<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Greg Young &#187; Security Research In Progress</title>
	<atom:link href="http://blogs.gartner.com/greg_young/category/security/security-research-in-progress/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.gartner.com/greg_young</link>
	<description>A member of the Gartner Blog Network</description>
	<lastBuildDate>Wed, 11 Nov 2009 14:42:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Do You Need One Firewall Vendor or Two?</title>
		<link>http://blogs.gartner.com/greg_young/2008/09/26/do-you-need-one-firewall-vendor-or-two/</link>
		<comments>http://blogs.gartner.com/greg_young/2008/09/26/do-you-need-one-firewall-vendor-or-two/#comments</comments>
		<pubDate>Fri, 26 Sep 2008 15:57:19 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Research In Progress]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2008/09/26/do-you-need-one-firewall-vendor-or-two/</guid>
		<description><![CDATA[A high number of client inquiries I receive are around DMZ redesign.&#160; This is the hardest task in network security you can undertake because there is no one-size-fits-all DMZ design and there are many moving parts in play.&#160; The good news is that getting the DMZ right will likely be one of the most beneficial [...]]]></description>
			<content:encoded><![CDATA[<p>A high number of client inquiries I receive are around DMZ redesign.&nbsp; This is the hardest task in network security you can undertake because there is no one-size-fits-all DMZ design and there are many moving parts in play.&nbsp; The good news is that getting the DMZ right will likely be one of the most beneficial undertakings in netsec, and makes so many other things across security and networking easier and cheaper.&nbsp; </p>
<p>One of the questions that comes up as part of DMZ design is&nbsp;is it best to have one firewall vendor (for simplicity of management) or two (to provide an overlap of protection in case one firewall has a vulnerability), and what are my peers doing on this topic?&nbsp; </p>
<p><a href="http://blogs.gartner.com/john_pescatore/">John Pescatore</a> and I have provided an update on this in a research note &ldquo;<a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=232&amp;mode=2&amp;PageID=466917&amp;resId=740613&amp;ref=Browse">Q&amp;A: Is It More Secure to Use Firewalls From Two Different Vendors</a>?&rdquo;</p>
<p><img alt="Overview" src="http://blogs.gartner.com/greg_young/files/2008/09/overview-small.jpg" border="0" />&nbsp;<font size="1"><em>The </em></font><a href="http://stonewall.nist.gov/Default.htm"><font size="1"><em>NIST stone test wall</em></font></a><font size="1"><em> in Gaithersburg, Md.</em></font><font color="#000000"></p>
<p>&nbsp;</p>
<p></font>
<div class="bjtags">Tags:  <a rel="tag" href="http://technorati.com/tag/firewall">firewall</a>, <a rel="tag" href="http://technorati.com/tag/Gartner">Gartner</a>, <a rel="tag" href="http://technorati.com/tag/security">security</a></div>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2008/09/26/do-you-need-one-firewall-vendor-or-two/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>In The Works: Hype Cycle for Infrastructure Protection 2008</title>
		<link>http://blogs.gartner.com/greg_young/2008/09/14/in-the-works-hype-cycle-for-infrastructure-protection-2008/</link>
		<comments>http://blogs.gartner.com/greg_young/2008/09/14/in-the-works-hype-cycle-for-infrastructure-protection-2008/#comments</comments>
		<pubDate>Sun, 14 Sep 2008 18:33:46 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Security Research In Progress]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2008/09/14/in-the-works-hype-cycle-for-infrastructure-protection-2008/</guid>
		<description><![CDATA[This year it was my turn to lead the update to the Hype Cycle for Infrastructure Protection. (HCIP to make your reading easier).&#160; There are 3 HCs underway in security right now: HC for&#160;Data and Application led by analyst Jay Heiser, the HCIP, and an &#8216;umbrella&#8217; HC for Information Security led by Managing VP Ray [...]]]></description>
			<content:encoded><![CDATA[<p>This year it was my turn to lead the update to the Hype Cycle for Infrastructure Protection. (HCIP to make your reading easier).&nbsp; There are 3 HCs underway in security right now: HC for&nbsp;Data and Application led by analyst Jay Heiser, the HCIP, and an &lsquo;umbrella&rsquo; HC for Information Security led by Managing VP Ray Wagner.&nbsp; This year&rsquo;s HCIP will reflect the convergence of only a few safeguards and the introduction of new safeguards as a result of the evolving threat.</p>
<p>The HCIP has 30 Technology Profiles (TP) or &lsquo;dots&rsquo; representing a&nbsp;safeguard that warrants incusion. Each TP has an author and may have co-authors.&nbsp; Each TP is reviewed extensively by individual peer review, group review, management review, editorial review, and review by the other HC leads&nbsp;&nbsp;&hellip;.&nbsp; About 12 analysts are listed as author in the HCIP, and about another&nbsp;10 people are handling quality, production, graphics,&nbsp;and editorial steps.&nbsp;&nbsp;I wanted to blog this to give a glimpse into the degree of rigor that goes into a research note and that no note is&nbsp;a&nbsp;solo effort &ndash;&nbsp;even the shortest document, a First Take, has a team&nbsp;of review and fact-checking behind it although only the&nbsp;primary author&rsquo;s name may appear on it.&nbsp; </p>
<p>If you want to get some more detailed information on HCs, Jackie Fenn and Mark Raskino have an <a href="http://blogs.gartner.com/hypecyclebook/">HC blog</a> and an upcoming <a href="http://harvardbusinessonline.hbsp.harvard.edu/b02/en/common/item_detail.jhtml;jsessionid=05B0UFRTVHOBCAKRGWDR5VQBKE0YIISW?id=2110&amp;referral=2340">book </a>entitled &ldquo;Mastering the Hype Cycle&rdquo;. </p>
<p>After so much effort to get it right, it is still just a snapshot in time.&nbsp; If you are basing a significant IT decision on any research piece, or just have a question about what analysis went into an element of it,&nbsp;I encourage our customers to schedule an inquiry (no matter how brief the question) and speak to the author.&nbsp; We&nbsp;always have&nbsp;more or more timely information available than what made it into a research note, and we can filter the analysis to your specific use-case.&nbsp; </p>
<p>Along with my colleague <a href="http://blogs.gartner.com/john_pescatore/">John Pescatore</a>, I am also working on the Magic Quadrant (MQ) for Enterprise Network Firewalls.&nbsp; This MQ is proceeding along well.&nbsp; More on the MQ in upcoming blog entries.&nbsp; </p>
<p>&nbsp;</p>
<div class="bjtags">Tags:  <a rel="tag" href="http://technorati.com/tag/Gartner">Gartner</a>, <a rel="tag" href="http://technorati.com/tag/Hype+Cycle">Hype+Cycle</a>, <a rel="tag" href="http://technorati.com/tag/Security">Security</a></div>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2008/09/14/in-the-works-hype-cycle-for-infrastructure-protection-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
