Managing Web Services Security
Kenny Khoo, Lina Zhou · Journal of the Association for Information Systems · 2004
The promising features of Web services also make them vulnerable to new types of security threats.Web service providers must assure their clients confidentiality, integrity and availability over a trusted relationship that may be asynchronous and that may involve multiple business partners.Despite the continued significance of the traditional approaches to securing content, transmission and connection in a Web-based business environment, including Secure Socket Layer, Virtual Private Networks, Internet Protocol Security, and so on, they are not able to address the new challenges posed by Web services.This paper aims to provide insight into the management of Web services security.It first introduces the key concepts and reviews state-of-the-art Web services security standards.Then, it aligns the Web services security standards with security threats to provide guidance for the practical implementation of Web services security.Finally, it points out some limitations in the current practice and highlights the managerial implications.