<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Greg Young</title>
	<atom:link href="http://blogs.gartner.com/greg_young/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.gartner.com/greg_young</link>
	<description>A member of the Gartner Blog Network</description>
	<lastBuildDate>Fri, 11 Feb 2011 18:00:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>Don&#8217;t Forget Your Security Bingo Card For the RSA Conference Next Week!</title>
		<link>http://blogs.gartner.com/greg_young/2011/02/11/dont-forget-your-security-bingo-card-for-the-rsa-conference-next-week/</link>
		<comments>http://blogs.gartner.com/greg_young/2011/02/11/dont-forget-your-security-bingo-card-for-the-rsa-conference-next-week/#comments</comments>
		<pubDate>Fri, 11 Feb 2011 18:00:06 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2011/02/11/dont-forget-your-security-bingo-card-for-the-rsa-conference-next-week/</guid>
		<description><![CDATA[The RSA Conference is the largest security event of the year, and a great venue to catch up with colleagues and see firsthand what security technology is popular.&#160; Here is this year’s lighthearted bingo card you can take with you onto the showfloor.&#160; Safe travels:&#160; &#160;]]></description>
			<content:encoded><![CDATA[<p>The RSA Conference is the largest security event of the year, and a great venue to catch up with colleagues and see firsthand what security technology is popular.&nbsp; Here is this year’s lighthearted bingo card you can take with you onto the showfloor.&nbsp; Safe travels:&nbsp; </p>
<p>&nbsp;</p>
<p><a href="http://blogs.gartner.com/greg_young/files/2011/02/Bingo1.jpg"><img style="border-bottom: 0px;border-left: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="Bingo" src="http://blogs.gartner.com/greg_young/files/2011/02/Bingo_thumb1.jpg" width="631" height="478"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2011/02/11/dont-forget-your-security-bingo-card-for-the-rsa-conference-next-week/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security Snuffleupagus Will Be Seen Only By Vendors</title>
		<link>http://blogs.gartner.com/greg_young/2011/01/25/security-snuffleupagus-will-be-seen-only-by-vendors/</link>
		<comments>http://blogs.gartner.com/greg_young/2011/01/25/security-snuffleupagus-will-be-seen-only-by-vendors/#comments</comments>
		<pubDate>Tue, 25 Jan 2011 19:32:19 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2011/01/25/security-snuffleupagus-will-be-seen-only-by-vendors-at-rsa/</guid>
		<description><![CDATA[You remember Mr. Snuffleupagus? On Sesame Street, only Big Bird could see him and was frustrated when others couldn&#8217;t.  For the rest of the year we&#8217;ll be hearing from sellers about APT &#8211; Advanced Persistent Threats.  This is a problem because this isn&#8217;t anything new &#8211; threats have always been advanced and persistent, otherwise they [...]]]></description>
			<content:encoded><![CDATA[<p>You remember <a href="http://en.wikipedia.org/wiki/Snuffleupagus">Mr. Snuffleupagus</a>? On Sesame Street, only Big Bird could see him and was frustrated when others couldn&#8217;t.  For the rest of the year we&#8217;ll be hearing from sellers about APT &#8211; Advanced Persistent Threats.  This is a problem because this isn&#8217;t anything new &#8211; threats have always been advanced and persistent, otherwise they aren&#8217;t threats.  New rotary phone based attacks and giant meteors.. you get the idea.</p>
<p>Is all well in security? No &#8211; the opposite.  IT security goes through linked sine waves where we are trailing the threat (where we are now) and where we catch up to the threat.  Virtualization, mobilization, socialization, and a lot of other &#8216;-ization&#8217; trends and technologies have security in catch-up mode to the stuff we need to secure. There doesn&#8217;t seem to be any shortage of bad things so making up new ones is over-FUD.  There are different kinds of botnets, so let&#8217;s call them that.  Anything else, and it is likely something no one but the seller sees.</p>
<p>And yes, on the TV show, Mr Snuffleupagus was real, but Big Bird, Sesame Street aren&#8217;t.  They were people in suits.. like sellers at trade shows  <img src='http://blogs.gartner.com/greg_young/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2011/01/25/security-snuffleupagus-will-be-seen-only-by-vendors/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New Network Intrusion Prevention System Magic Quadrant Published</title>
		<link>http://blogs.gartner.com/greg_young/2010/12/06/new-network-intrusion-prevention-system-magic-quadrant-published/</link>
		<comments>http://blogs.gartner.com/greg_young/2010/12/06/new-network-intrusion-prevention-system-magic-quadrant-published/#comments</comments>
		<pubDate>Mon, 06 Dec 2010 21:33:00 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2010/12/06/new-network-intrusion-prevention-system-magic-quadrant-published/</guid>
		<description><![CDATA[The updated Network IPS MQ was published today, for our clients.&#160; The IPS market is driven mostly by the adjacent firewall market.&#160; Firewall vendors have in the past not been able to deliver IPS within the firewall that is both integrated and competitive with stand-alone IPS.&#160; This edition of the IPS MQ highlights that as [...]]]></description>
			<content:encoded><![CDATA[<p>The updated <a href="http://www.gartner.com/DisplayDocument?doc_cd=208628">Network IPS MQ</a> was published today, for our clients.&nbsp; </p>
<p>The IPS market is driven mostly by the adjacent firewall market.&nbsp; Firewall vendors have in the past not been able to deliver IPS within the firewall that is both integrated and competitive with stand-alone IPS.&nbsp; This edition of the IPS MQ highlights that as the IPS market has expanded into a due diligence market, the pace of innovation of firewalls will determine IPS&#8217; future.&nbsp; </p>
<p>Firewall vendors need next generation firewall features of which quality IPS is a mandatory, and IPS vendors need to decide whether they move into the anchor point of the enterprise firewall market and take on the incumbents. The additional theme is success in acquisition &#8211; both in making them and in being acquired.</p>
<p>A great companion document is &#8220;<a href="http://www.gartner.com/DisplayDocument?doc_cd=154752">Magic Quadrants and MarketScopes: How Gartner Evaluates Vendors Within a Market</a>&#8220;. </p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2010/12/06/new-network-intrusion-prevention-system-magic-quadrant-published/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Canadian Perspective: Gartner Privacy Survey Research Note</title>
		<link>http://blogs.gartner.com/greg_young/2010/11/10/canadian-perspective-gartner-privacy-survey-research-note/</link>
		<comments>http://blogs.gartner.com/greg_young/2010/11/10/canadian-perspective-gartner-privacy-survey-research-note/#comments</comments>
		<pubDate>Wed, 10 Nov 2010 20:46:10 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2010/11/10/canadian-perspective-gartner-privacy-survey-research-note/</guid>
		<description><![CDATA[&#160; Gartner recently conducted a series of surveys on privacy.&#160; For our clients, we have just published a research note with the data and our analysis on the Canadian segment of the survey.&#160;]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p>Gartner recently conducted a series of surveys on privacy.&nbsp; For our clients, we have just published a <a href="http://www.gartner.com/DisplayDocument?doc_cd=208564">research note with the data and our analysis</a> on the Canadian segment of the survey.&nbsp; </p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2010/11/10/canadian-perspective-gartner-privacy-survey-research-note/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Q&amp;A: Is It More Secure to Use Firewalls From Two Different Vendors?</title>
		<link>http://blogs.gartner.com/greg_young/2010/11/04/qa-is-it-more-secure-to-use-firewalls-from-two-different-vendors/</link>
		<comments>http://blogs.gartner.com/greg_young/2010/11/04/qa-is-it-more-secure-to-use-firewalls-from-two-different-vendors/#comments</comments>
		<pubDate>Thu, 04 Nov 2010 21:18:41 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2010/11/04/qa-is-it-more-secure-to-use-firewalls-from-two-different-vendors/</guid>
		<description><![CDATA[For our clients, we have an updated research piece on using more than one brand of firewall, including virtual network firewalls. This has been a continuing topic of inquiry, especially of late as DMZ designs are being refreshed to accommodate virtualization, changes in the data center, and especially as part of a mergers/acquisition.]]></description>
			<content:encoded><![CDATA[<p>For our clients, we have an <a href="http://www.gartner.com/DisplayDocument?doc_cd=208704">updated research piece</a> on using more than one brand of firewall, including virtual network firewalls.</p>
<p>This has been a continuing topic of inquiry, especially of late as DMZ designs are being refreshed to accommodate virtualization, changes in the data center, and especially as part of a mergers/acquisition.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2010/11/04/qa-is-it-more-secure-to-use-firewalls-from-two-different-vendors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WAFS: It&#8217;s The Buying Center, Silly</title>
		<link>http://blogs.gartner.com/greg_young/2010/08/12/wafs-its-the-buying-center-silly/</link>
		<comments>http://blogs.gartner.com/greg_young/2010/08/12/wafs-its-the-buying-center-silly/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 12:58:20 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2010/08/12/wafs-its-the-buying-center-silly/</guid>
		<description><![CDATA[Web Application Firewalls (WAF)Paraphrasing James Carville&#8217;s quote about the economy, WAFs are not ubiquitous because of the fragmented buying centers for them, silly, rather than any confusion over over the market name or concerns over false positives. WAFs are a high value safeguard for custom applications, but are held back because so many groups are [...]]]></description>
			<content:encoded><![CDATA[<p>Web Application Firewalls (WAF)<br />Paraphrasing James Carville&#8217;s quote about the economy, WAFs are not ubiquitous because of the fragmented buying centers for them, silly, rather than any confusion over over the market name or concerns over false positives.</p>
<p>WAFs are a high value safeguard for custom applications, but are held back because so many groups are potentially involved in the operation and buying of applications.&nbsp; Data center ops, server ops, appdev, application owners, security, network ops&#8230;&nbsp; Unlike other products like IPS which have usually two buying centers, there is a wide spread to which roles are involved in WAF.&nbsp; There will be some reduction in the number of buying centers, but as long as custom web applications are housed and delivered in this complex manner, don&#8217;t expect organizations to change to accommodate the safeguard. </p>
<p>And a moment of zen is me with James Carville.</p>
<p><a href="http://blogs.gartner.com/greg_young/files/2010/08/WindowsLiveWriterWAFSItsTheBuyingCenterSilly_7E0CIMGP1045.jpg"><img style="border-right: 0px;border-top: 0px;border-left: 0px;border-bottom: 0px" height="184" alt="IMGP1045" src="http://blogs.gartner.com/greg_young/files/2010/08/WindowsLiveWriterWAFSItsTheBuyingCenterSilly_7E0CIMGP1045_thumb.jpg" width="244" border="0"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2010/08/12/wafs-its-the-buying-center-silly/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Market Names</title>
		<link>http://blogs.gartner.com/greg_young/2010/07/23/market-names/</link>
		<comments>http://blogs.gartner.com/greg_young/2010/07/23/market-names/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 17:14:15 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2010/07/23/market-names/</guid>
		<description><![CDATA[WAF MARKETThe web application firewall market is challenged because of the multiple buying centers, and the competition with scanners.&#160; Not because of the name.&#160; GARTNER JOBS VIA TWITTERRT @cpettey: RT @Gartner_inc We&#8217;ve set up a twitter feed for new vacancies at #Gartner: it&#8217;s @Gartner_Jobs.&#160; Of course, also available at www.gartner.com]]></description>
			<content:encoded><![CDATA[<p>WAF MARKET<br />The web application firewall market is challenged because of the multiple buying centers, and the competition with scanners.&nbsp; Not because of the name.&nbsp; </p>
<p>GARTNER JOBS VIA TWITTER<br />RT @cpettey: RT @Gartner_inc We&#8217;ve set up a twitter feed for new vacancies at #Gartner: it&#8217;s @Gartner_Jobs.&nbsp; Of course, also available at <a href="http://www.gartner.com">www.gartner.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2010/07/23/market-names/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>APT Is A Four Letter Word</title>
		<link>http://blogs.gartner.com/greg_young/2010/07/21/apt-is-a-four-letter-word/</link>
		<comments>http://blogs.gartner.com/greg_young/2010/07/21/apt-is-a-four-letter-word/#comments</comments>
		<pubDate>Wed, 21 Jul 2010 15:35:19 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2010/07/21/apt-is-a-four-letter-word/</guid>
		<description><![CDATA[APT!I thought it was only security company names that were sounding like pharmaceuticals.&#160; Now new artificial terms are as well: &#8220;Advanced Persistent Threats&#8221; or APT (&#8220;if you think you have APT, contact your doctor &#8230;&#8221;).&#160; APT is valueless when viewed through the lens of relativism: when weren&#8217;t threats persistent or advanced?&#160; Yes, attacks that use [...]]]></description>
			<content:encoded><![CDATA[<p>APT!<br />I thought it was only security company names that were sounding like pharmaceuticals.&nbsp; Now new artificial terms are as well: &#8220;Advanced Persistent Threats&#8221; or APT (&#8220;if you think you have APT, contact your doctor &#8230;&#8221;).&nbsp; APT is valueless when viewed through the lens of relativism: when weren&#8217;t threats persistent or advanced?&nbsp; Yes, attacks that use multiple vectors are different but call them that.&nbsp; APT and BOO are synonyms.&nbsp; Threats continue to advance, are more persistent and don&#8217;t stand still &#8211; an artificial milestone is just artificial.</p>
<p>RETIREMENT<br />My old friend and colleague Mathew Soong has retired from Gartner Consulting: best wishes and I&#8217;ll miss you Mathew.&nbsp; Mathew wasn&#8217;t a security guy but I leaned a lot from him. The best memory I have is Mathew explaining the budget impediment of incumbent products, leaving such a small % to spend on new things.&nbsp; And if you spend that % on new things, that will leave less money next year for new things.</p>
<p>INFRASTRUCTURE PROTECTION HYPE CYCLE<br />The InfraPro HC is coming along well.&nbsp; We&#8217;re not seeing many new technologies added this year.&nbsp; </p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2010/07/21/apt-is-a-four-letter-word/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Good Book on ITSec?</title>
		<link>http://blogs.gartner.com/greg_young/2010/07/06/a-good-book-on-itsec/</link>
		<comments>http://blogs.gartner.com/greg_young/2010/07/06/a-good-book-on-itsec/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 10:52:21 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2010/07/06/a-good-book-on-itsec/</guid>
		<description><![CDATA[Computer security, like video games or golf, makes for a fascinating time, and dulls in the retelling.&#160; We&#8217;ve been punished from the start with War Games (yes it was a classic but it was silly) and then onto Firewall.&#160; It was a real surprise how much I enjoyed Fatal System Error by Joseph Menn.&#160; Not [...]]]></description>
			<content:encoded><![CDATA[<p>Computer security, like video games or golf, makes for a fascinating time, and dulls in the retelling.&nbsp; We&#8217;ve been punished from the start with <a href="http://www.imdb.com/title/tt0086567/">War Games</a> (yes it was a classic but it was silly) and then onto <a href="http://www.imdb.com/title/tt0408345/">Firewall</a>.&nbsp; </p>
<p>It was a real surprise how much I enjoyed <a href="http://www.amazon.com/Fatal-System-Error-Bringing-Internet/dp/1586487485">Fatal System Error</a> by Joseph Menn.&nbsp; Not just enjoyed, but informed.&nbsp; </p>
<p>I enjoyed speaking with Joseph at the Gartner Security Summit, and being able to say hi again to the primary subject of his book Barrett Lyon.&nbsp; Kudos to SecureWorks for having them both at their hospitality suite. </p>
<p>My recommended Computer Security Read for 2010.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2010/07/06/a-good-book-on-itsec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lawsuits In ITSec</title>
		<link>http://blogs.gartner.com/greg_young/2010/07/05/lawsuits-in-itsec/</link>
		<comments>http://blogs.gartner.com/greg_young/2010/07/05/lawsuits-in-itsec/#comments</comments>
		<pubDate>Mon, 05 Jul 2010 20:25:20 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2010/07/05/lawsuits-in-itsec/</guid>
		<description><![CDATA[At the recent Gartner IT Security Summit I had a conversation about geography and litigation.&#160; In North America, lawsuits around IT security companies and products are pretty frequent, let alone if those companies are public ones.&#160; Like it or not, it has become part of the background noise in threat defense that we have unfortunately [...]]]></description>
			<content:encoded><![CDATA[<p>At the recent Gartner IT Security Summit I had a conversation about geography and litigation.&nbsp; In North America, lawsuits around IT security companies and products are pretty frequent, let alone if those companies are public ones.&nbsp; Like it or not, it has become part of the background noise in threat defense that we have unfortunately become inured to &#8230; at least in North America.&nbsp; </p>
<p>In many other geographies lawsuits are uncommon and of a great concern.&nbsp; I often see competing vendors will often raise what are often trivial or nuisance suits as reason not to consider that solution.&nbsp; So sure vendor viability and serious suits are worth considering in a product selection, but like many things in life geography and context matter.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2010/07/05/lawsuits-in-itsec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

