4.5. GOVERNANCE AND POLICY ENFORCEMENT MODEL
As you transition from the SOA policy model to enforcement of policies, you must consider three broad policy enforcement mechanisms for your enterprise: (1) a governance organizational model, including boards and committees; (2) governance processes, enforcement triggers and events; and (3) automated policy enforcement via governance-enabling technology and tools.
Integrating these three broad categories of policy enforcement mechanisms forms a holistic fabric of SOA governance and policy enforcement for your enterprise. Exhibit 4.7 depicts the concept of an integrated policy enforcement model.
The mechanisms must be integrated into a comprehensive and holistic governance model without being too oppressive and overbearing, and yet they must provide policy enforcement coverage for critical policies across critical SOA processes for your enterprise.
As you develop the policy enforcement model, you must consider two initial scenarios for various policies: automated policy enforcement via SOA enabling technology and tools, and manual policy enforcement via governance organizations, boards, and committees. These are the two extremes, with the potential for technology-enabled policy enforcement as a middle ground approach. The tools and technologies of SOA governance are very immature, and the industry standards for SOA policy are similarly works in progress.
Exhibit 4.8 depicts the bifurcation of policy enforcement scenarios into manual ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access