Sunday, October 21, 2007

SOA Security

The National Institute of Standards and Technology has released a 128-page guide to help organizations understand the security challenges of Web services in service-oriented architecture. Download link http://csrc.nist.gov/publications/nistpubs/800-95/SP800-95.pdf

Issues addressed in the publication include:

  • Confidentiality and integrity of data transmitted via Web services protocols.
  • Functional integrity of the Web services requiring the establishment of trust between services.
  • Availability in the face of denial-of-service attacks that exploit vulnerabilities unique to Web service technologies.

Web site dedicated to Service Oriented Security http://www.service-orientedsecurity.com/

California Enterprise Architecture Program issues SOA Security White Paper http://www.cio.ca.gov/caIT/pdf/SOA_Security_White_Paper.pdf

Free SOA Security E-Book http://www.team509.com/download/docs/security/hacking/McGraw.Hill.Osborne.Media.XML.Security.eBook-TLFeBOOK.pdf

BPM and Security from James McGovern http://duckdown.blogspot.com/2006/12/thoughts-on-bpm-and-security.html

Colin White on SOA Security and reuse http://colin.trematon.com/enterprise-business/soa-security-and-enterprise-reuse/

Most of these are courtesy of Garry E. Smith