I am thinking about writing a paper on security aspects of this service oriented, loosely coupled thing that everyone seems to be talking about. The problem I have with this is as follows.

Many people seem to have deep understanding of different specialised bits - related to SOA and their implementation, such as conceptual level architecture, underlying technology, but strangely enough, I haven’t seen an article connecting all dots in the puzzle. Unfortunately, security is cross-disciplinary, and connecting the application infrastructure, management, and business model dots is critical for the security design. And I haven’t seen any articles that would do this.

Slightly off tangent, I am also not convinced about economic impacts of all this. Despite various claims to contrary, I have a lurking suspicion that in the real world, SOA will be about as important as component or object-oriented development models were in the past. Which is quite important for developers, less important for infrastructure specialists and completely uninteresting for business people.

I will probably do something around this anyway as it looks like a good fun.

Comments are closed.