Smart Shopper Rating Identity Management Vendors Dr David

  • Slides: 32
Download presentation
Smart Shopper: Rating Identity Management Vendors Dr. David Taylor The. Info. Pro Security Study

Smart Shopper: Rating Identity Management Vendors Dr. David Taylor The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Information Security Studies Overview Ø Studies: Wave 1: Wave 2: Wave 3: Wave 4:

Information Security Studies Overview Ø Studies: Wave 1: Wave 2: Wave 3: Wave 4: Winter 2003 Summer 2003 Winter/Spring 2004 Fall 2004 Ø Population: Wave 1: Wave 2: Wave 3: Wave 4: 164 175 198 220+ Ø Content: Ratings and commentary on vendors and products in 15 information security market sectors, including: - Anti-Virus, Anti-Spam (including Anti-Phishing) - Firewalls (including Application Proxy, Personal, Stateful and Packet) - Identity Management (including Provisioning, SSO and Directory) - Intrusion Detection & Prevention (including Host and Network-based) - Security Management (including SIM, ESM and SEM) - Security Services (including Vulnerability Assessment and Audit Services) - Wireless Security (including Wi. Fi and WLANs) - Management Tools (including Patch Management and Mgmt Dashboards) - Access Control (including Tokens, Certificates and Encryption) - Security Appliances The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Emerging Trends From Security Wave 3 Data l. F 1000 and SME spending focused

Emerging Trends From Security Wave 3 Data l. F 1000 and SME spending focused on different security sectors - F 1000 complexity is driving infrastructure buildup; SMEs still much more focused on perimeter l. Infrastructure will continue to dominate overall spending through the end of 2005 - Infrastructure-related projects and technologies make up 8 of the top 15 technology priorities l. Enterprise Security Management (ESM) is gaining momentum - Users are seeking more “architected” solutions; integration becoming major criterion l. Spending on tactical security products narrowing to “visible” problems - Anti-SPAM and Patch Management are high “tactical” priorities The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Industry Breakdown The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161

Industry Breakdown The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Revenue Breakdown The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161

Revenue Breakdown The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Number of Enterprise Employees Breakdown The. Info. Pro Security Study – Wave 3 n=198;

Number of Enterprise Employees Breakdown The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Business Drivers or Pain Points Heavy driver of Identity Management interest The. Info. Pro

Business Drivers or Pain Points Heavy driver of Identity Management interest The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Top 2 Most Valuable Technologies for Protecting Information How regulations drive Identity Management SSO

Top 2 Most Valuable Technologies for Protecting Information How regulations drive Identity Management SSO Still “Emerging” The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Identity Management Deployment Status The. Info. Pro Security Study – Wave 3 n=198; Wave

Identity Management Deployment Status The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Identity Management Technologies are “Hot” The. Info. Pro Security Study – Wave 3 n=198;

Identity Management Technologies are “Hot” The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Identity Management Technologies In Use and In Plan Users consider Active Directory a Meta.

Identity Management Technologies In Use and In Plan Users consider Active Directory a Meta. Directory 39% say no need for integrated ID Mgmt Suite The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Top 10 Enterprise Meta Directory Vendors The “Top 10” vendors were those named by

Top 10 Enterprise Meta Directory Vendors The “Top 10” vendors were those named by users (without prompting) as in use or being considered for each project or technology The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Top 10 Identity Management – Self Service Vendors IBM growth opportunity Other Vendors Being

Top 10 Identity Management – Self Service Vendors IBM growth opportunity Other Vendors Being Considered Include: Citrix SA Sentillion CA Courion Nortel Symantec Cisco M-Tech The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Top 10 Single Sign-On Vendors Rare lead by a specialty vendor Other Vendors Being

Top 10 Single Sign-On Vendors Rare lead by a specialty vendor Other Vendors Being Considered Include: Aventail Courion F 5 Networks M-Tech Sun Cisco BMC Open Source Qwest Schlumberger. Sema The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Top 10 Identity Management – User Provisioning Vendors More a process than a product

Top 10 Identity Management – User Provisioning Vendors More a process than a product IBM growth opportunity Other Vendors Being Considered Include: Cisco M-Tech RSA Bind. View Qwest Abridean The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Top 10 Identity Management Suite Vendors Surprisingly, not being considered for new ID Mgmt

Top 10 Identity Management Suite Vendors Surprisingly, not being considered for new ID Mgmt Suite deployments Other Vendors Being Considered Include: Cisco M-Tech RSA Bind. View Qwest Schlumberger. Sema The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Identity Management Project Status Commentary “We are having a hard time justifying [ID Management

Identity Management Project Status Commentary “We are having a hard time justifying [ID Management – Self Service] to ourselves. It saves some time for us, but we haven't seen a value to the information we gain through Self Service. ” (Sr. Security Specialist – F 1000 Financial Services Company) “We're always looking at [ID Management – Self Service] vendors. There are two reasons why we have not done this so far: (1) the existing solution satisfies requirements so far and (2) because our homegrown solution is widely distributed. It's hard to find a third-party product that can handle the wide distribution. ” (Business Manager – IT Security – F 100 Financial Services Company) The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Identity Mgmt Customer Planned Spending Change for 2005 The. Info. Pro Security Study –

Identity Mgmt Customer Planned Spending Change for 2005 The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Vendor/Product Customer Ratings – 8 Open-ended Questions Is this vendor a strategic or a

Vendor/Product Customer Ratings – 8 Open-ended Questions Is this vendor a strategic or a tactical vendor for your organization? What are this vendor's (or product's) top 1 -2 strengths, and why? What are this vendor's (or product's) top 1 -2 weaknesses? What feature(s) would you most like to see added to this product? About how much money did your enterprise spend with this vendor (for security) during 2004? Approximately how much (what percentage) will your spending with this vendor change next year? "Are you planning to switch from this vendor to another vendor? If so, to which vendor? " Would you consider outsourcing this to a managed service provider? If so, what vendor would you consider first? The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Vendor/Product Customer Ratings – 15 Ratings Criteria The company's brand or reputation Technical innovation

Vendor/Product Customer Ratings – 15 Ratings Criteria The company's brand or reputation Technical innovation Management's strategic vision Competitive positioning of the products or services Interoperability with other vendors Interoperability within the vendor's product line Product features / functionality Product manageability Product reliability Product quality Value for the money Sales force quality Delivery of products as promised Quality of technical support Ease of doing business with the company The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Wave 4 Identity Management Strategic Ratings Lots of commentary The. Info. Pro Security Study

Wave 4 Identity Management Strategic Ratings Lots of commentary The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Wave 4 Identity Management Operational Ratings Lots of commentary The. Info. Pro Security Study

Wave 4 Identity Management Operational Ratings Lots of commentary The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

ID Mgmt Customer Comments About Their Vendors/Products “With Microsoft Active Directory, the promise of

ID Mgmt Customer Comments About Their Vendors/Products “With Microsoft Active Directory, the promise of this is light years away from what you get out of it if you don't do your homework. You must do the restructuring needed. We're using probably 10% of its capabilities. ” “We’re using Novell’s e. Directory, but we're phasing it out and going to Active Directory, which is a monumental project. We'll need to double or triple our staff to do it, but that won't happen. ” “We have a homegrown Single Sign-on strategy. We have scripts that synchronize passwords among applications and accounts. We will add components as we go along. ” “Netegrity’s Site. Minder works well. We haven’t used it a lot because it is expensive because of the way it is licensed. ” The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Wave 4 Identity Management Product Features & Reliability Ratings Lots of commentary The. Info.

Wave 4 Identity Management Product Features & Reliability Ratings Lots of commentary The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Wave 4 Identity Management Product Quality & Value Ratings Pricing issues The. Info. Pro

Wave 4 Identity Management Product Quality & Value Ratings Pricing issues The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

ID Mgmt Customer Comments About Their Vendors/Products “This is more of a workflow than

ID Mgmt Customer Comments About Their Vendors/Products “This is more of a workflow than a particular product. We have a number of integration points and Access 360 with some of this stuff. I didn't make the selection, but they were best or close to best of class. ” “We use CA’s e. Trust – they have the strongest offering at this point. ” “[We are] using Net. IQ’s package called Directory and Resource Manager. They provided ability to parcel out portions of network management authority to lower level people. Remote office people can be given the ability to re-set passwords. This is very granular level authority. ” “We chose Oblix. We had a very large project to examine user provisioning vendors. We looked at them, Netegrity and IBM. Picked them based upon flexibility of their product configurations. ” The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Wave 4 Identity Management – Corporate Ratings Summary The. Info. Pro Security Study –

Wave 4 Identity Management – Corporate Ratings Summary The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Wave 4 Identity Management – Product Ratings Summary The. Info. Pro Security Study –

Wave 4 Identity Management – Product Ratings Summary The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Investor Commentary About Identity Management Vendors “Identity Management / Single Sign-on is Netegrity’s legacy

Investor Commentary About Identity Management Vendors “Identity Management / Single Sign-on is Netegrity’s legacy business. Netegrity made a strange foray into portal that hurt it with its channel partners and it’s a positive that Netegrity sold that business. The end markets are improving to help Netegrity and it has rounded out to provide provisioning. IBM is its big gorilla competitor, BEA is second, and third is RSA. Netegrity’s functionality is a little better than RSA. Netegrity is not taking away market share from IBM or BEA, but it's taking a little from RSA. Still, it’s a takeover candidate as it offers a good product in an emerging space. ” “CA has become more focused on security the past year and a half since it brought in Ron Moritz. It is becoming even more price aggressive. It is unknown whether this strategy will work. While it may not increase its revenue too much, it puts pricing pressure on the competition. Symantec talked recently about having to sharpen its pencil and it wouldn’t surprise me if CA was part of the reason. CA is more focused on Enterprise than Consumer. ” The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Investor Commentary About Identity Management Vendors “ISS has introduced a good innovative product line

Investor Commentary About Identity Management Vendors “ISS has introduced a good innovative product line in Proventia, with faster throughput and many less false detections. Intrusion Detection was a disappointment earlier and products were not as robust as they are now. This will be a growth area in 2004 and 2005. We have confirmation data that the sector will grow because Check Point and others recently introduced products. Even Nortel is introducing product. ” “Within Information Security, IBM’s revenue outlook is flat to down. For Mainframe, it will continue to decline, but Tivoli will help to offset this. There is a lot of competition in the Security Management Software space where Tivoli plays. There are no market leaders yet. CA and HP will compete and Symantec is working on bringing out a product. ISS’s Intrusion Detection has been out for a number of years. ” The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

Conclusions & Recommendations l Sarbanes-Oxley and other regulations will drive investment in Identity Management,

Conclusions & Recommendations l Sarbanes-Oxley and other regulations will drive investment in Identity Management, including Provisioning and Single Sign-on products through 2006. l Identity Management is still a “hot” technology, but deployment haven’t grown much in the last 6 months. Projects are large and impact many current processes. l Nearly 40% of users say they don’t plan to implement an integrated ID Mgmt suite. l Microsoft and IBM are in use and/or under consideration for more ID Mgmt projects than other vendors, due to the broad scope of these projects. l Customers planning to spend more on CA, IBM and others, but Netegrity customers say they’re planning to spend less on the vendor. l RSA, Symantec and Microsoft received the strongest corporate ratings from current customers; ISS and CA received the weakest corporate ratings. l Novell, RSA and Veri. Sign received the strongest product ratings from current customers; CA, ISS and IBM received the weakest product ratings. The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+

This presentation contains confidential information which is the property of The. Info. Pro and

This presentation contains confidential information which is the property of The. Info. Pro and is given to the recipient pursuant to a confidential relationship between the recipient and The. Info. Pro. Such information shall not be copied, disclosed to others, or used for any purpose other than that for which is given, without the written permission of The. Info. Pro, Inc. The. Info. Pro™ & logo are registered trade marks and property of The. Info. Pro, Inc. © 2004 The. Info. Pro, Inc. All Rights Reserved. 645 Madison Avenue, 22 nd Floor, New York, NY 10022 P > 212 -672 -0010 F > 212 -688 -6598 E > Info@The. Info. Pro. net theinfopro. net The. Info. Pro Security Study – Wave 3 n=198; Wave 4 n=161 (to date); Final Wave 4 n=220+