- 1
- 2
- 3
- < previous
- +
Process Trip 04/02/2008 13:07:03
Why Maritz Travel revamped key business processes — and how business and IT came together to make it workWhen Rich Phillips became COO OF Maritz Travel about two and-a-half years ago, he sat down and took a hard look at the big industry picture - +
Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients? - +
How to Get Real About Strategic Planning 04/02/2008 12:50:59
Everyone agrees that having a strategic plan for IT is a good thing but most CIOs approach the process with fear and loathing. In fact, the majority of CIOs (and the enterprises they work for) are faking it when it comes to strategic planning. Isn't it time we all got real?Oh, it must be nice to be the CIO of a FedEx or a GE or a Credit Suisse. Places where IT and the business are so tightly aligned you can barely tell the two apart. Where corporate leaders understand that IT is a strategic asset and support it as such - +
ACT govt to overhaul financial system 10/12/2007 15:52:59
A single application to provide more common business process informationThe ACT government will re-implement its Oracle Financials system by consolidating nine separate instances into one.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. APEC Police Force / Geomatic Technologies
Mobile Security
Delivering the Power of Choice with Microsoft Dynamics CRM
Packet Eyes Home & Small Business Surveillance System
Smartphones & Enterprise Mobility
Vendor Influence Curves And How You Can Get The Best Value Out Of Your Network
CFA Victoria Collaboration between Telstra and CFA Victoria.
Wireless protection for the Mobile Workforce
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
On the standards front, groups such as the Event Processing Technical Society are working on developing common languages, formats and more for CEP tools. In the meantime, enterprise IT managers today should work with their business intelligence, BPM, middleware or SOA vendors on how they can make CEP work in their environments. Enterprise users need to understand the technologies they have today that could augment or enable more advanced CEP capabilities before selecting a vendor or tool, Kobielus says.
"If users want to bring CEP in, they need to ask their vendors to what extent their CEP technology implementation would be consistent or interoperable with their current SOA stack. Without set standards, each user has to understand what they have before they bring in more tools," he says. "It is entirely possible to create more of a mess with multiple [enterprise service buses], SOA governance tools and CEP products."
Security in a dynamic environment
The advent of SOA represents many changes for IT environments, not the least of which involves security.
The nature of SOA introduces flexibility and transitions an environment from being static to behaving in a dynamic fashion to meet business needs. SOA applications are loosely coupled and reuse components scattered about an environment, which is not ideal for the locked-down nature of most enterprise security technologies in use today. The impending issue of security in an SOA environment has some industry watchers looking for technologies and tools that could fall into a bigger category of security-oriented architecture or put simply, security for SOA.
"The fundamental security challenge that SOA presents is that by abstracting IT capabilities and data as services, the security for those capabilities is at risk of being lost," says Jason Bloomberg, principal and senior analyst at ZapThink. "As a result, SOA essentially necessitates enterprisewide identity and access management to maintain the security context for users as they interact with abstracted services -- essentially allowing the right users to do what they're supposed to do. Services must also be protected from threats, as well -- preventing the wrong users from doing what they're not supposed to do."
That means instead of locking down systems, IT security executives need to learn how to attach security measures to components that operate independently in the environment. One way to provide such protection is with XML firewalls or content-level protection (such as the technology Citrix just acquired with QuickTree) and endpoint security tools, such as antivirus, network access control and intrusion-prevention tools. Other options include an up-and-coming extension of identity and access management technologies dubbed entitlement management that includes fine-grained, role-based access controls. These technologies require granular policies for access rights to applications, which could be extended into an SOA environment.
"Security is becoming identity-centric, and this goes well beyond simply directories and into detailed entitlements. That is a move in the right direction," says Andreas Antonopoulos, a founding partner at Nemertes Research. "We have to move away from the security model of the past that involved one vendor and closed systems with little ability to do anything outside of that system. In an SOA environment, you may have one primary security vendor, but that vendor can accept data from multiple sources to make security more fluid to better address subtle threats and to ensure protection across the components."
But the issue around securing SOA environments today isn't the lack of promising concepts; it's the absence of standards, industry watchers say. Stand-alone SOA security vendors such as Forum Systems and Layer 7 have emerged to augment the market and security efforts by SOA providers such as SOA Software and Software AG. Yet pure-play security vendors haven't quite come on board with the effort, which stalls standards and prevents true security-oriented architectures from being developed, Antonopoulos says. For now, that leaves enterprises cobbling together their identity and access management and single sign-on deployments to SOA initiatives.
"SOA and applications vendors are working more and more for security, but security vendors simply aren't getting involved. That is a problem, because you need all your security components to be able to talk to each other. Start-ups addressing the issue of SOA security can only take it so far," Antonopoulos says.
Essentially, security-oriented architecture technologies would be similar to SOA technologies: not one product, but several products equipped to communicate, integrate and secure the overall environment. While OASIS and other standards bodies are working on standards such as Web-Services Security, or WS-Security, without security vendors signing on to comply there isn't much headway in terms of integrated security across an SOA environment yet.
"Most systems can talk SOAP for instance. But typical security systems are deaf, dumb and blind to SOAP. Buyers need to make SOA features critical to their security buying decisions going forward," Antonopoulos says. "2008 will bring a higher level of adoption for SOA and that is going to put pressure on security infrastructure to adapt and security vendors would be well served to work on those integrations and standards that would enable the exchange of information security-oriented architecture requires."
- 1
- 2
- 3
- < previous
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
F-Secure achieves excellent results in Internet security suite comparison 2008-10-10 14:37:00+10
M2M Connectivity announces the new Sierra Wireless MC8792V embedded module for 900 MHz 3G/HSPA networks 2008-10-10 08:51:00+10
Pitney Bowes MapInfo Launches New Version of AnySite 2008-10-10 05:58:00+10
IOGEAR Gears Up in Australia 2008-10-09 20:18:00+10
Internet Service Providers offer new unlimited Online Backup from F-Secure 2008-10-09 19:42:00+10
CRM your salespeople will love
Winning over the sales department and obtaining buy-in at all levels is crucial to the success of any CRM initiative. Discover how you can let salespeople work how they want to and reduce their administrative burden with the latest CRM technology.










