Opinion: Approach mashups with caution
Computerworld - I hate to be the teetotaler at the mashup party, but someone has to take a sober look at the security implications of this emerging approach to business intelligence.
Mashups let you take data from an outside source and combine it with your own data to yield new information or insight.
Think about that for a minute. Data from somewhere else running on your network? Even if the person who initiates the mashup believes the data comes from a trusted source, do you know if the originating systems meet your security standards? Are those systems at current patch levels? If your business works in a regulated environment, will such a mashup put you out of compliance?
Do you have people on staff who are up to date on mashup security issues? Here's one to consider: For mashups to work, you have to suspend the security feature in browsers called same-origin policy. Same-origin was designed to stop one Web site from dropping malicious code onto another.
Oh, and then there's JavaScript. Does the mashup your company is creating include JavaScript from outside your company?
Think about that one. Your data. Someone else's script processing it. Is it proprietary data of special value to your enterprise? Do you know exactly what the script does with your data?
You should also ask yourself whether you would treat the data in a traditional BI app as cavalierly as some people use data in a mashup. As Chris Rafter, vice president of consulting services at Logicalis Inc., a technology services company with a BI practice, explained to me, "Mashups violate some of the unwritten rules of business intelligence."
For example, he says, BI apps are generally built around a data warehouse, which is highly secured and certainly unreachable by outsiders. He also notes that good governance for BI precludes generating reports laden with unaudited external data.
This isn't to say you shouldn't explore mashup technology behind your firewall and with your own data sources, or with data from established and vetted partners whose scripts you have scrutinized and tested. Mashups can be a quick way for business analysts to get insight from the knowledge locked in different silos inside your organization, where most of the illuminating information about and for your business resides.
But be wary of business units that want to contrast internal data with outsiders -- say, a boutique market research house that can stream information to your network. The data may be golden, but it could turn into fool's gold if that firm's data-streaming application doesn't conform to WS-Security standards and its program gets compromised.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Forrester: Economic Impact of Switching to Google Apps
- Content provided by Google
Read this Forrester report on the "total economic impact" of Google Apps, and learn how switching to Google Apps creates... - Intelligent Systems: Unlocking Hidden Business Value with Data
- An intelligent system enables data to flow across an enterprise infrastructure, spanning the devices where valuable data is gathered from employees and customers,...
- Concepts of NonStop SQL/MX
- For DBAs and developers who are familiar with Oracle solutions and want to learn about NonStop SQL/MX, this whitepaper provides an overview of...
- HP Advanced Information Services for SAP In-Memory Appliance (SAP HANA)
- Organizations are eager to connect the vast amounts of data available within and outside their businesses to compete more effectively and make better... All BI and Analytics White Papers
- Live Webcast
North Pole to South Seas: Overcoming the Pitfalls of remote Performance - In today's always-on world, connectivity is a business requirement. You need the tools that allow you to operate as if you were on...
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Live Webcast
Banish Poor Application Performance: Eliminate Business Disruptions, Increase End User Productivity - End User Experience, 30-Min Webinar
Wed. Feb. 22nd ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Quantifying the Business Value of VMware View - Webcast
- Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price...
- Good to Great - How to Take Business Analytics to the Next Level
- By attending this webcast you will learn how you can implement an effective BA strategy that will deliver maximum strategic value to your...
- Supporting Mobile Productivity With A Limited IT Budget
- Join us and hear from Kaseya mobile IT management experts as we discuss core strategies for supporting the mobile revolution on a shoestring...
- User Experience Monitoring
- In this webinar, you will learn hints & tips for improving end-user response times from Forrester Research analyst, Jean-Pierre Garbani.
- Hints & Tips Cisco
- Overwhelmed by tracking your Vblock, Flexpod or Cisco UCS performance? Spend one hour with Nimsoft to learn how you can eliminate the overhead... All BI and Analytics Webcasts