NIH | National Cancer Institute | NCI Wiki  

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Children Display

Page info
title
title

Governance Policies Functional Profile

Service Oriented Architecture is an architectural paradigm for organizing and utilizing distributed capabilities that may be under the control of different ownership domains. Consequently, it is important that organizations that plan to engage in service interactions adopt governance policies and procedures sufficient to ensure that there is standardization across both internal and external organizational boundaries to promote the effective creation and use of SOA-based services.

SOA governance requires numerous architectural capabilities on the Semantic Infrastructure:

Governance is expressed through policies and assumes multiple use of focused policy modules that can be employed across many common circumstances. This is provided by

From inherited abstract Artifact Functional Profile

An artifact is a managed resource within the Semantic Infrastructure.

An artifact is associated with the following capabilities:

  • descriptions to enable the policy modules artifact to be visible, where the description includes a unique identifier for the policy artifact and a sufficient, and preferably a machine process-ableprocessible, representation of the meaning of terms used to describe the policyartifact, its functions, and its effects;
  • one or more discovery mechanisms that enable searching for policies artifacts that best meet the search criteria specified by the service participant; where the discovery mechanism will have access to the individual policy artifact descriptions, possibly through some repository mechanism;
  • accessible storage of policies artifacts and policy artifact descriptions, so service participants can access, examine, and use the policies as defined.artifacts as defined.
From inherited abstract Change Functional Profile

Artifact descriptions change over time and their contents will reflect changing needs and context.

Architectural implications of change on the Semantic Infrastructure are reflected in the following capabilities:

  • mechanisms to support the storage, referencing, and access to normative definitions of one or more versioning schemes that may be applied to identify different aggregations of descriptive information, where the different schemes may be versions of a versioning scheme itself;
  • configuration management mechanisms to capture the contents of the each aggregation and apply a unique identifier in a manner consistent with an identified versioning scheme;
  • one or more mechanisms to support the storage, referencing, and access to conversion relationships between versioning schemes, and the mechanisms to carry out such conversions.
From inherited abstract Composition Functional Profile

Artifact Descriptions may capture very focused information subsets or can be an aggregate of numerous component descriptions. Service description is an example of a likely aggregate for which manual maintenance of all aspects would not be feasible.

Architectural implications of composition on the Semantic Infrastructure are reflected in the following capabilities:

  • tools to facilitate identifying description elements that are to be aggregated to assemble the composite description;
  • tools to facilitate identifying the sources of information to associate with the description elements;
  • tools to collect the identified description elements and their associated sources into a standard, referenceable format that can support general access and understanding;
  • tools to automatically update the composite description as the component sources change, and to consistently apply versioning schemes to identify the new description contents and the type and significance of change that occurred.
From inherited abstract Governance Functional Profile

Service Oriented Architecture is an architectural paradigm for organizing and utilizing distributed capabilities that may be under the control of different ownership domains. Consequently, it is important that organizations that plan to engage in service interactions adopt governance policies and procedures sufficient to ensure that there is standardization across both internal and external organizational boundaries to promote the effective creation and use of SOA-based services.

Governance is expressed through policies and assumes multiple use of focused policy modules that can be employed across many common circumstances.

SOA governance requires numerous architectural capabilities on the Semantic Infrastructure:

Governance requires Governance requires that the participants understand the intent of governance, the structures created to define and implement governance, and the processes to be followed to make governance operational. This is provided by the following capabilities:

  • an information collection site, such as a Web page or portal, where governance information is stored and from which the information is always available for access;
  • a mechanism to inform participants of significant governance events, such as changes in policies, rules, or regulations;
  • accessible storage of the specifics of Governance Processes;
  • SOA services to access automated implementations of the Governance Processes

capabilities specialized from the inherited Management Profile.

Governance Governance policies are made operational through rules and regulations. This is provided by the following capabilities, most of which are specializations of the inherited Artifact Profile:

  • descriptions to enable the rules and regulations to be visible, where the description includes a unique identifier and a sufficient, and preferably a machine process-able, representation of the meaning of terms used to describe the rules and regulations;
  • one or more discovery mechanisms that enable searching for rules and regulations that may apply to situations corresponding to the search criteria specified by the service participant; where the discovery mechanism will have access to the individual descriptions of rules and regulations, possibly through some repository mechanism;
  • accessible storage of rules and regulations and their respective descriptions, so service participants can understand and prepare for compliance, as defined.
  • SOA services to access automated implementations of the Governance Processes.
From inherited abstract Interaction Functional Profile

Descriptions of interactions are important for enabling auditability and repeatability, thereby establishing a context for results and support for understanding observed change in performance or results.

Architectural implications of interactions on the Semantic Infrastructure are reflected in the following capabilities:

  • one or more mechanisms to capture, describe, store, discover, and retrieve interaction logs, execution contexts, and the combined interaction descriptions;
  • one or more mechanisms for attaching to any results the means to identify and retrieve the interaction description under which the results were generated.
From inherited abstract Interoperability Functional Profile

Descriptions provide up-to-date information on what a resource is, the conditions for interacting with the resource, and the results of such interactions. As such, the description is the source of vital information in establishing willingness to interact with a resource, reachability to make interaction possible, and compliance with relevant conditions of use.

Architectural implications of interoperability on the Semantic Infrastructure are reflected in the following capabilities:

  • one or more discovery mechanisms that enable searching for described resources that best meet the criteria specified by a service participant, where the discovery mechanism will have access to individual descriptions, possibly through some repository mechanism;
  • tools to appropriately track users of the descriptions and notify them when a new version of the description is available.
From inherited abstract Management Functional Profile

Governance implies management to define and enforce rules and regulations.

Management is provided by the following capabilities:

  • an information collection site, such as a Web page or portal, where management information is stored and from which the information is always available for access;
  • a mechanism to inform participants of significant management events, such as changes in rules or regulations;
  • accessible storage of the specifics of processes followed by management.
From inherited abstract Metrics Functional Profile

Artifact Descriptions include references to metrics which describe the operational characteristics of the subjects being described

Architectural implications of metrics on the Semantic Infrastructure are reflected in Governance relies on metrics to define and measure compliance. This is provided by the following capabilities:

  • the access to platform infrastructure monitoring and reporting information on SOA resources;
  • possible interface requirements to make accessible metrics information generated or most easily accessed by the service itself.
  • capabilities
  • access to metrics information generated or accessible by related services
  • mechanisms to catalog and enable discovery of which metrics are available for a described artifact and information on how these metrics can be accessed;
  • mechanisms to catalog and enable discovery of compliance records associated with policies, contracts, and constraints that are based on these metrics.
From inherited abstract Policy Functional Profile

Artifact Descriptions include references to policies defining conditions of use and optionally contracts representing agreement on policies and other conditions.

Architectural implications of policy on the Semantic Infrastructure are reflected in the following capabilities:

  • descriptions to enable the policy modules to be visible, where the description includes a unique identifier for the policy and a sufficient, and preferably a machine processible, representation of the meaning of terms used to describe the policy, its functions, and its effects;
  • one or more discovery mechanisms that enable searching for policies that best meet the search criteria specified by the service participant; where the discovery mechanism will have access to the individual policy descriptions, possibly through some repository mechanism;
  • accessible storage of policies and policy descriptions, so service participants can access, examine, and use the policies as defined.

Policy capabilities are specialization of Artifact capabilities.

From inherited abstract PolicyAndContract Functional Profile

While policy and contract descriptions have much of the same architectural implications as Service Descriptions, mechanisms supporting policies and contracts also have the following architectural implications:

  • decision procedures which must be able to measure and render decisions on constraints;
  • enforcement of decisions;
  • measurement and notification of obligation constraints;
  • auditability of decisions, enforcement, and obligation measurements;
  • administration of policy and contract language artifacts;
  • storage of policies and contracts;
  • distribution of policies/contracts;
  • conflict resolution or elevation of conflicts in policy rules;
  • delegation of policy authority to agents acting on behalf of a client;
  • decision procedures capable of incorporating roles and/or attributes for rendered decisions.
From inherited abstract PolicyAndContractLanguage Functional Profile

While policy and contract descriptions have much of the same architectural implications as Service Descriptions, languages supporting policies and contracts also have the following architectural implications:

  • expression of assertion and commitment policy constraints;
  • expression of positive and negative policy constraints;
  • expression of permission and obligation policy constraints;
  • nesting of policy constraints allowing for abstractions and refinements of a policy constraint;
  • definition of alternative policy constraints to allow for the selection of compatible policy constraints for a consumer and provider;
  • composition of policies to combine one or more policies.
Capability Elaborations

This Functional Profile includes, but is not limited to, the following capability elaborations:

Derived From Requirements

  • Semantic Infrastructure Requirements::Service Discovery and Governance::Service Policies Service policies help establish constraints on the service specifications and mandate an approach. Policies can be specified around governance, access control and other design and runtime constraints.

Anchor
_16_5_1_24a0131_1283703443772_860088_3293
_16_5_1_24a0131_1283703443772_860088_3293
assembly capability elaboration

Tools to facilitate identifying description elements that are to be aggregated to assemble the composite description.

Anchor
_16_5_1_24a0131_1283702219073_894098_3212
_16_5_1_24a0131_1283702219073_894098_3212
complianceDiscovery capability elaboration

Mechanisms to catalog and enable discovery of compliance records associated with policies, contracts, and constraints that are based on these metrics.

Anchor
_16_5_1_24a0131_1283704509983_673729_3325
_16_5_1_24a0131_1283704509983_673729_3325
componentAcquisition capability elaboration

Tools to facilitate identifying the sources of information to associate with the description elements.

Anchor
_16_5_1_24a0131_1283703443770_810122_3292
_16_5_1_24a0131_1283703443770_810122_3292
compositionArchive capability elaboration

Tools to collect the identified description elements and their associated sources into a standard, referenceable format that can support general access and understanding.

Anchor
_16_5_1_24a0131_1283703443775_178969_3294
_16_5_1_24a0131_1283703443775_178969_3294
compositionChange capability elaboration

Tools to automatically update the composite description as the component sources change, and to consistently apply versioning schemes to identify the new description contents and the type and significance of change that occurred.

Anchor
_16_5_1_24a0131_1283700133655_905377_3117
_16_5_1_24a0131_1283700133655_905377_3117
configurationManagement capability elaboration

Mechanisms to support the storage, referencing, and access to normative definitions of one or more versioning schemes that may be applied to identify different aggregations of descriptive information, where the different schemes may be versions of a versioning scheme itself.

Anchor
_16_5_1_24a0131_1283714222600_103266_4106
_16_5_1_24a0131_1283714222600_103266_4106
discovery capability elaboration

One or more discovery mechanisms that enable searching for artifacts that best meet the search criteria specified by the service participant; where the discovery mechanism will have access to the individual artifact descriptions, possibly through some repository mechanism.

Anchor
_16_5_1_24a0131_1283418677626_125372_8996
_16_5_1_24a0131_1283418677626_125372_8996
governanceModel capability elaboration

Governance Model with capabilities to create, destroy, edit, maintain governance policy.

...

  • unique identification for each policy the Governance meta-model describing term representations, functions, and effects of a policy description (model)
  • one or more discovery mechanisms that enable searching for policies that best meet the search criteria specified by the service participant; where the discovery mechanism will have access to the individual policy descriptions through some repository mechanism;
  • services enabling access, examination, and use of the policies.
  • notifications to inform participants of significant governance events, such as changes in policies, rules, or regulations;
  • comprehensive, accessible, Governance Model;
  • services to access implementations of the Governance Processes
  • Rules and regulation models are accessible from the Governance model; they all have meta-models describing their terms, functions, effects; they all have discovery and search mechanisms accessible through some repository
  • Utilize platform monitoring and notification capabiities to monitor, report, and make accessible metrics related to compliance
  • expression of assertion and commitment policy constraints;
  • expression of positive and negative policy constraints;
  • expression of permission and obligation policy constraints;
  • nesting of policy constraints allowing for abstractions and refinements of a policy constraint;
  • definition

Anchor
_16_5_1_24a0131_1283718946661_463032_4374
_16_5_1_24a0131_1283718946661_463032_4374
governanceService capability elaboration

SOA services to access automated implementations of the Governance Processes.

Anchor
_16_5_1_24a0131_1283714222601_506267_4107
_16_5_1_24a0131_1283714222601_506267_4107
identity capability elaboration

Descriptions which include a unique identifier for the artifact.

Anchor
_16_5_1_24a0131_1283703044067_803205_3257
_16_5_1_24a0131_1283703044067_803205_3257
interactionLog capability elaboration

One or more mechanisms to capture, describe, store, discover, and retrieve interaction logs, execution contexts, and the combined interaction descriptions.

Anchor
_16_5_1_24a0131_1283703044069_331285_3258
_16_5_1_24a0131_1283703044069_331285_3258
interactionResults capability elaboration

One or more mechanisms for attaching to any results the means to identify and retrieve the interaction description under which the results were generated.

Anchor
_16_5_1_24a0131_1283704952692_78857_3340
_16_5_1_24a0131_1283704952692_78857_3340
interoperabilityDiscovery capability elaboration

One or more discovery mechanisms that enable searching for described resources that best meet the criteria specified by a service participant, where the discovery mechanism will have access to individual descriptions, possibly through some repository mechanism.

Anchor
_16_5_1_24a0131_1283719206847_206279_4421
_16_5_1_24a0131_1283719206847_206279_4421
managementInformation capability elaboration

An information collection site, such as a Web page or portal, where management information is stored and from which the information is always available for access.

Anchor
_16_5_1_24a0131_1283719206849_873728_4422
_16_5_1_24a0131_1283719206849_873728_4422
managementNotification capability elaboration

A mechanism to inform participants of significant management events, such as changes in rules or regulations.

Anchor
_16_5_1_24a0131_1283719206851_835373_4423
_16_5_1_24a0131_1283719206851_835373_4423
managementProcesses capability elaboration

Accessible storage of the specifics of processes followed by management.

Anchor
_16_5_1_24a0131_1283714222603_853936_4108
_16_5_1_24a0131_1283714222603_853936_4108
metadata capability elaboration

A representation of the meaning of terms used to describe the artifact, its functions, and its effects.

Anchor
_16_5_1_24a0131_1283702219069_775824_3210
_16_5_1_24a0131_1283702219069_775824_3210
metrics capability elaboration

Access to metrics information generated or accessible by related services

Anchor
_16_5_1_24a0131_1283702219071_411273_3211
_16_5_1_24a0131_1283702219071_411273_3211
metricsDiscovery capability elaboration

Mechanisms to catalog and enable discovery of which metrics are available for a described artifact and information on how these metrics can be accessed.

Anchor
_16_5_1_24a0131_1283702219067_789210_3209
_16_5_1_24a0131_1283702219067_789210_3209
monitor capability elaboration

Access to platform infrastructure monitoring and reporting capabilities.

Anchor
_16_5_1_24a0131_1283709534035_370700_3630
_16_5_1_24a0131_1283709534035_370700_3630
policyAdministration capability elaboration

Administration of policy and contract language artifacts.

Anchor
_16_5_1_24a0131_1283709354487_144893_3557
_16_5_1_24a0131_1283709354487_144893_3557
policyAlternative capability elaboration

Definition of alternative policy constraints to allow for the selection of compatible policy constraints for a consumer and provider

...

.

Anchor
_16_5_1_24a0131_1283708802840_147328_3513
_16_5_1_24a0131_1283708802840_147328_3513
policyAssertion capability elaboration

Expression of assertion and commitment policy constraints.

Anchor
_16_5_1_24a0131_1283709534037_796250_3631
_16_5_1_24a0131_1283709534037_796250_3631
policyAudit capability elaboration

Auditability of decisions, enforcement, and obligation measurements.

Anchor
_16_5_1_24a0131_1283710107694_279074_3717
_16_5_1_24a0131_1283710107694_279074_3717
policyAuthorityDelegation capability elaboration

Delegation of policy authority to agents acting on behalf of a client.

Anchor
_16_5_1_24a0131_1283709357663_548317_3568
_16_5_1_24a0131_1283709357663_548317_3568
policyComposition capability elaboration

Composition of policies to combine one or more policies.

...

Anchor
_16_5_1_24a0131_1283710104206_368283_3706
_16_5_1_24a0131_1283710104206_368283_3706
policyConflictResolution capability elaboration

Conflict resolution or elevation of conflicts in policy rules.

Anchor
_16_5_1_24a0131_1283708802845_910120_3515
_16_5_1_24a0131_1283708802845_910120_3515
policyConstraint capability elaboration

Expression of positive and negative policy constraints.

Anchor
_16_5_1_24a0131_1283709534042_669768_3633
_16_5_1_24a0131_1283709534042_669768_3633
policyDecision capability elaboration

Decision

...

procedures which must be able to measure and render decisions on constraints

...

.

Anchor
_16_5_1_24a0131_1283710110550_888548_3728
_16_5_1_24a0131_1283710110550_888548_3728
policyDecisionProcedures capability elaboration

Decision procedures capable of incorporating roles and/or attributes for rendered decisions.

Anchor
_16_5_1_24a0131_1283710100788_883107_3695
_16_5_1_24a0131_1283710100788_883107_3695
policyDistribution capability elaboration

Distribution of policies/contracts.

Anchor
_16_5_1_24a0131_1283709534033_698521_3629
_16_5_1_24a0131_1283709534033_698521_3629
policyEnforcement capability elaboration

Enforcement of decisions.

Anchor
_16_5_1_24a0131_1283709534044_887600_3634
_16_5_1_24a0131_1283709534044_887600_3634
policyMetrics capability elaboration

Measurement and notification of obligation constraints.

Anchor
_16_5_1_24a0131_1283708802843_961852_3514
_16_5_1_24a0131_1283708802843_961852_3514
policyObligation capability elaboration

Expression of permission and obligation policy constraints.

Anchor
_16_5_1_24a0131_1283708802847_903040_3516
_16_5_1_24a0131_1283708802847_903040_3516
policyRefinement capability elaboration

Nesting of policy constraints allowing for abstractions and refinements of a policy constraint.

Anchor
_16_5_1_24a0131_1283709534039_440038_3632
_16_5_1_24a0131_1283709534039_440038_3632
policyStore capability elaboration

Storage of policies and contracts.

Anchor
_16_5_1_24a0131_1283704952697_176583_3341
_16_5_1_24a0131_1283704952697_176583_3341
serviceChangeNotification capability elaboration

Tools to appropriately track users of the descriptions and notify them when a new version of the description is available.

Anchor
_16_5_1_24a0131_1283714222609_981432_4109
_16_5_1_24a0131_1283714222609_981432_4109
store capability elaboration

Accessible storage of artifacts and artifact descriptions, so service participants can access, examine, and use the artifacts as defined.

Anchor
_16_5_1_24a0131_1283700246486_44421_3128
_16_5_1_24a0131_1283700246486_44421_3128
transition capability elaboration

One or more mechanisms to support the storage, referencing, and access to conversion relationships between versioning schemes, and the mechanisms to carry out such conversions.

Anchor
_16_5_1_24a0131_1283699095521_961509_3106
_16_5_1_24a0131_1283699095521_961509_3106
versioning capability elaboration

Configuration management mechanisms to capture the contents of the each aggregation and apply a unique identifier in a manner consistent with an identified versioning scheme

...

.

Scrollbar