Accenture Slides - Soa Workshop Starter Kit Web Se

整理文档很辛苦,赏杯茶钱您下走!

免费阅读已结束,点击下载阅读编辑剩下 ...

阅读已结束,您可以下载文档离线阅读编辑

资源描述

ServiceOrientedArchitectureSOAWorkshopStarterKitWebServicesSecurityLastUpdated:July,2006SOAWorkshop–V2.02Copyright©2006AccentureAllRightsReserved.SOAWorkshopStarterKit–WebServicesSecuritySOAWorkshopStarterKitSponsor:DavidL.NicholsLastUpdated:July,2006Version:2.0IntentofSection:ThisdocumentlaysdescribeskeyconceptsandconsiderationsforimplementationofawebservicessecurityarchitectureIntendedAudience:Forinternalandexternaluse(Unlessotherwisedocumented)MasterDocument:7-SOA_Workshop_WS-Securityv0.2.ppt10/05/05=71808&listid=ContributionsSOAforSeniorITExecutivesWorkshop–SecuringServiceOrientedArchitectures–AnthonyRobinson,London,February,2006(nolinkprovided)ToFindAdditionalSOAcontent:–V2.03Copyright©2006AccentureAllRightsReserved.Contents•SecurityandWebServices•IndustryStandards•WS*InDetail•PlatformSupport•RecommendationsSOAWorkshop–V2.04Copyright©2006AccentureAllRightsReserved.BusinessOpportunities•Newbusinessmodels•ServiceprovidersthatprovideIdentityrelatedservices•Serviceprovidersthatprovide“traditional”value-addedservices(e.g.,HRorpayroll)whichcanbemoreeasilyintegratedintoacustomer’senterprise•Driverevenuegrowth•Improveandstreamlinetheprocessforidentifyingandacquiringnewcustomers•Streamlineabilityforcollaborationwithbusinesspartners•Costsavings•Reduceuseradministrationcoststhroughautomation•Reduceapplicationdevelopment/integrationcoststhroughreusability•Improveuserexperience•Haveasingleidentitythatcanbeusedglobally•ImprovetheoverallsecuritythroughthereductionofdatasourcesandduplicatedataSignificantopportunitiesexistfororganizationstodriverevenuegrowth,createnewbusinessmodels,realizecostsavings,andimprovetheuserexperienceleveragingSecurityconceptsSOAWorkshop–V2.05Copyright©2006AccentureAllRightsReserved.SecurityConcernsLimitsUse(Source:“WebServicesSecurity”,MarkO’Neil,2003)(Source:SCMagazine,January2004)(Source:“MakingSenseofWebServicesSecurityStandards”,GartnerAug‘03)SecurityconcernshavehistoricallybeenoneofthekeyreasonsthatbusinesseshavenottakenadvantageofthebenefitsthatWebServicesandServiceOrientedArchitectureshavetooffer:“…theprospectofsoftwarefromdifferentcompaniescommunicatingtogether,whilepowerful,isfraughtwithsecurityconcerns.”“...unlesssecurityandmanagementissuesareaddressedeffectivelytheywillholdWebServicesbackfrombecomingatrulymainstreamtechnologywithinenterpriseapplicationintegrationprojects.”“ConflictingstandardsmakeWebServicessecuritydecisionscomplexanddifficult.(Companiesshould)beginwithsimpleWebServicesdeploymentsthatsupportonlyyourcurrentbusinessneeds.”Thisisnotjustatechnologyissue.SOAWorkshop–V2.06Copyright©2006AccentureAllRightsReserved.BusinessChallenges•Mitigatingriskandensuringqualitybetweenpartiesinthecircleoftrustcanbeperformedthrough:•Definitionofbusinessstandards•Definitionofminimumrequirements•EnforcementthroughcertificationandauditsMutualConfidence(Trust)•Pooledknowledge:sharingofcustomer/identityinformation(e.g.#ofcustomers,customernames,etc...)betweenorwithinenterprises–dataprivacy•Revocationprocedures:increasedrelianceonthirdpartiesforauthentication•Fraudprotection:broadenedpotentialforfraudifanidentityisevercompromised•Securityincidentprocedures:coordinatedeffortforanalysisandcorrelationofauditlogsamongpartiesinvolvedRisk•Whoisatfaultifacriticaltransactionfailedduetofailure?Towhatextent?•Definitionofliability•DefinitionofdisputeresolutionprocessLiability•Privacylegislation:ensureprivacytermsarenotviolatedwhenfederatinganidentitybetweenenterprises•Whoinitiatedeachtransaction–audittrailbacktoinitiatinguser.ComplianceKeyfactorsforwidespreadadoptionofwebservicesincludetheidentificationofsoundbusinessmodelsandmoreexperiencewiththecontractualframeworksthatdefinetrustrelationships.MostcurrentimplementationsareinternalthoughthisischangingSOAWorkshop–V2.07Copyright©2006AccentureAllRightsReserved.WhatareYOURSecurityRequirements?Non-RepudiationConfidentialityIntegrityIdentificationAuthenticationAdministrationAuthorizationAccountabilityThereareseveralnewbusinesschallengesthatmustbeaddressedbeforeWebServicescanbesecurelydeployedCanIensureprivacyofthetransactions(sensitivebusiness/clientdataregulatorycompliance,etc..)?CanIguaranteethattransactionsarenottamperedwith?CanIensurethatonlyauthorizedtransactionsarebeingperformedonthesystem?CanIensurethattherewillbeadequatecontrols/recordstoguaranteetheresultsofaprocessedtransaction?CanIquicklydeploynewserviceswithoutcompromisingmyinternalbusinessprocesses?CanIensurethattransactionsareonlybeingperformedbytrustedparties(sendorreceive)?SOAWorkshop–V2.08Copyright©2006AccentureAllRightsReserved.OvercomingtheSecurityBarriersAccenturehasproventhatnewstandardsandnewproductsarenowabletoprovidecustomizedsolutionstoovercomethesecuritychallengesWebServicesAccessControlEncryptionWebServicesDevelopmentPlatformsElectronicSignatureAuditingXMLFirewallsFederatedIdentityNon-RepudiationConfidentialityIntegrityIdentificationAuthenticationAdministrationAut

1 / 44
下载文档,编辑使用

©2015-2020 m.777doc.com 三七文档.

备案号:鲁ICP备2024069028号-1 客服联系 QQ:2149211541

×
保存成功