SOA raises security worries

Who's afraid of the big bad architecture?

NEWS

Service-orientated architecture (SOA) technologies could open up a security-based can of worms as they begin to move beyond the walls of individual businesses, according to one analyst house.

Companies are happily trialling tech's latest TLA internally but problems could crop up as there has been little discussion of the impact the new architecture will have when unleashed on the wider IT environment, according to the analysts.

The analyst house warned there is concern SOA might open up new gaps within IT systems, and that simply restricting access to authorised personnel via standard access-control mechanisms becomes impracticable in a service-oriented environment.

While the analyst house said SOA has "significant potential" to boost the value organisations derive from their IT investments, early adopters have also encountered problems around security, service performance, reliability and data management.

You what…?

Bust through tech jargon with silicon.com's Cheat Sheets.

Mike Thompson, Butler Group business process management practice director told silicon.com the "major security concern" for companies implementing SOAs is how to protect their data as it is transmitted over a "completely loosely coupled" system.

Thompson said companies could be put off transferring data to the outside world via SOA in two to three years' time as the architecture would no longer be enclosed within an internal system, making it difficult to implement security measures.

Thompson added: "But any system is inherently insecure the moment you open it up to the outside world."

Despite this, companies are busy trialling SOA with more than one-sixth (17 per cent) of tech chiefs engaged in trials and more than one-third (36 per cent) weighing up whether to move to the new architecture, according to a Butler Group survey.

A lack of in-house expertise on SOAs was also named as one of the major barriers to the adoption of new architecture by the Butler Group.

A recent survey found nine out of 10 city bosses had not heard of the latest industry TLA.

Comments

There is 1 comment. Join the discussion

  1. 1. anonymous

    I have heard of SOA but I have absolutely no idea what TLA stands for. Surely your article should explain this term? (Ed note. Three letter acronym)

    • 10 January 2007 10:21
    • Add comment

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters