Click here to close now.


Related Topics: Microservices Expo

Microservices Expo: Article

SOA Governance Best Practices – Architectural, Organizational, and SDLC Implications

Taking the management of services to the next level

Influencing SOA Behavior
Determining and shaping the behavior patterns that will sustain an SOA effort through time is often the work of change management specialists. However, it is easier to conceptualize the role of behavior in SOA if we examine the intersection of major influences on organizational and individual behavior. Some of these influences are the following:

  • Corporate culture
  • Major decision-making processes
  • Budgeting processes
  • Incentives and penalty structures
  • Compensation linkages to corporate goals and mantras
  • Portfolio management processes
  • Architecture process (definition, acquisition, implementation)
  • Architecture practice (solutions development)
  • Corporate performance metrics, such as return on invested capital (ROIC), revenue and market share growth, cost controls, etc.
  • Promotion and advancement criteria
All of these factors influence behavior of organizations and individuals within an enterprise. In the context of an SOA, however, there are a few key factors that determine how effective an SOA can be without fundamental changes to the organization and processes of an organization. To understand these essential factors, we must locate the "center of gravity" of an SOA. Understanding certain key organizational and process relationships will help with the organization of SOA governance, the design of SOA governance processes, as well as understanding the behavior and incentive models that may be required in order to implement SOA governance. For example, the relationship of the budgeting process to project execution and implementation helps determine how effectively budgeting oversight impacts the resulting architecture of IT systems. Without proper budget-to-project alignment, teams will be inclined to build project-centric services that don't necessarily fit the broader needs of the organization's SOA. The relationship of the acquisition/procurement process to enterprise architecture is another key relationship that has a tremendous impact on the resulting architecture of an organization. Does the acquisition process reflect the goals and standards of the EA organization? If not, how can it be changed to better reflect it?

Another critical relationship is the relationship of EA to project or solution architecture - in other words, connecting architecture via governance to downstream activities (more on this in the next section of this article). If there is a disconnection between enterprise architecture and the architecture that is designed at the project level, then there is the possibility of a disjointed architecture.

These important relationships all point to how sociopolitical forces and organizational forces converge to either facilitate or hinder SOA governance. There are no easy answers to these challenges. However, understanding how these organizational tensions either help or hinder SOA governance will point to a path to implementing appropriate organizational institutions and processes to achieve SOA governance objectives.

Production/Distribution/Consumption: Separation of Concerns Within SOA Governance
SOA, in conjunction with other loosely coupled architectural approaches, forces IT organizations to recognize that teams producing services are not likely to be the consumers of those services. Unlike traditional application development, SOA is built upon the premise that a set of services can be employed within a wide range of applications. In other words, SOAs depend upon the separation of the production and consumption concerns within the IT organization, and a distribution vehicle that allows service producers and consumers to communicate and collaborate with each other. Let's define these production, distribution, and consumption concerns with a bit more detail:

  • Production: Identification of and governance over the development and maintenance of existing and newly defined candidate reusable services
  • Distribution: Publication of those services for widespread dissemination to potential service consumers
  • Consumption: Discovery of and governance over the appropriate use of services within application development projects
While it may be technically feasible to execute the responsibilities within these concerns through manually defined and managed procedures, the reality is that for IT organizations of any size to build out a successful SOA, both political/organizational issues such as those discussed in the previous section, and appropriate tooling such as a services repository/registry that automates both service governance and service distribution are essential. The following sections of this article highlight how a services repository/registry can be employed to support key best practices within the production/distribution/consumption life cycle inherent within SOA.

Production Best Practice: Pragmatic Service Definition
Services within an SOA cannot be developed in a "bottom-up," ad hoc manner. Bottom-up development of services is inherently driven by immediate project needs - how do I solve this specific problem with a specific implementation (often driven by the influence of existing applications and their behaviors masquerading as true business requirements). What happens when an organization defines and implements its services with this mindset? The service layer simply becomes YALOT (yet another layer of technology) - more spaghetti code of a different form that didn't improve our business process flexibility, but simply implemented a monolithic application in a different technology.

However services also cannot be defined solely in a "top-down" manner. Top-down business process analysis left to its own devices leads to either "analysis paralysis" - continual refinement of a model hoping to reach perfection (which never comes), or "Big-Bang" projects - trying to define and implement everything at once, usually with disastrous consequences (most typically a combination of "death march" projects and cost and schedule overruns).

Ultimately, what organizations need to make progress in SOA is to develop a coarse-grained business model driven by key business processes (not all of them, but only a representative set of high-priority processes to begin with). Architects and business analysts should collaborate to build this model using those processes to extract and define a normalized set of functions, then grouping those functions together based on behavioral affinity (read components and interfaces for those of you who are UML centric) as a strawman set of initial target service definitions.

At this point, we have a useful framework for the "real work" - detailed analysis, design, and implementation of the services we need for our current set of prioritized projects. Based on business process (and project) prioritization, we identify the needed services from our business reference model and formalize the service definition for these prioritized services. Ideally, each service should be driven by the requirements extracted from at least two separate processes - designing a service based on a single use case is very likely to result in a fragile and narrowly defined service that will not be flexible enough to meet our next set of prioritized projects. Our formalization efforts are likely to result in modifications to our business architecture - which is just fine! We can iteratively enhance our architecture as we make progress towards service implementation.

Production Best Practice:
Recommended Service SDLC Governance/Review Checkpoints
Now that we have our first set of services defined, we need to build and deliver them. Developing services within an SOA (i.e., for purposes of reuse across multiple applications) usually requires more of the production team than a single-use component, module, or object. In order for a service to be considered reusable, it must be maintainable, discoverable, and consumable. Maintainability introduces such concepts as version control (which we will address in more detail later in this article), models and other design documentation, and requirements traceability (why was the asset implemented in this way from a technical and business perspective). Discoverability forces us to consider how we help potential consumers of this asset find the asset in a timely fashion - via keywords, domain taxonomies, and mapping to models, for example. Consumability involves looking at the asset from the point of view of the downstream project planning to use the asset: Is there a user guide, a well-documented API, sample client code, and other artifact available to help the user rapidly understand how to apply this asset to the project at hand? Are dependencies on other assets (and to prior versions of this asset) specified and easily navigated?

More Stories By Brent Carlson

Brent Carlson is vice president of technology and cofounder of LogicLibrary, a provider of software development asset (SDA) management tools. He is the coauthor of two books: San Francisco Design Patterns: Blueprints for Business Software (with James Carey and Tim Graser) and Framework Process Patterns: Lessons Learned Developing Application Frameworks (with James Carey). He also holds 16 software patents, with eight more currently under evaluation.

More Stories By Eric Marks

Eric Marks is founder, president, and CEO of AgilePath Corporation, a service-oriented architecture (SOA) and Web services consulting firm based in Newburyport, MA. Marks is a software and technology veteran with 18 years of experience with firms including PricewaterhouseCoopers, Cambridge Technology Partners, Novell, Electronic Data Systems, StreamServe, Ontos, and Square D/Schneider Electric.

Comments (2) View Comments

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.

Most Recent Comments
robertmorschel 10/10/12 03:57:00 AM EDT

In my experience SOA needs to begin with a single, skilled team that can define evolving standards and processes in an agile manner, before being let loose on the enterprise; and even then, only if the enterprise has an established and effective centralised governance function that would be able to enforce SOA policies across multiple teams.


Gary Smith - SOA Network Architect 02/22/06 11:51:19 AM EST

Excellent. This puts governance into perspective.
All the hype around SOA appliances and governance shouldn't have you running out and putting these devices on your network until you understand what governance is all about.


Latest Stories
DevOps and Continuous Delivery software provider XebiaLabs has announced it has been selected to join the Amazon Web Services (AWS) DevOps Competency partner program. The program is designed to highlight software vendors like XebiaLabs who have demonstrated technical expertise and proven customer success in DevOps and specialized solution areas like Continuous Delivery. DevOps Competency Partners provide solutions to, or have deep experience working with AWS users and other businesses to help t...
The modern software development landscape consists of best practices and tools that allow teams to deliver software in a near-continuous manner. By adopting a culture of automation, measurement and sharing, the time to ship code has been greatly reduced, allowing for shorter release cycles and quicker feedback from customers and users. Still, with all of these tools and methods, how can teams stay on top of what is taking place across their infrastructure and codebase? Hopping between services a...
Containers are changing the security landscape for software development and deployment. As with any security solutions, security approaches that work for developers, operations personnel and security professionals is a requirement. In his session at @DevOpsSummit, Kevin Gilpin, CTO and Co-Founder of Conjur, will discuss various security considerations for container-based infrastructure and related DevOps workflows.
WebRTC has had a real tough three or four years, and so have those working with it. Only a few short years ago, the development world were excited about WebRTC and proclaiming how awesome it was. You might have played with the technology a couple of years ago, only to find the extra infrastructure requirements were painful to implement and poorly documented. This probably left a bitter taste in your mouth, especially when things went wrong.
Enterprises can achieve rigorous IT security as well as improved DevOps practices and Cloud economics by taking a new, cloud-native approach to application delivery. Because the attack surface for cloud applications is dramatically different than for highly controlled data centers, a disciplined and multi-layered approach that spans all of your processes, staff, vendors and technologies is required. This may sound expensive and time consuming to achieve as you plan how to move selected applicati...
Nowadays, a large number of sensors and devices are connected to the network. Leading-edge IoT technologies integrate various types of sensor data to create a new value for several business decision scenarios. The transparent cloud is a model of a new IoT emergence service platform. Many service providers store and access various types of sensor data in order to create and find out new business values by integrating such data.
The broad selection of hardware, the rapid evolution of operating systems and the time-to-market for mobile apps has been so rapid that new challenges for developers and engineers arise every day. Security, testing, hosting, and other metrics have to be considered through the process. In his session at Big Data Expo, Walter Maguire, Chief Field Technologist, HP Big Data Group, at Hewlett-Packard, will discuss the challenges faced by developers and a composite Big Data applications builder, foc...
The cloud has reached mainstream IT. Those 18.7 million data centers out there (server closets to corporate data centers to colocation deployments) are moving to the cloud. In his session at 17th Cloud Expo, Achim Weiss, CEO & co-founder of ProfitBricks, will share how two companies – one in the U.S. and one in Germany – are achieving their goals with cloud infrastructure. More than a case study, he will share the details of how they prioritized their cloud computing infrastructure deployments ...
There are so many tools and techniques for data analytics that even for a data scientist the choices, possible systems, and even the types of data can be daunting. In his session at @ThingsExpo, Chris Harrold, Global CTO for Big Data Solutions for EMC Corporation, will show how to perform a simple, but meaningful analysis of social sentiment data using freely available tools that take only minutes to download and install. Participants will get the download information, scripts, and complete en...
Data loss happens, even in the cloud. In fact, if your company has adopted a cloud application in the past three years, data loss has probably happened, whether you know it or not. In his session at 17th Cloud Expo, Bryan Forrester, Senior Vice President of Sales at eFolder, will present how common and costly cloud application data loss is and what measures you can take to protect your organization from data loss.
WebRTC: together these advances have created a perfect storm of technologies that are disrupting and transforming classic communications models and ecosystems. In his session at WebRTC Summit, Cary Bran, VP of Innovation and New Ventures at Plantronics and PLT Labs, will provide an overview of this technological shift, including associated business and consumer communications impacts, and opportunities it may enable, complement or entirely transform.
SYS-CON Events announced today that Dyn, the worldwide leader in Internet Performance, will exhibit at SYS-CON's 17th International Cloud Expo®, which will take place on November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. Dyn is a cloud-based Internet Performance company. Dyn helps companies monitor, control, and optimize online infrastructure for an exceptional end-user experience. Through a world-class network and unrivaled, objective intelligence into Internet condit...
Between the compelling mockups and specs produced by analysts, and resulting applications built by developers, there exists a gulf where projects fail, costs spiral, and applications disappoint. Methodologies like Agile attempt to address this with intensified communication, with partial success but many limitations. In his session at DevOps Summit, Charles Kendrick, CTO and Chief Architect at Isomorphic Software, will present a revolutionary model enabled by new technologies. Learn how busine...
Interested in leveraging automation technologies and a cloud architecture to make developers more productive? Learn how PaaS can benefit your organization to help you streamline your application development, allow you to use existing infrastructure and improve operational efficiencies. Begin charting your path to PaaS with OpenShift Enterprise.
Achim Weiss is Chief Executive Officer and co-founder of ProfitBricks. In 1995, he broke off his studies to co-found the web hosting company "Schlund+Partner." The company "Schlund+Partner" later became the 1&1 web hosting product line. From 1995 to 2008, he was the technical director for several important projects: the largest web hosting platform in the world, the second largest DSL platform, a video on-demand delivery network, the largest eMail backend in Europe, and a universal billing syste...