Re: Gartner's Security 3.0

From: Nick Selby (nick.selby@the451group.com)
Date: Sun Nov 04 2007 - 10:43:10 EST


Joining this conversation late. . .

----- Original Message -----
From: "Pete Herzog" <lists@isecom.org>
To: "M.B.Jr." <marcio.barbado@gmail.com>
Cc: "pen-test list" <pen-test@securityfocus.com>
Sent: Saturday, October 20, 2007 6:38:45 PM (GMT-0500) America/New_York
Subject: Re: Gartner's Security 3.0

Hi,

> They didn't stablished a precise number. Their suggestion ranges from
> 5 to 8 percent.

<lotta stuff snipped>

*Disclosure: I'm an analyst at another company*

I think another thing to remember here - an important one - is that analyst firms are there to make statements like that one not to actually set their users' budgets, but to help frame conversations. I agree that an analyst making a blanket statement about how much to spend is kinda wacky - it's easy to see how difficult predicting that kind of thing would be for anyone, and I wonder why Gartner does it - in 2004 Gartner said, according to TechTarget:

"By 2006, information security spending (including staff salaries and external services) will drop to 4% to 5% of IT budgets, on average, as enterprises improve security management and efficiency," said [Gartner Group's Victor] Wheatman. "The lowest-spending 20% of organizations, the most efficient ones, will safely reduce the share of security in the IT budget to 3% to 4% by 2006."*

So in 2006, the average will spend 4% to 5%, the pikers and cheapskates 3%-4%, but in 2008 everyone will spend from 5%-8%? Cool!

However, in my personal blog (I usually blog about seething, ludicrous vendor spin, not this kind of stuff, but I put it there cause it's long and I didn't want to clog inboxes) I wrote about one possibly useful interpretation of the recommendation:

http://nickselby.com/yak/2007/10/21/how-much-security-would-you-like-to-buy/

*http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci969563,00.html

-- 
Nick Selby
Senior Analyst
Director, Enterprise Security Practice
The 451 Group 
------------------------------------------------------------------------
This list is sponsored by: Cenzic
Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!
http://www.cenzic.com/downloads
------------------------------------------------------------------------


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:58:11 EDT