Security for the service-oriented architecture (SOA) was described by Brian V. Cummings of Tata Consultancy Services at the IBM SHARE conference this week. In general, a company's data is always the security prize, and providing good security means managing a reasonable restriction to that data. The goal for security personnel is to balance security risks with the enablement of users, he said.
Cummings defined SOA according to IBM's definition, which is that SOA is an IT architectural style that supports service orientation. The trend is to use SOA as a way to integrate businesses using linked services. SOA involves publishing and discovering services. Applications are loosely coupled in an SOA and offered up as services, and, for that reason, the registry becomes an important concern for security in an SOA.