6.5. DERIVING SOA GOVERNANCE PRINCIPLES
SOA governance principles set the strategic role for IT and articulate expectations to support your business strategy and goals. The principles in Exhibit 6.3 are derived from a set of fairly typical SOA goals. In addition to these principles, we have highlighted expected categories of policies that would support or enforce those principles.
From our experience, it is useful to begin with policy categories first before delving into a fine-grained policy model comprised of specific policy statements and policy assertions. The use of policy categories will simplify the derivation of your SOA policies from SOA principles.
Also, remember that SOA policies are derived from two related analysis streams: First, they are derived from the top-down goals-principles-policies cycle we described above. Second, there are also some "policy absolutes" that will and must be governed, and these are related to SOA reference architecture and the SOA extensions to your enterprise architecture. For example, some SOA governance policy absolutes might include:
Figure 6.3. SOA Governance Principles and Policies
Security Policies
Authentication, authorization, and credential management
Encryption and signing of confidential content
Passing credentials within and across trust domains
Service Design and Implementation Policies
Service interface design standards
Service ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access