Securing a service-oriented architecture (SOA) environment
Nataraj Nagaratnam,
Anthony Nadalin and
Sridhar Muppidi
Journal of Business Continuity & Emergency Planning, 2007, vol. 1, issue 2, 129-145
Abstract:
Securing access to information is important for any business. Security becomes even more critical for implementations structured according to service-oriented architecture (SOA) principles, due to loose coupling of services and applications and their possible operations across trust boundaries. To enable a business so that its processes and applications are flexible, changes should be expected — both to process and application logic, as well as to the policies associated with them. Merely securing the perimeter with firewalls or routers is not sufficient for a flexible on demand business. Security must be factored into the SOA life cycle, reflecting that security is a business requirement, not just a technology attribute. This approach helps enable the capability to secure services. Another characteristic of SOA security is about rendering and using security functionality itself as security services. This paper discusses the SOA life cycle and security. It presents an SOA security model that captures the essence of security services and securing services. These approaches to SOA security are discussed in the context of scenarios, and observed patterns. The paper also introduces a reference model to address the requirements, patterns of deployment and usage, and an approach to integrated security management for SOA.
Keywords: service-oriented architecture; SOA; SOA security; security services; policy management; business security (search for similar items in EconPapers)
JEL-codes: M1 M10 M12 (search for similar items in EconPapers)
Date: 2007
References: Add references at CitEc
Citations:
Downloads: (external link)
https://hstalks.com/article/938/download/ (application/pdf)
https://hstalks.com/article/938/ (text/html)
Requires a paid subscription for full access.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:aza:jbcep0:y:2007:v:1:i:2:p:129-145
Access Statistics for this article
More articles in Journal of Business Continuity & Emergency Planning from Henry Stewart Publications
Bibliographic data for series maintained by Henry Stewart Talks ().