Comments
Richard Davies wrote: The UK has a good crop of technology pioneers in cloud computing - for example ElasticHosts, FlexiScale, Flexiant, OnApp - and also some strong government initiatives such as G-Cloud. We will have to see whether this kind of technical leadership converts into swift mass-market adoption or not.
Cloud Expo on Google News


2008 West
DIAMOND SPONSOR:
Data Direct
SOA, WOA and Cloud Computing: The New Frontier for Data Services
PLATINUM SPONSORS:
Red Hat
The Opening of Virtualization
GOLD SPONSORS:
Appsense
User Environment Management – The Third Layer of the Desktop
Cordys
Cloud Computing for Business Agility
EMC
CMIS: A Multi-Vendor Proposal for a Service-Based Content Management Interoperability Standard
Freedom OSS
Practical SOA” Max Yankelevich
Intel
Architecting an Enterprise Service Router (ESR) – A Cost-Effective Way to Scale SOA Across the Enterprise
Sensedia
Return on Assests: Bringing Visibility to your SOA Strategy
Symantec
Managing Hybrid Endpoint Environments
VMWare
Game-Changing Technology for Enterprise Clouds and Applications
Click For 2008 West
Event Webcasts

2008 West
PLATINUM SPONSORS:
Appcelerator
Get ‘Rich’ Quick: Rapid Prototyping for RIA with ZERO Server Code
Keynote Systems
Designing for and Managing Performance in the New Frontier of Rich Internet Applications
GOLD SPONSORS:
ICEsoft
How Can AJAX Improve Homeland Security?
Isomorphic
Beyond Widgets: What a RIA Platform Should Offer
Oracle
REAs: Rich Enterprise Applications
Click For 2008 Event Webcasts
SYS-CON.TV
Top Links You Must Click On


Security Strategy for EAI
Security Strategy for EAI

In today's global economy, organizations are expanding their market opportunities by extending their reach. Mergers and acquisitions, new partnerships, and new business models - including e-business and Web services - are changing the way companies interact with their customers, and with each other. Yet these same initiatives are creating tremendous challenges for the IT groups faced with making it all work.

Today's extended enterprise model is creating complex, distributed IT infrastructures - vast networked environments that comprise hundreds of different systems and dozens of different applications across multiple-partner organizations. To meet this challenge, many organizations are turning to Enterprise Application Integration (EAI) strategies that reduce the cost and time associated with development, integration, implementation, and management of their distributed systems and applications.

This complex, heterogeneous environment doesn't just present new interoperability challenges; it also presents serious privacy and security challenges. No longer is the "back office" hermetically sealed off from the outside world. In exposing critical business functions to suppliers, customers, and employees via the Internet, institutions can expose data, applications, and systems to a variety of potential threats - both internal and external. Meanwhile, users expect that sensitive corporate and personal information will be readily available to those authorized to see it, while securely protected from access by everyone else.

To address security needs, organizations have deployed a variety of point security solutions for each application or system - a situation that increases complexity for both users and administrators. Users of multiple services or applications must remember multiple user IDs and passwords, which is not user friendly and increases security risk. On the operational side, security administrators must manage security policies for each user - for authentication, authorization, and audit - across numerous administrative interfaces. As the number of users, applications, and systems increases, this complexity becomes extremely costly to manage - and increases the chances of a breach through which a hacker or a disgruntled employee can slip in unnoticed.

How can organizations manage this complexity while enhancing security? Just as they have turned to EAI architectures to streamline integration of their distributed applications, they need a comprehensive architecture for Enterprise Application Security Integration (EASI). This framework, which leverages existing security services and applications, enables organizations to meet the critical demand for security across their entire extended enterprise, while reducing risk, cost, and complexity.

A comprehensive EASI framework enables organizations to address a range of critical business and technology requirements, including:

  • Establishing trust with end-to-end accountability across all systems and applications, from perimeter security to mid-tier security to back-office security
  • Managing complexity by providing a single, comprehensive solution for managing security policies across the entire heterogeneous infrastructure of today's extended enterprise
  • Preserving existing investments by leveraging existing best-of-breed security solutions
  • Accommodating evolution through adherence to open technology standards

    So what, exactly, is an EASI framework? It's a flexible, standards-based framework that integrates security technologies and products from multiple vendors across the perimeter, middle, and back-office tiers - both within a single enterprise and across multiple enterprise domains. It simplifies the unification of complex security infrastructures by providing the key P's of security integration:

  • Programming interfaces that simplify cross-domain integration today and permit cost-effective future evolution
  • Policies enabling centralized definition and security management across a variety of diverse security products
  • Protocols leveraging open standards, including XML and SAML (Security Assertion Markup Language), an XML-based standard for defining application-independent authentication/authorization credentials
  • Products enabling seamless interoperation of third-party products for authorization, authentication, cryptography, accountability, and administration

    The result is a single, virtual "business engine" that unites disparate technologies to address the four A's of enterprise security: Authentication, Authorization, Accountability, and Administration. This seamless, distributed framework can enhance end-to-end security, minimize disruption to the existing security infrastructure, and maximize ROI.

    From a user's perspective, this means enjoying the simplicity and convenience of Single Sign-on (SSO) when accessing multiple services or applications. From the administrator's viewpoint, EASI enables centralized management of the entire distributed security infrastructure, with end-to-end audit and alerts. For enterprise management, EASI represents a flexible solution for security interoperation that reduces risk while preserving technology investments and accelerating time to deployment.

    As organizations continue to extend their reach through innovative e-business models - and as the list of potential threats grows - there is little question that the need for distributed security will increase. By providing a flexible, standards-based integration architecture, an EASI framework can be the key to profitable, new capabilities - while closing the door to information security threats.

    About Bret Hartman
    Bret Hartman, VP of Technology Solutions at DataPower, has more than 23 years of experience in information security and secure systems development. His expertise includes Web Services security, distributed component security, policy development and management, and security modeling and analysis. Bret is a nationally recognized expert on distributed systems security; and he is a book author, regular speaker, and panelist on a variety of secure distributed system topics.

  • In order to post a comment you need to be registered and logged in.

    Register | Sign-in

    Reader Feedback: Page 1 of 1

    Enterprise Open Source Magazine Latest Stories . . .
    Apache Deltacloud, the Red Hat-contributed ReSTful API that abstracts differences between clouds so services on any cloud can be managed – provided of course there’s a driver – has graduated from the Apache Foundation’s incubator and is now a full-fledged Top-Level Project (TLP). The...
    With Cloud Expo 2012 New York (10th Cloud Expo) just four months away, what better time to start introducing you in greater detail to the distinguished individuals in our incredible Speaker Faculty for the technical and strategy sessions at the conference... We have technical and st...
    AMD said late Tuesday that its chief sales officer Emilio Ghilardi had left the company and that CEO and president Rory Read is going to do his job while a replacement is sought. AMD didn’t say why Ghilardi left but it’s assumed Read wants his own people. Read is relatively new to th...
    During the lifespan of M3 (Monitis Monitor Manager) there has always been something lacking – timers. M3 execution procedure was outlined in this previous article. The execution mentioned in the latter was a one-time-execution, whereas server monitoring requires periodic invocati...
    Red Hat is putting its bought-in Gluster scale-out NAS storage technology, acquired in October, on the Amazon cloud. It’s styled Red Hat Virtual Storage Appliance for Amazon Web Services and other clouds are supposed to follow in short order.
    A new episode of the screencast series is now available at the OpenNebula YouTube Channel. This screencast demonstrates the new easily-customizable self-service portal for cloud consumers. Its aim is to offer a simplified access to shared infrastructure for non-IT end users. The scree...
    Subscribe to the World's Most Powerful Newsletters
    Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
    Click to Add our RSS Feeds to the Service of Your Choice:
    Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
    myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
    Publish Your Article! Please send it to editorial(at)sys-con.com!

    Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021


    SYS-CON Featured Whitepapers
    ADS BY GOOGLE