* his is a major change, which will take a lot of effort, but you have to plan for 10 times as many deployments, so there is really no option

h6. 8. Security is not optional in SOA

* You basically need to pass a Security Token with each service invocation. On pre-invocation you do the normal access control, of post-invocation you need to filter the data-values (i.e. remove sensitive data if the security token does not have the right access. This is necessary, since we no longer have any single point of control, or trying to establish a single point of control will break the agility and time-to-marked values of your SOA.

h6. 9. Reflect and work strategically against SOA Maturity Model.

* See []


{tip}To be merged with content above{tip}

h3. Intro