InfoQ

Interview

Mohammad Akif - SOA Beyond the Hype and the Security Development Life Cycle

Interview with Mohammad Akif on Dec 19, 2006

Community
.NET,
SOA
Topics
Security ,
.NET Framework
Summary
InfoQ sits down Mohammad to discuss the myths of SOA, common pitfalls in designing for SOA, J2EE and .NET interoperability and injecting the Security Development Lifecycle into enterprise development lifecycles.

Bio
Mohammad Akif is a Senior Architect Evangelist at Microsoft;member of the Microsoft Architecture Editorial Board, he presents and publishes frequently about Web 2.0, Web Services, Interoperability and Software Architecture best practices.He worked as a Senior Java Architect at Sun Microsystems Inc. He co-authored several publications and he contributed to the development of the J2EE core patterns.
I'm here with Mohammed Akif at VS Live in Toronto. Would you introduce yourself and tell us what do?
SOA, What's behind the hype? What's the real story behind SOA?
With SOA, when do you go with tight-coupling vs. loose-coupling?
The key thing is not to get too granular with it and keep your services coarse.
A service with only one customer or one user isn't really necessary. If it's going to be used by one thing what's the point of abstracting that out?
To expand a little more on who's using this service, there's the whole interop story. What are the challenges on the interop space now?
What are some of the things you can do to address security in your development process?
So that is part of the whole "Secure by Default" Initiative.
Jesper Johansson does a wonderful talk where he starts with a SQL injection attack and literally hacks his way through two domains to the main accounting server in his scenario and he does it live and it's a frightening demonstration of what is possible.
As an architect how do you design security in your architecture, in your process upfront so that there's no choice but to do it because it's part of the overall architecture?
For example for each milestone you have a quality gateway that says: Are these security issues addressed and if they are not you don't move forward.
So you're not talking about somebody who knows how to configure Active Directory, but someone with experience in multiple technologies and platforms?
I'd like to thank you for showing your time with us today. Do you have any final words?
show all  show all
Please do revert by Jeeten Masrani Posted Mar 13, 2007 10:30 AM
  1. Back to top

    Please do revert

    Mar 13, 2007 10:30 AM by Jeeten Masrani

    Greetings

    Let me introduce myself , I am Jeeten C, a Bangalore based consultant. I happen to view your profile while surfing on the net and thought if I could suggest a few opportunities which I am currently working on in the area of Research and Development for few of the premier and most admired companies.

    Kindly get back to me with your contact number and a available slot to call so that we could discuss and take it forward or updated profile which I can take into procees.

    Thanks & Regards
    Jeeten/c
    Associate - Executive Search

Educational Content

Brian Marick on 4 Challenges and 5 Guiding Values of Agile Software Development

Brian Marick takes us through a quick tour of the most important values and challenges to adopting Agile successfully (they aren't the typical challenges and values we hear in the community).

Are You a Software Architect?

The line between development and architecture is tricky. Does it exist at all? Is an ivory tower actually needed? There's a balance in the middle, but how do you move from developer to architect?

Agile – A Way of Life and Pragmatic Use of Authority

The word 'authority' sometimes produces an allergic response in hard-line agilists. Freedom and authority – both are bad if misused and both are good if used in right spirit for a noble cause.

Getting Started with Grails, Second Edition

"Getting Started with Grails" brings you up to speed on this modern web framework. Companies as varied as LinkedIn, Wired, and Taco Bell are all using Grails. Are you ready to get started as well?

Using ITIL V3 as a Foundation for SOA Governance

Those familiar with only ITIL V2 often scoff at the thought that ITIL could serve as a governance framework for SOA. With ITIL V3, the focus of the framework shifted towards service-orientation.

Adrian Colyer on AspectJ, tc Server and dm Server

SpringSource CTO Adrian Colyer discusses AspectJ, SpringSource's dm Server and tc Server products, OSGi and Scrum.

Adam Wiggins on Heroku

Heroku's Adam Wiggins talks about Rails, Background Jobs, Add-Ons, Ruby, and how Heroku manages to work around Ruby's inefficiencies using Erlang and other languages.

SOA as an Architectural Pattern: Best Practices in Software Architecture

For Grady Booch the foundation of a good architecture is patterns, SOA being just one of many patterns. In this Second Life presentation, Booch attempts to bring more clarity on what architecture is.