Re: [fw-wiz] OT: Av and Gartner...

From: Marcus J. Ranum (mjr_at_ranum.com)
Date: 07/31/03

  • Next message: David Wagner: "Re: [fw-wiz] Off topic: Any one know of a good IPV6 reference book?"
    To: John Keeton <jkeeton@nettoxin.net>, firewall-wizards@honor.icsalabs.com
    Date: Wed, 30 Jul 2003 23:37:07 -0400
    
    

    John Keeton wrote:
    >Also, anyone have any experiance with Garner regarding security items?

    Yes.

    I am amazed that anyone listens to Gartner about anything. Their
    "research" is based almost entirely on hearsay, vendor marketing
    literature, and vendor briefings (aka "consulting") - while they
    try very hard to dodge the question of whether their "research"
    is influenced by the amount of money they get from a vendor, it's
    pretty obvious what's going on if you line up who pays them and
    who gets covered. You virtually never see anyone on thier stupid
    magic quadrant who is not a Gartner research customer or a
    consulting customer. Of course they're very cagy about the
    relationship between how much you pay and where you wind up,
    there have been some extraordinary anomalies. Perhaps the
    most significant recently was Gartner's hyping of "Intrusion
    Prevention" technology - in particular they widely hyped Intruvert's
    IPS. Yet no customers, according to a Gartner analyst I discussed
    Intruvert with, used Intruvert in its in-line "prevention" mode. So
    what did Gartner base their "research" on? Intruvert's marketing
    literature? There's a serious credibility gap - indeed I'd go so far
    as to say there's a serious integrity gap.

    Does Gartner test technology? No. What do they actually
    base their "recommendations" on? They base them on what
    the vendors who pay them the most - their real customers -
    want them to recommend. If you want recommendations that
    have some kind of integrity, you need to look to people who
    have actually gotten some hands-on time with products
    and who actually understand a technology.

    When I talk to "C-level" senior management I rate their
    clue level based on whether they believe Gartner reports
    or not. I figure if I run into a CIO who takes Gartner
    reports seriously, that I've run into someone who worked
    up the management chain through political skills and
    organizational skills, not through technical skills, or
    technological vision. Taking Gartner reports seriously
    is a dead-on tipoff that you're dealing with an incompetent
    empty suit - after all, to take Gartner seriously, you'd
    have to be more ignorant about technology than they
    are. Which is hard to imagine.

    mjr.

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: David Wagner: "Re: [fw-wiz] Off topic: Any one know of a good IPV6 reference book?"

    Relevant Pages

    • Re: Recent Gartner IDS/IPS report
      ... regardless of the marketing buzzwords involved Gartner is ... simply suggesting IDS features will exist in firewalls and IDS data is ... Most of the messages regarding the Gartner report have been ... A harsh indictment such as "technology X is dead" shouldn't be based on ...
      (Focus-IDS)
    • Re: [fw-wiz] OT: Av and Gartner...
      ... John (and Marcus), ... Gartner, however,... ... paid Gartner for advice and we kept getting glowing reports back from ... > and who actually understand a technology. ...
      (Firewall-Wizards)
    • Re: HP #1 in Servers and Notebooks
      ... > According to Gartner IBM is the largest Server vendor not HP. ...
      (comp.os.vms)