Comments
Richard Davies wrote: The UK has a good crop of technology pioneers in cloud computing - for example ElasticHosts, FlexiScale, Flexiant, OnApp - and also some strong government initiatives such as G-Cloud. We will have to see whether this kind of technical leadership converts into swift mass-market adoption or not.
Cloud Expo on Google News

SYS-CON.TV
Cloud Expo & Virtualization 2009 East
PLATINUM SPONSORS:
IBM
Smarter Business Solutions Through Dynamic Infrastructure
IBM
Smarter Insights: How the CIO Becomes a Hero Again
Microsoft
Windows Azure
GOLD SPONSORS:
Appsense
Why VDI?
CA
Maximizing the Business Value of Virtualization in Enterprise and Cloud Computing Environments
ExactTarget
Messaging in the Cloud - Email, SMS and Voice
Freedom OSS
Stairway to the Cloud
Sun
Sun's Incubation Platform: Helping Startups Serve the Enterprise
POWER PANELS:
Cloud Computing & Enterprise IT: Cost & Operational Benefits
How and Why is a Flexible IT Infrastructure the Key To the Future?
Click For 2008 West
Event Webcasts
Opinion: Web Services Security Hype
If we're going downhill, that means we're gaining momentum, right?

Related Links:

  • SYS-CON Media and Burton Group to Stage Application Server Shoot-Out at Web Services Edge Conference 2005
  • Application Servers to Vie for Top Position in Boston Shoot-Out 


    According to the latest Web services "hype cycle" from Gartner, both Web services security standards and the deployment of Web services with security are rushing headlong into the dreaded "Trough of Disillusionment." This means that the greatest levels of hype in these areas are supposedly behind us and the reality of just what can and cannot be done is collectively dawning on us.

    Taken at face value, this news could be either good or bad. The good news could be that now that the hype is over and we have passed the lofty "Peak of Inflated Expectations," we can all get down to the serious work of putting together workable security solutions and solid security standards to help bring Web services to where they deserve to be. The bad news could be the security components of Web services getting mired in the "Trough of Disillusionment" for too long and losing their appeal for the enterprise.

    Rightful Place?
    One question we should ask ourselves is, do the Web services security categories belong where Gartner has placed them on the hype curve? There are a number of ways that we can look at it. One way is to examine the position of the security elements on the hype curve relative to their peers. The security pieces still have a long way to go to catch up with established components of Web services, such as SOAP and WSDL, which are already on the "Plateau of Productivity" and are on the verge of exiting the hype cycle as they approach full mainstream adoption.

    Another way to look at it is to consider how these components are progressing over time. If you look at where they were placed on the curve at the same time last year, the security elements have been big movers - especially when compared to some other areas, like UDDI, which have been essentially frozen in place. In last year's hype cycle, Web services security standards had not even made it to the top of the "Peak of Inflated Expectations." In just a year's time, by Gartner's estimation, the security standards have made respectable advances toward broad acceptance and implementation; secure Web services made a roughly equal advance along the curve.

    Unfortunately, the path to productivity must inevitably pass through disillusionment, which is where Gartner sees the current state of Web services security. To really make a judgment about whether Gartner has made the right call about where we are with security, and where we might be heading, it is useful to understand how we got here.

    Keeping the Momentum
    Gartner's hype cycle assumes that all new technologies will eventually hit some rough spots in their life cycle, especially if they fail to meet the lofty expectations that are so often set for them early on. This is certainly true of Web services security. As Web services took off, there seemed to be no shortage of efforts to answer the need for securing this new paradigm. Creativity, and even unprecedented cooperation, appeared to be the order of the day: rival authentication standards banding together to create SAML; Microsoft and IBM joining hands to chart out a whole family of standards; promises of quick action from standards bodies to "fast track" Web services security standards; dozens of companies responding to the call to create technologies for implementing the standards. Plus, the newly conceived security standards showed bright promise for applications far beyond the world of Web services. It all felt so good, we should have known it would have to end. Competition, old rivalries, "standards bloat," and many other factors have served to pull us collectively back to reality. For example, Microsoft and IBM started to see different directions for their WS-* roadmap. And, the notion that standards would make security products interoperable right out of the box remains a dream for most. So, perhaps the assessment that we are in a state of disillusionment around Web services security, if it is off the mark at all, is not off by much.

    But that doesn't mean this is the end of the story. The descent into disillusionment could mean that real productivity and value from Web services security is just over the next rise. The danger is that if momentum is lost, these key components of the Web services world could suffer the same fate that intrusion detection technologies have suffered in the larger security space - a permanent place in the "trough." Losing momentum at this critical juncture could have dire consequences for security in Web services and the usefulness of Web services as a whole.

    The Next Big Step
    So, how can we ensure that security stays on track to help Web services deliver on their promises? I see three things that we can do for a start:

    • Keep it real: If we can properly manage our expectations and not fall back on the overblown hype of the past, then our disillusionment will likely be short-lived;
    • Close the gap: Right now, Gartner shows deployment of Web services with security as being a good deal further along in the cycle than the Web services security standards. This is a dangerous gap since it could indicate that many Web services security deployments are not using standards. I hope it is actually more of a matter of definitions, since Gartner considers the use of Secure Sockets Layer (SSL) encryption to constitute a Web service deployed with security (most robust applications Web services require much more to be secure). Whether the gap is real or just a gap in understanding, we must work to close it;
    • Maintain the focus: If those who are experimenting with or adopting Web services for use in their environments keep a strong focus on the importance of security to Web services, then the momentum should be able to carry these components over the hump.
    It will be exciting to see if this next year turns out to be one in which the security pieces of the Web services puzzle at last snap firmly into place.


    Related Links:
  • SYS-CON Media and Burton Group to Stage Application Server Shoot-Out at Web Services Edge Conference 2005
  • Application Servers to Vie for Top Position in Boston Shoot-Out
  • About Michael Mosher
    Michael Mosher is the technology director of the CSC Consulting Business and Technology Risk Management practice. He specialized in security architecture and security strategy, and has designed security solutions for Fortune 500 clients in financial services, manufacturing, energy, and health care. Michael has a broad background in government and commercial security, including six years as a special agent with the U.S. government investigating computer and white-collar crimes.

    In order to post a comment you need to be registered and logged in.

    Register | Sign-in

    Reader Feedback: Page 1 of 1

    Latest Cloud Developer Stories
    Can you bring services from the cloud to your customers faster and have them adopt it with ease of use or bring the power of bundled services to the fingertips of your clients without creating new rigid ‘apps stove pipes'? Do you want to prevent your business running away to publ...
    OCZ Technology Group, a provider of high-performance solid-state drives (SSDs) for computing devices and systems, on Tuesday announced the Z-Drive R4 CloudServ PCI Express (PCIe) flash storage solution, designed to accelerate cloud computing applications and reduce operating expe...
    Many organizations have embraced, or are considering, the benefits of cloud computing – speed, flexibility, increased expertise, shared workload, reduced costs, etc. The benefits are many – but so are the risks. What are the threats to cloud security? Which parties assume respons...
    In August 2011, SHI Enterprise Solutions (ESS) division launched the SHI Cloud, offering reliable and cost-effective industrial-grade cloud computing platforms. That same division achieved an 82 percent increase in revenue over 2010.
    SoftLayer Technologies on Tuesday announced the immediate worldwide availability of SoftLayer Object Storage, a redundant and highly scalable cloud storage service that allows users to easily store, search and retrieve data across the Internet, with optional CDN connectivity, or ...
    Subscribe to the World's Most Powerful Newsletters
    Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
    Click to Add our RSS Feeds to the Service of Your Choice:
    Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
    myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
    Publish Your Article! Please send it to editorial(at)sys-con.com!

    Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

    SYS-CON Featured Whitepapers
    ADS BY GOOGLE

    Breaking Cloud Computing News

    Quest Software’s Board of Directors announced today that Doug Garn is stepping down...