SOA Service Governance Policy Enforcement



SOA Service Governance Policy Enforcement

Policy Enforcement Integrated Governance Centrasite SOA Governance

Integrated Governance Background

SOA Governance is often highlighted as the reason why Service oriented architecture based IT projects succeed or fail. SOA Governance can be divided into three parts:

  1. Design-time governance refers to the phase in which a service is designed and published with a service definition (WSDL). The processes and controls around who can change a service, who gets notified when a service changes, and how to implement impact analysis for these changes are typically addressed by SOA repositories such as Software AG’s CentraSite® or IBM’s WSRR solutions.
  2. Runtime governance refers to the phase where the SOA runtime environment (an application server, an Enterprise Service Bus) relies on the repository to get a Service update, an associated policy, and other metadata to make a policy enforcement decision.
  3. The monitoring phase is the final phase of governance whereby the service runtime quality of service characteristics are made available to the operators.

Intel Solution

Intel® Expressway Service Gateway enables an Enterprise to have a fully integrated governance lifecycle for SOA by delivering:

  • Standard UDDI support for SOA registry/repository solutions.
  • An integration framework and specific validated integration packages with major SOA Repository solutions such as CentraSite and IBM* WSRR.
  • A full runtime governance environment able to enforce policies designed in SOA repository solutions based on standards such WS-SecurityPolicy and WS-Policy. Provides a policy enrichment capability to add policy artifacts not yet supported by such standards.
  • A rich monitoring capability that can easily be integrated with the Security Information Event Manager (SEIM) products or other monitoring solutions.

 


Security Gateway