6.14. POLICY GRANULARITY
SOA implementations almost always trigger discussions about the notion of service granularity—of course referring to the relative coarse or fine-grained size of services and the industry best practices, or lack thereof. What has not been a topic of discussion is the concept of "policy granularity."
Policy granularity refers to certain scenarios where SOA policies span multiple levels of the enterprise and therefore require a multi-level policy enforcement model. Security is a good example of a policy that is enforced at multiple levels, beginning with a simple coarse-grained policy statement and then ultimately enforced automatically at service run time via security appliances and other automated enforcement mechanisms. Exhibit 6.6 depicts the concept of a coarse-grained business policy being decomposed and translated into fine-grained policies that can be enforced manually at design time and automatically at run time.
Figure 6.5. A Policy Meta Model and Policy Taxonomy
In this case, security is a business policy, a process policy, a technical service design policy and a runtime policy. The business version of the security policy might be written as follows: "All IT initiatives must conform to the corporate security policy. All IT projects must submit the security conformance declaration form, be reviewed by enterprise architecture and the corporate security ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access