Feeds

The policy is...get some

Apps upgrades will need policies, even if you don't want them

  • alert
  • submit to reddit

The Power of One Brief: Top reasons to choose HP BladeSystem

Further indications that the coming upgrades of the major business applications such as SAP and Oracle could cause unsuspecting IT managers more problems than they have planned for, first noted here, have come from SOA Software.

Acknowledging that the next round of upgrades will all be enabled to run within - or even run - Service Oriented Architecture environments, the company's executive VP of product strategy, Frank Martinez, observed that IT managers now face a situation where it would no longer be a question of whether they opt for an SOA environment, as they will get it anyway. "The only questions they face now are 'when', and 'how'," he said. "And this can raise issues they have not planned for."

One of the most important issues is the fundamental change SOA can bring in the way IT is exploited in running businesses. Up until the arrival of SOA consumers have had to interact with suppliers' business systems in whatever way demanded by those business systems and the processes they run.

There has always been, therefore, an implicit direct coupling between the two, with any supplier policy automatically impacting the consumers for good or ill.

As Martinez points out, however, SOA infrastructures change this situation significantly. "It is not only possible to completely decouple the consumer and supplier sides of the business but also for the consumer side to start driving the way a company does business," he said. "That means businesses now need separate consumer-side and supplier-side policies and that they need to be decoupled from each other."

Though many users may opt to upgrade their applications suites to obtain other functionality than the SOA capabilities, the fact they are there, available for use by developers, means that business processes may be open to unintentional vulnerabilities simply because no management or process policies are in place. Such policies need to be implementable from the moment any upgraded application suite moves into the production environment.

The real trick then, according to Martinez, is having the ability to manage the necessary mediation between policies when contention occurs. For many businesses this issue will be a new one they have face, and one that cannot be avoided once they upgrade their applications. "Yes, it is a daunting prospect for many of them," he acknowledged. "But the fact that it is daunting is no longer acceptable as an argument."

Policy mediation is only one of four main areas of infrastructure management that users need to address as they drift into the SOA waters, the others being management tools, security and governance.

Martinez suggests that, taken together, this produces the need for very deep end-to-end integration across the infrastructure, deeper than the level of integration currently provided by available standards. "These may not close the loop around applications or process life cycles," he said.

But policy definition and implementation remain two of the most serious issues facing businesses as they plan for application suites upgrades, for they remain something of an unsuspected dark horse in the stable of new technologies those users will be acquiring. The key step for many will not be in implementing policies well.

As Martinez put it: "SOA has tools to manage and implement the most complex policies and mediate between them. But the users now need to understand that they do need the policies in the first place." ®

Securing Web Applications Made Simple and Scalable

More from The Register

next story
Apple fanbois SCREAM as update BRICKS their Macbook Airs
Ragegasm spills over as firmware upgrade kills machines
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
NO MORE ALL CAPS and other pleasures of Visual Studio 14
Unpicking a packed preview that breaks down ASP.NET
Captain Kirk sets phaser to SLAUGHTER after trying new Facebook app
William Shatner less-than-impressed by Zuck's celebrity-only app
Cheer up, Nokia fans. It can start making mobes again in 18 months
The real winner of the Nokia sale is *drumroll* ... Nokia
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
EU dons gloves, pokes Google's deals with Android mobe makers
El Reg cops a squint at investigatory letters
Chrome browser has been DRAINING PC batteries for YEARS
Google is only now fixing ancient, energy-sapping bug
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.