How can security policies be centralized across an enterprise's set of Web
applications? In particular, we examine the case of security policies for web
services and for traditional websites and describe how the two can be
administered and enforced together to improve both the cost of administration
as well as the strength and flexibility of the security system.
Web Services and Websites: Different or the Same?
Organizations have significant investments in web-delivered applications. To
date, these web systems have typically taken the form of websites serving up
HTML pages accessible via web browsers. These systems include employee
intranets, partner extranets, and consumer websites of infinite variety. The
architecture of these sites is generally three-tier web applicatio... (more)