 9 September 2009, R3179 10182010 Manufacturing, by its very nature, relies on the

More information

Magic Quadrant for Oracle ERP Implementation Services, North America

Magic Quadrant for Oracle ERP Implementation Services, North America Magic Quadrant for Oracle ERP Implementation Services, North America Gartner RAS Core Research Note G00207427, Alex Soejarto, Susan Tan, 30 November 2010, RA2 03202011 The Magic Quadrant for Oracle ERP

More information

Magic Quadrant for Client Management Tools

Magic Quadrant for Client Management Tools G00247238 Magic Quadrant for Client Management Tools Published: 9 April 2013 Analyst(s): Terrence Cosgrove The client management tool market is maturing and evolving to adapt to consumerization, desktop

More information

Gartner MarketScope for DNS, DHCP and IP Address Management

Gartner MarketScope for DNS, DHCP and IP Address Management Gartner MarketScope for DNS, DHCP and IP Address Management 4 April 2012 ID:G00229075 Analyst(s): Lawrence Orans VIEW SUMMARY DNS, DHCP and IP address management solutions help improve network manageability

More information

EMEA CRM Analytics Suite Magic Quadrant 3Q02

EMEA CRM Analytics Suite Magic Quadrant 3Q02 Markets, J. Radcliffe, G. Herschel Research Note 26 September 2002 EMEA CRM Analytics Suite Magic Quadrant 3Q02 SAS Institute leverages its strength in analytics to take the lead in the immature CRM analytics

More information

Magic Quadrant for Content Monitoring and Filtering and Data Loss Prevention, 2Q07

Magic Quadrant for Content Monitoring and Filtering and Data Loss Prevention, 2Q07 Magic Quadrant for Content Monitoring and Filtering and Data Loss Prevention, 2Q07 Gartner RAS Core Research Note G00147610, Paul E. Proctor, Rich Mogull, Eric Ouellet, 13 April 2007, R2269 04192008 The

More information

CLOUDSCAPE. IT SERVICES Tooling up for ITaaS KEY FINDINGS

CLOUDSCAPE. IT SERVICES Tooling up for ITaaS KEY FINDINGS IT SERVICES Tooling up for ITaaS IT as a service (ITaaS) is an operational model where the enterprise IT department acts and operates as a distinct business entity, creating services for the other lines

More information

Economics of the Cloud: Business Value Assessments

Economics of the Cloud: Business Value Assessments Economics of the Cloud: Business Value Assessments Gartner RAS Core Research Note G00168554, Joseph Feiman, David W. Cearley, 25 September 2009, RA7 042010 This research defines and quantitatively assesses

More information

Module 6 Essentials of Enterprise Architecture Tools

Module 6 Essentials of Enterprise Architecture Tools Process-Centric Service-Oriented Module 6 Essentials of Enterprise Architecture Tools Capability-Driven Understand the need and necessity for a EA Tool IASA Global - India Chapter Webinar by Vinu Jade

More information

Vertical Data Warehouse Solutions for Financial Services

Vertical Data Warehouse Solutions for Financial Services Decision Framework, M. Knox Research Note 24 July 2003 Vertical Data Warehouse Solutions for Financial Services Packaged DW financial services solutions differ in degree of and approach to verticalization,

More information

Patch management point solution. Platform. Patch Management Point Solution

Patch management point solution. Platform. Patch Management Point Solution Markets, R. Colville, M. Nicolett Research Note 18 March 2003 Patch Management: Identifying the Vendor Landscape As the importance of patch management increases, it is important to understand the limitations

More information

Understanding Vulnerability Management Life Cycle Functions

Understanding Vulnerability Management Life Cycle Functions Research Publication Date: 24 January 2011 ID Number: G00210104 Understanding Vulnerability Management Life Cycle Functions Mark Nicolett We provide guidance on the elements of an effective vulnerability

More information

IT asset management (ITAM) will proliferate in midsize and large companies.

IT asset management (ITAM) will proliferate in midsize and large companies. Research Publication Date: 2 October 2008 ID Number: G00161024 Trends on Better IT Asset Management Peter Wesche New exiting trends will lead to a higher adoption of asset management methodologies. Tighter

More information

Overcoming the Gap Between Business Intelligence and Decision Support

Overcoming the Gap Between Business Intelligence and Decision Support Research Publication Date: 9 April 2009 ID Number: G00165169 Overcoming the Gap Between Business Intelligence and Decision Support Rita L. Sallam, Kurt Schlegel Although the promise of better decision

More information

Agenda Overview for Social Marketing, 2015

Agenda Overview for Social Marketing, 2015 G00270737 Agenda Overview for Social Marketing, 2015 Published: 19 December 2014 Analyst(s): Julie Hopkins Social marketing programs are maturing; executives increasingly expect ROI to follow social marketing

More information

Magic Quadrant for Security Information and Event Management

Magic Quadrant for Security Information and Event Management Magic Quadrant for Security Information and Event Management Gartner RAS Core Research Note G00176034, Mark Nicolett, Kelly M. Kavanagh, 13 May 2010, RA1 05212011 Broad adoption of SIEM technology is driven

More information