Where should you put your Web services security?
According to a new report from the Burton Group, you should put it everywhere as part of a layered defense network incorporating public key infrastructure and identity management as part of the mix.
Key to all of it, according to Anne Thomas Manes, Burton Group vice president and research director, is using both XML security devices for intermediary and access points with Web services management intelligence enforcing policy at the endpoints of the network.
"I don't think it's appropriate to rely on just the hardware devices or just the Web services managers," Manes said. "The combination is the way to go."