Comments
Patrick Collands wrote: collands (AT) gmail com I'd be very grateful for an invitation. Thank you.
Cloud Expo on Google News

SYS-CON.TV

2009 East
PLATINUM SPONSORS:
IBM
Smarter Business Solutions Through Dynamic Infrastructure
IBM
Smarter Insights: How the CIO Becomes a Hero Again
Microsoft
Windows Azure
GOLD SPONSORS:
Appsense
Why VDI?
CA
Maximizing the Business Value of Virtualization in Enterprise and Cloud Computing Environments
ExactTarget
Messaging in the Cloud - Email, SMS and Voice
Freedom OSS
Stairway to the Cloud
Sun
Sun's Incubation Platform: Helping Startups Serve the Enterprise
POWER PANELS:
Click For 2008 West
Event Webcasts
Governance: The Last Mile of SOA
So what exactly is SOA governance, why is it important, and what needs should it address?

Runtime governance relies on an SOA infrastructure that is able to exercise policy enforcement in a way that is transparent to, and independent of, the service providers and consumers. This is generally achieved through an agent or intermediary that resides between provider and consumer, and a registry that addresses both the needs of service discovery as well as policy enforcement. The intermediary interacts with the registry to find services and their runtime policies, and enforces the policies during the execution of the service (See Figure 1).

Intermediaries serve as the policy enforcement points for SOA. Without SOA, the ability to control and manage applications is restricted both by the scope and the capabilities of the underlying platform. Thus, when different applications are integrated, it is generally infeasible to apply a common policy context to the integrated result. A typical challenge is enforcing access security when two applications with different user communities are integrated. For example, application A automatically draws data from application B, but application A users are not authorized to use application B. How do you now control the data that users have gained access to within application A? With intermediation, it becomes possible for a distributed network of services to share a common policy-managed context. This is a powerful capability which emerges as a direct result of SOA.

Change Time Governance
Change is inevitable and at some point, services deployed in the runtime environment will have to be changed to adapt to new business requirements. Since the majority of services will be designed once and then modified several times over their lifespan, change time governance - the act of managing services through the cycle of change - is arguably more important in the long term than design time governance. Change time governance requirements and considerations include:

  • Understanding inter-service relationships and dependencies
  • Performing impact analysis to determine the implications of changing a particular service within the runtime environment
  • Managing the rollout of services into the existing runtime environment
  • Managing service custody transfers through the design, coding, testing, and deployment stages
  • Managing changes to existing policies and service-level agreements
An important aspect of change time governance is involvement from the line of business. While easy to overlook when looking at governance from an IT-centric perspective, this need arises from the fact that services exist to support business functions as well as the inter-organizational relationships and dependencies that are implicit in SOA, particularly when services are exposed and invoked across organizational and corporate boundaries. Since changes are generally initiated and driven by business requirements, business users need to be intrinsic participants in the governance lifecycle.

Consider, for example, a service that enables vendor managed inventory. A change in the service, say, to reduce inventory data latency from a week to one day, will involve not only technical changes to the service (and possibly source applications and databases), but more importantly, changes in the business relationship between the company and its suppliers. A comprehensive governance strategy is needed to ensure coordination between the technical and business-level changes. As with design time and runtime, this change time governance can be facilitated by a governance-enabled SOA infrastructure that allows change time policies to be defined and enforced through service contracts and workflows.

Getting Started
For the many companies who are just getting started with SOA, at what point should consideration of governance come into play and where should it be focused?

One priority is to make an SOA governance strategy a subset of any larger SOA strategy, and to ensure that governance capability related milestones are synchronized with SOA adoption milestones, so that you do not end up trying to retro-fit governance after the fact. Ideally, the right time for governance is before you put any services into place so that any SOA pilot proves out not only the approach itself, but also the related governance practices along the way.

As part of the SOA governance strategy, there should be a roadmap that defines which specific governance capabilities the organization wants to put into place and when they will be implemented. Typically, companies will first want to pay attention to the SOA architecture and to design time governance policies in order to get the SOA journey off on the right foot. In fact, since architecture and governance are what separate a collection of Web services from being a true SOA, organizations that went down the path of simply developing and exposing Web services without the appropriate controls or a broader architecture will want to consider an investment in governance.

Finally, while governance is not a solution that comes in a box, having the right technology framework makes it easier - and in some situations is the only feasible way - to enforce policies and controls. As explained in this article, this framework should include mechanisms for defining and enforcing policies and service contracts through the service life cycle of workflows, intermediaries, and other automated means. By establishing the right balance between organizational practices and supporting technologies, companies will be able to turn the concept of SOA governance into a practical reality.

About Gary So
Gary So is vice president, Office of the Chief Technology Officer, at webMethods, Inc, where he is responsible for advancing the company’s status as a recognized industry thought leader. Gary has over 10 years experience in the integration field, serving previously as a system architect in corporate IT and as a director of professional services at Active Software, Inc., before joining webMethods in 2000. Gary has a masters degree in computer engineering from the University of Toronto.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

Latest Cloud Developer Stories
CloudBench Applications, Inc. announced its financial results for the three months and nine months ending September 30, 2009. All amounts are stated in Canadian dollars unless otherwise noted. Revenues from BasicGov, the Company's cloud computing solution for local government, gr...
The new contract is an industry first, with CSC being the first Microsoft partner to lead and win a cloud computing services agreement of this scale. Under terms of the contract, CSC will provide Royal Mail Group's 30,000 employees with access to new IT services using Microsoft's...
Operates in over 170 countries and is one of the world’s leading providers of communications solutions and services. Richard Tarboton talks for MeettheBoss.TV on his role as Head of Energy & Carbon for BT and what they are doing towards reducing carbon emissions.
CA is going to put its Agile Planner software on salesforce.com’s Force.com platform in the first half to accelerate development time and give users visibility over their development initiatives to reduce time-to-market. Customers are supposed to be able to accelerate the deploym...
Despite its uncertain fate Sun soldiers on. Monday it trotted out a cloud-based multiplatform desktop as a service for K-12 and community colleges that can run Windows, the Mac OS, Linux and Solaris applications to nearly any client device, including its own Sun Ray thin clients....
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON Featured Whitepapers
ADS BY GOOGLE

Breaking Cloud Computing News
CloudBench Applications, Inc. announced its financial results for the three months and nine months e...