49,797 Members
0 added today
329,652 Resources
35 added today

All Devdex   All Gurus  

Securing Data beyond PCI in a SOA environment - Best Practices for Advanced Data Protection
Author: Ulf Mattsson
Rating: Rate this Resource
Visits: 2985

Discuss in Newsgroups

Page:

New business models rely on open networks with multiple access points to conduct business in real time, driving down costs and speeding responses to revenue generating opportunities. That’s the good news. The bad news is that this modern business architecture is often riddled with vulnerabilities that can easily be exploited to gain unauthorized access to sensitive information.

To make life even more exciting, you can’t rely on traditional best practices like establishing strong boundaries around critical applications to secure SOAs or you’ll be defeating the features and flexibility that SOA brings to the enterprise.

Another attractive feature of SOAs is the use of standardized contracts and contract retrieval methods, which make life much easier for developers, authorized users and malicious hackers. Using a collection of freely available contract descriptions a hacker can target weakly authenticated or high-value services, easily penetrate an improperly secured SOA, eavesdrop on SOAP message traffic and see information that may be private. In addition, it is relatively easy to intercept a SOAP message in an unsecured SOA and reroute it or transform its content for purposes of mischief or fraud.

Layers of security -- including integrated key management, identity management and policy-based enforcement as well as encryption are essential for a truly secure SOA. This article reviews a practical implementation of a transparent, risk-based management approach that can be used to lock down sensitive data utilizing policy driven encryption and key management for data-at-rest and in-transit across enterprise systems. 


Next Page >>

Visitor Comments

Be the first to rate this article!

 

Rate this Article







	
	
	



ASP.NET Web Hosting
- FREE Setup & Domain
- First month FREE
100% IIS6 / Server 2003

ASP ArticlesThis category has been added to your weekly newsletter
ASP Web Sites
ADSI & WSH BooksThis category has been added to your weekly newsletter
FREE ComponentsThis category has been added to your weekly newsletter
ASP EventsThis category has been added to your weekly newsletter
ASP HeadlinesThis category has been added to your weekly newsletter

CSharp ArticlesThis category has been added to your weekly newsletter
C# Web SitesThis category has been added to your weekly newsletter

SQL ArticlesThis category has been added to your weekly newsletter
SQL Events
SQL HeadlinesThis category has been added to your weekly newsletter
SQL Jobs

Jobs in CaliforniaThis category has been added to your weekly newsletter

XML ArticlesThis category has been added to your weekly newsletter
XML BooksThis category has been added to your weekly newsletter
XML Web Sites
XML Tutorials

free asp host

"Alex Homer"This search has been added to your weekly newsletter

Edit My Favorites Edit Profile & Favorites

 




Developersdex Home | ASP | C# | SQL | VB | XML | Gurus
Add Your Link | Add Your Code | FAQ | Advertise | Link To Us | Contact Us |
Copyright © 2010 Developersdex™. All rights reserved.