Feeds

The policy is...get some

Apps upgrades will need policies, even if you don't want them

  • alert
  • submit to reddit

Combat fraud and increase customer satisfaction

Further indications that the coming upgrades of the major business applications such as SAP and Oracle could cause unsuspecting IT managers more problems than they have planned for, first noted here, have come from SOA Software.

Acknowledging that the next round of upgrades will all be enabled to run within - or even run - Service Oriented Architecture environments, the company's executive VP of product strategy, Frank Martinez, observed that IT managers now face a situation where it would no longer be a question of whether they opt for an SOA environment, as they will get it anyway. "The only questions they face now are 'when', and 'how'," he said. "And this can raise issues they have not planned for."

One of the most important issues is the fundamental change SOA can bring in the way IT is exploited in running businesses. Up until the arrival of SOA consumers have had to interact with suppliers' business systems in whatever way demanded by those business systems and the processes they run.

There has always been, therefore, an implicit direct coupling between the two, with any supplier policy automatically impacting the consumers for good or ill.

As Martinez points out, however, SOA infrastructures change this situation significantly. "It is not only possible to completely decouple the consumer and supplier sides of the business but also for the consumer side to start driving the way a company does business," he said. "That means businesses now need separate consumer-side and supplier-side policies and that they need to be decoupled from each other."

Though many users may opt to upgrade their applications suites to obtain other functionality than the SOA capabilities, the fact they are there, available for use by developers, means that business processes may be open to unintentional vulnerabilities simply because no management or process policies are in place. Such policies need to be implementable from the moment any upgraded application suite moves into the production environment.

The real trick then, according to Martinez, is having the ability to manage the necessary mediation between policies when contention occurs. For many businesses this issue will be a new one they have face, and one that cannot be avoided once they upgrade their applications. "Yes, it is a daunting prospect for many of them," he acknowledged. "But the fact that it is daunting is no longer acceptable as an argument."

Policy mediation is only one of four main areas of infrastructure management that users need to address as they drift into the SOA waters, the others being management tools, security and governance.

Martinez suggests that, taken together, this produces the need for very deep end-to-end integration across the infrastructure, deeper than the level of integration currently provided by available standards. "These may not close the loop around applications or process life cycles," he said.

But policy definition and implementation remain two of the most serious issues facing businesses as they plan for application suites upgrades, for they remain something of an unsuspected dark horse in the stable of new technologies those users will be acquiring. The key step for many will not be in implementing policies well.

As Martinez put it: "SOA has tools to manage and implement the most complex policies and mediate between them. But the users now need to understand that they do need the policies in the first place." ®

High performance access to file storage

More from The Register

next story
Android engineer: We DIDN'T copy Apple OR follow Samsung's orders
Veep testifies for Samsung during Apple patent trial
This time it's 'Personal': new Office 365 sub covers just two devices
Redmond also brings Office into Google's back yard
Batten down the hatches, Ubuntu 14.04 LTS due in TWO DAYS
Admins dab straining server brows in advance of Trusty Tahr's long-term support landing
Microsoft lobs pre-release Windows Phone 8.1 at devs who dare
App makers can load it before anyone else, but if they do they're stuck with it
Half of Twitter's 'active users' are SILENT STALKERS
Nearly 50% have NEVER tweeted a word
Windows XP still has 27 per cent market share on its deathbed
Windows 7 making some gains on XP Death Day
Internet-of-stuff startup dumps NoSQL for ... SQL?
NoSQL taste great at first but lacks proper nutrients, says startup cloud whiz
Windows 8.1, which you probably haven't upgraded to yet, ALREADY OBSOLETE
Pre-Update versions of new Windows version will no longer support patches
Microsoft TIER SMEAR changes app prices whether devs ask or not
Some go up, some go down, Redmond goes silent
Red Hat to ship RHEL 7 release candidate with a taste of container tech
Grab 'near-final' version of next Enterprise Linux next week
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.