With the advent of mashups, innovative developers all over the enterprise are seeking new ways to leverage the value of corporate information through the use of external Web applications, APIs, or services. Although the thought of this adventure has sent many corporate security specialists running behind their firewalls, mashups are here to stay. Indeed, they have strategic value for many enterprises, so you'd better figure out how to live with them.
The risks, however, are real. When multiple data sources and services live inside and outside the firewall, mashed into Web apps, vulnerabilities may emerge. So, what are those potential holes and how should you plug them? First you need to understand how the various types of mashups work and then create a strategy to apply appropriate security for creating and maintaining mashups.
Here's how to deal with the risks around mashups -- and how your enterprise can have its cake and eat it too.
Mashups seen and unseen
Although enterprise mashups (and the problems they inherently create) are new, solution patterns are already emerging. Broadly speaking, there are two types of mashups: presentation-centric and data-centric. Each has a different set of security issues.
The Google Maps variety of mashup typifies the presentation-centric type. In many instances they are dashboards, portals, or reduced-size data displays for mobile devices. The formula is simple: Take two or more different resources and create something that is more useful than the sum of its parts. It's easy to see the value because it's right there on the screen in front of you.
Presentation-centric mashups are already infiltrating the enterprise with or without the knowledge of IT. A typical example: customer information mashed together with Google Maps in support of a delivery schedule application that maps customer addresses, creates routes, and even examines traffic to expedite deliveries.
While clearly a valuable application, important customer information is in play. Steps can be taken to make sure the information remains behind the firewall. But in many instances, the information has to be transmitted to the Web application over the Internet, and therein lies the problem.
Data-centric mashups, on the other hand, combine two or more services to create an integration point that serves a true business process. They may operate behind the scenes and never appear on screen, at least not directly, but they are mashups nonetheless. This is actually lightweight XML integration and may involve all manner of vital information, depending on what's exposed or available. Data-centric mashups present the greatest security challenges because they have the potential to do the most harm. Indeed, megabytes of valuable customer or financial data could be compromised in just a few seconds if a rogue data-centric mashup is created.
Transmitting private information outside the firewall without encryption or other security measures invites disaster. For instance, leveraging an Internet-based service to calculate the risk of a financial trade is certainly a valuable thing to mashup with existing trade information on the corporate mainframe. But flowing that trade information through that Internet-hosted service opens a big, fat vulnerability.
Five mashup security strategies
To get the most from an enterprise mashup, you need to strike a balance between the value of the mashup and the need for security. There are several security approaches to take: policy level, data access level, service access level, screen access level, and identity management.
Policy level security refers to design-time policies and procedures. The policy-level approach typically doesn't deal with the underlying technology, nor security tools and technology, but addresses security threats through rules, governance, procedures, and education. There are legal issues here as well: Sarbanes-Oxley compliance, for example, or the use of published polices that could protect corporate assets and provide a means to fire employees who violate those policies.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. CRM your salespeople will love
Controlling storage costs with Oracle database 11g
How to improve employee productivity in small and medium businesses
Gaining Competitive Advantage Through Enterprise Planning
Email Archiving Implementation: Five Costly Mistakes to Avoid
Best Practice in Building an Integrated Information Management Strategy
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Strategies for Eliminating .PST Files
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Fortinet November Threatscape Report Shows Calm Before Holiday Storm 2008-12-05 16:00:00+11
Epicor® Cited as an Order Management Solutions Leader by Independent Research Firm 2008-12-05 15:52:00+11
F-Secure: Growth In Internet Crime Calls For Growth In Punishment 2008-12-05 13:00:00+11
International researchers gather in Sydney to preview the clever web 2008-12-05 09:48:00+11
Borderless corporate networks to shift focus to secure content management in Australia in 2009 2008-12-04 16:06:00+11
Email Archiving 101—Customer Case Study
Join Lee Benjamin, a Microsoft Exchange MVP and Ryan Shipkowski, network administrator for Matthews, to discuss the process and ROI of implementing an email archiving solution, with emphasis on a case study from Matthews International.












