Advertisement
Co Presented By
Co Presented By

From SOA To SOA Governance

Despite its celebrity status, SOA remains one of the least understood topics in the enterprise space.

Advertisement
Rajendra Chaudhary|Aug 22, 2007, 13:36:38 IST

Given the amount of press Service Oriented Architecture (SOA) has received in the last couple of years, it wouldn’t actually be a bad analogy if one compared it with a major Hollywood celebrity. Continuous string of events, seminars, panel discussions, research reports and news articles have ensured that SOA remains the hottest topic of interest in the enterprise IT consciousness.

Advertisement

And yet despite its celebrity status, SOA remains one of the least understood topics in the enterprise space. In the past, proponents of SOA kept presenting compelling arguments favouring SOA and how organisations need to move toward SOAization and have SOA as the foundation for their IT infrastructure.

But the element that often got ignored (may be not deliberately so) or got lost somewhere in the SOA talk was the amount of complexity that SOA tends to bring in and the importance of a good governing framework for a successful SOA deployment.

biztechMore from Biztech

But that was yesterday, fortunately this is starting to change and increasingly we find that the talks are now centered on SOA governance rather than SOA itself. Yes, they are now talking about SOA governance.

Why SOA Governance?

Before we proceed any further, let’s just establish the case for SOA governance. SOA governance is important simply for the reason that it lets you analyse and plan projects a whole lot better and thus increases the success probabilities of those projects.

Advertisement

According to Tilak Mitra, executive architect in IBM and a SOA Subject Matter Expert, SOA governance allows enterprises to realise the business benefits of SOA and ensures flexibility in the enterprise business processes. “SOA governance can help mitigate business risk, regain control through maintaining quality of service of the runtime services and ensuring consistency of service. It can also lead to improved team effectiveness through establishing an efficient communication mechanism between business and IT,” said Mitra.

In addition to this, SOA governance also allows to define the dependencies from an interoperability point of view to the consumers be it an enterprise architect, a developer or a project manager.

Adding to the list of reasons why an efficient SOA governance mechanism is needed Toufic Boubez, CTO, Layer 7 Technologies said, “There are two factors that make SOA governance an urgent requirement. First, we live in a new regulatory environment consisting of Sarbanes-Oxley, HIPAA, HL7 and Basel II. This new environment requires much more stringent oversight, monitoring and enforcement of corporate and IT governance policies. Secondly, loose coupling, a fundamental SOA tenet, is a double edged sword. Along with the potential for much greater IT flexibility and business agility, it brings the potential for harder oversight.”

Advertisement

Elements of SOA Governance Strategy

Ok, now that we’ve firmly established the need for governance, let’s look at some of the crucial elements that enterprises need to take into account when they chart a governance strategy. The best way to go about this is to first define SOA governance goals, and perform a gap analysis in order to establish a clear roadmap centred on elements such as organisational structure, policies and processes, enterprise architecture, and infrastructure and tools.

“It helps to have the right people, skills and roles in place in order to effectively implement, enforce and monitor your governance policies. On the policies and processes side, having a comprehensive set of corporate and IT policies (such as technology standards such as WS-Security, WS-Policy; industry standards such as HL7; security policies for identity and access management, data integrity and confidentiality) and appropriate processes to create, enforce and monitor these policies is a must,” according to Boubez.

As far as having the right level of enterprise architecture is concerned, organisations need to establish global, corporate-wide oversight and guidelines for their architects in addition to departmental or project architecture. These guidelines should take into account the goal of building a Service Oriented enterprise, and ensure that project design goals meet the overarching requirements of the enterprise, not just the particular project. The enterprise architecture would set guidelines for creating, registering and deploying services and interfaces; for separating enforcement points from component logic, etc.

And last but certainly not the least, the right tools to enable policy enforcement, monitoring, reporting, auditing, and remedial action. This includes Policy Enforcement Points (PEPs), service registries, messaging backbone, auditing, monitoring and reporting tools.

According to James Kobielus, principal analyst, Current Analysis, “SOA governance often involves new layers of business and IT bureaucracy. In other words, it may require that companies institute a high-level planning and prioritisation process, under which new services are approved and SOA-wide corporate policies are hammered out.”

Need to manage Individual Service Lifecycles

Along with the above mentioned requirements, another crucial element that needs attention is the efficient management of individual service lifecycle. SOA introduces an entirely new concept wherein organisations create “productised” services that can be consumed both internally as well as externally. Now, typical code assets in the past didn’t have product management lifecycle that extended beyond your own IT organisation, but with SOA these services become products or enterprise assets that people throughout the enterprise can consume and even offer them to external consumers like trading partners etc. It is for this reason management of individual service lifecycles is crucial to SOA governance.

Another reason for managing service lifecycles is preventing abuse by exercising greater control.

“Lifecycle management is one of the main tasks in any SOA governance strategy because SOA puts a large amount of flexibility in the hands of developers, with the consequence that this flexibility can be easily misused. Therefore, every aspect of a service lifecycle, from requirement, to design, to implementation, to deployment, to access control, to versioning, to phasing out, needs to be controlled, monitored and audited,” told Boubez.

Delving further on the issue of lifecycle management, Mitra opined that any service that has direct alignment with the business goals and has a proper ownership model attached to it is critical to be managed.

According to him, “The more organised the management of a service lifecycle is, the more efficient and controlled is the SOA governance framework. Which ones to manage more critically than the other is one of the decisions that the SOA governance framework undertakes.”

Hurdles in establishing SOA Governance

If someone asks what’s the definition of good SOA governance model? The answer, though highly clichéd, is fairly simple. A good governance model is one that bridges the divide between the business and IT though successful SOAization across an enterprise. But in a real sense, SOA governance is a never ending fight between the business side and the IT.

More often than not, time and organisational commitment prove to be the most challenging factors for SOA governance.

"To be able to sell to the business stakeholders, the business value of and the relevance of SOA governance in an enterprise SOA undertaking, before it is actually implemented and its effectuality proven in practice, and convince them to invest in SOA governance, is often times the most challenging task. Establishing an SOA Centre of Excellence (CoE), a key aspect of an efficient SOA governance mechanism, and to invest in people, process and technology in the CoE is another hard point to prove the worth of before its benefits can be realised," informed Mitra.

Some of the other challenges which hinder SOA governance include, defining high value business services, institutionalising a proposed change in the organisational structure, measuring the effectiveness of the governance mechanism and managing the lifecycle of assets.

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Aug 22, 2007, 13:36:38 IST
Advertisement
Advertisement
Advertisement
Advertisement
Up Next