10.14. INTEGRATED POLICY ENFORCEMENT MODELS
Along with the unified model of policies, we need to develop an integrated concept of policy enforcement. We identified the barriers to an integrated policy enforcement model in Chapter 6. Here are the actions to be taken going forward in addressing this governance gap:
Encourage the horizontal integration of tools supporting end-to-end SOA and service lifecycle processes.
Establish a mapping of designtime policies to quality assurance and testing and runtime policies, and a consistent syntax and enforcement model to support it.
Establish integration standards for designtime tools with governance tools supporting design, quality assurance (QA)/test and runtime policy enforcement.
Establish industry standards for the vertical integration of enterprise, corporate, business and process policies with technical policies enforced across a corporate SDLC or project delivery processes.
Demand the development of integration between key governance processes and tools with project execution tools (e.g., portfolio management tools integrated with Integrated Development Environment (IDE) and software development tools, which may integrate with policy engines and policy repositories).
These are only partial solutions, but taken together, they may help in the creation of widely adopted industry standards for policies and policy enforcement models. Even a partial improvement will take us miles down the governance highway!
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access