Penetration Testing mailing list archives

Re: Gartner's Security 3.0


From: Nick Selby <nick.selby () the451group com>
Date: Sun, 4 Nov 2007 09:43:10 -0600 (CST)

Joining this conversation late. . . 

----- Original Message -----
From: "Pete Herzog" <lists () isecom org>
To: "M.B.Jr." <marcio.barbado () gmail com>
Cc: "pen-test list" <pen-test () securityfocus com>
Sent: Saturday, October 20, 2007 6:38:45 PM (GMT-0500) America/New_York
Subject: Re: Gartner's Security 3.0

Hi,

They didn't stablished a precise number. Their suggestion ranges from
5 to 8 percent.


<lotta stuff snipped>

*Disclosure: I'm an analyst at another company*


I think another thing to remember here - an important one - is that analyst firms are there to make statements like 
that one not to actually set their users' budgets, but to help frame conversations. I agree that an analyst making a 
blanket statement about how much to spend is kinda wacky - it's easy to see how difficult predicting that kind of thing 
would be for anyone, and I wonder why Gartner does it - in 2004 Gartner said, according to TechTarget:

"By 2006, information security spending (including staff salaries and external services) will drop to 4% to 5% of IT 
budgets, on average, as enterprises improve security management and efficiency," said [Gartner Group's Victor] 
Wheatman. "The lowest-spending 20% of organizations, the most efficient ones, will safely reduce the share of security 
in the IT budget to 3% to 4% by 2006."*

So in 2006, the average will spend 4% to 5%, the pikers and cheapskates 3%-4%, but in 2008 everyone will spend from 
5%-8%? Cool! 

However, in my personal blog (I usually blog about seething, ludicrous vendor spin, not this kind of stuff, but I put 
it there cause it's long and I didn't want to clog inboxes) I wrote about one possibly useful interpretation of the 
recommendation:

http://nickselby.com/yak/2007/10/21/how-much-security-would-you-like-to-buy/



*http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci969563,00.html


-- 
Nick Selby
Senior Analyst
Director, Enterprise Security Practice
The 451 Group 



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: