For Enterprise Architecture Professionals (Length: 11 pages)

July 16, 2009

SOA Security 2009: Requirements And Design

Understanding Your SOA Security Requirements And Iterative Solution Design

This is the second document in the "SOA Security: 2009" series.

by Randy Heffner

with Khalid Kark, Matt Czarnecki


Executive Summary (This is a document excerpt)

In industry discussions about SOA, external integration is treated as the benchmark indicator of SOA security maturity: If it's secure enough for external integration, SOA must be secure. By that benchmark, 30% of SOA users think SOA security is mature enough — they have SOA-based external connections to customers and partners. Despite this, full maturity is yet to come for both internal and external SOA connections. Companies can achieve simple SOA security, which is mature and solid, by making service requests over a virtual private network. Advanced SOA security, which is in its early days, can involve federation among partners, nonrepudiation, and propagation of user identities across multiple layers of service implementations. The first major step in setting a strategy for your current and future SOA security solutions is to understand the breadth of your SOA security requirements. The second step is setting an iterative design process to ensure a fully integrated view that considers security requirements, industry specifications, SOA security products, and custom security integration possibilities.

Buy Risk-Free

Download and print PDF immediately. Price: US $499

Our Money-Back Guarantee: If you are not completely satisfied, return it for a full refund within three weeks of your online purchase.

Already a Forrester Client?
Log in to read this document.

Add to cart

TABLE OF CONTENTS

NOTES & RESOURCES

itemMany Enterprises Lack A Comprehensive Strategy For SOA Security

itemAlthough Key Standards Are Finally In Place, Maturity Is Slow To Develop

itemBasic SOA Security Is Simple But Fails To Address Many Requirements

itemDiverse Scenarios Lead To A Long List Of Detailed Requirements In Four Problem Areas

itemDevelop An Iterative Process For Designing SOA Security

recommendations

itemSet An Evolutionary Strategy For SOA Security

Forrester surveyed 26 vendors and 198 user companies to identify their support for and use of SOA security standards, products, and usage scenarios.

Related Research Documents

itemAcross All Vertical Industry Groups, The Majority Of SOA Users Are Expanding Its Use

May 28, 2009

itemSOA Is Far From Dead — But It Should Be Buried

May 11, 2009

itemWeb Services Security Specifications: WS-Security Achieves Critical Mass Of User Adoption

January 5, 2009

Find Documents In Related Categories

This document falls under the following categories. Click on a link below to find similar documents.

Analyst: Randy Heffner
Technology: Application Development, Application Development Processes & Tools, Application Security, Security & Risk, SOA & Web Services
Geography: Asia Pacific, Europe, North America