Home > Ask the Software Quality Experts > Application Security Questions & Answers > Why do Web services impact security?
Ask The Software Quality Expert: Questions & Answers
EMAIL THIS

Why do Web services impact security?

Alex Smolen EXPERT RESPONSE FROM: Alex Smolen

Pose a Question
Other Software Quality Categories
Meet all Software Quality Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 10 January 2006
What are Web services and why do they impact security?

>
"Web services" is a fairly broad term applied to a set of technologies that conform to the basic idea that services that process and consume data should be able to communicate regardless of platform or implementation. Web services are used for many different purposes, and have the potential to be widespread throughout the industry and the Web. The common thread through Web services is XML, which organizes the data that is passed back and forth. There are Web services interoperability standards organizations, such as OASIS, WS-I and W3C, which provide common guidelines to promote shared standards of message formatting and delivery.

When it comes to Web service security, there is a broad range of issues to deal with. Web services are being used to replace previously proprietary inter-process communication schemes, such as RMI and EDI, as well as provide new means of distributing data on the Web (think AJAX and Web APIs). Besides traditional security concerns, such as verifying authentic users and guarding against potentially dangerous submitted data, Web services architects and developers must be very careful about the kinds of information they expose, the business processes they allow to be run and the potential security implications of providing what is essentially an API to a general, anonymous audience. That being said, all of the vendors who are pushing Web services are working to solve these problems. An organization's success in creating secure Web services typically boils down to how well the organization's security requirements are elucidated, designed for, and implemented.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Building security into the SDLC (Software development life cycle)
ALM boundaries are expanding in application development
Top software testing and quality assurance news stories from 2009
Aligning business goals with Focus Stories
Which requirements have the greatest effect on quality in software development?
How to write an SRS document for three different databases
Problems caused by skipping analysis stage of SDLC
Inexpensive phase of SDLC to catch and fix bugs
GatherSpace beefs up cloud-based requirements management
ALM: Best of breed vs. complete systems
Software development life cycle phases, iterations, explained step by step

Application Security
Are SQL injection attacks really a big software security risk?
Beating software's cross-site scripting, authentication problems
Expert resolves issues plaguing OpenSTA users
What is fuzz testing? What are some ways to use fuzz testing?
How do I convince management to take application security seriously?
Security testing sales, marketing websites
Top tools for testing Web application security
How to prevent HTTP response splitting
PCI DSS compliance: WAF, code review or both?
Open source application security testing tools

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
SQL injection  (SearchSoftwareQuality.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Software Quality - Software Maintenance, Software Requirements, Software Standards
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts