Eve Maler serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
Follow Eve on Twitter.
Eve Maler serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
Follow Eve on Twitter.
Posted by Eve Maler on July 15, 2011
“There is no enterprise — the work we do is a collection of people that dynamically changes through a mix of organization control.” That’s what I heard from one venerable old construction company while working on my new research report, Protecting Enterprise APIs With A Light Touch. I wanted to investigate how enterprises are using and securing lightweight RESTful web services, and in particular to figure out the problems for which OAuth is well suited. (You might recall my request for feedback in a prior post.)
What I found was that forward-thinking enterprises of many types – not just hip-happenin’ Web 2.0 companies – are pushing service security and access management to the limit in environments that can truly be called “Zero Trust,” to use John Kindervag’s excellent formulation. This particular firm dynamically manipulates authorizations to control access to a variety of innovative lightweight APIs on which the whole company is being run, not actually distinguishing between “internal” and “external” users. They’ve kind of turned themselves inside-out.
No more chewy centers, indeed. And OAuth is playing an increasing role in a variety of business scenarios, from B2B to identity federation to variants on classic SOA security, wherever light weight and agility are prized. I hope you’ll get a chance to check out the report to see my recommendations for using OAuth effectively in whisper-light app environments, and weigh in here with your thoughts.
p.s. Alex Crumb and I experimented a bit in putting this report together, reaching out through a variety of social-media vectors to gather data. Special thanks to those folks on Twitter who gave me great tips!
Attend Forrester’s Forum for Security & Risk Professionals EMEA, June 10-11, London UK
Comments
Eve - agree with this stance
Eve - agree with this stance completely. It's all about providing access to the information and leveraging Web services and the cloud to do so. Just the next step in our conversations a few years about deperimiterization. With more data moving to the cloud, companies need to focus on developing "network of trust" and access control rules that balance security and access. Thanks!
Now a days companies are also
Now a days companies are also moving towards automated web development software.