Ads by TechWords

See your link here
Receive the latest technology news and information.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Opinion: Approach mashups with caution

September 1, 2008 12:00 PM ET

Computerworld - I hate to be the teetotaler at the mashup party, but someone has to take a sober look at the security implications of this emerging approach to business intelligence.

Mashups let you take data from an outside source and combine it with your own data to yield new information or insight.

Think about that for a minute. Data from somewhere else running on your network? Even if the person who initiates the mashup believes the data comes from a trusted source, do you know if the originating systems meet your security standards? Are those systems at current patch levels? If your business works in a regulated environment, will such a mashup put you out of compliance?

Do you have people on staff who are up to date on mashup security issues? Here's one to consider: For mashups to work, you have to suspend the security feature in browsers called same-origin policy. Same-origin was designed to stop one Web site from dropping malicious code onto another.

Oh, and then there's JavaScript. Does the mashup your company is creating include JavaScript from outside your company?

Think about that one. Your data. Someone else's script processing it. Is it proprietary data of special value to your enterprise? Do you know exactly what the script does with your data?

You should also ask yourself whether you would treat the data in a traditional BI app as cavalierly as some people use data in a mashup. As Chris Rafter, vice president of consulting services at Logicalis Inc., a technology services company with a BI practice, explained to me, "Mashups violate some of the unwritten rules of business intelligence."

For example, he says, BI apps are generally built around a data warehouse, which is highly secured and certainly unreachable by outsiders. He also notes that good governance for BI precludes generating reports laden with unaudited external data.

This isn't to say you shouldn't explore mashup technology behind your firewall and with your own data sources, or with data from established and vetted partners whose scripts you have scrutinized and tested. Mashups can be a quick way for business analysts to get insight from the knowledge locked in different silos inside your organization, where most of the illuminating information about and for your business resides.

But be wary of business units that want to contrast internal data with outsiders -- say, a boutique market research house that can stream information to your network. The data may be golden, but it could turn into fool's gold if that firm's data-streaming application doesn't conform to WS-Security standards and its program gets compromised.



Jump to comments

mashups

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

Featured Zone
The SAS Business Analytics Zone
Is your enterprise constantly challenged by the need to manage huge data volumes in near-real time to make fast, accurate decisions? If so, get into the zone — and learn more about how SAS® Data Integration and SAS® Data Quality solutions - powered by DataFlux - can help you access, validate, cleanse, enhance and distribute trustworthy information. SAS provides the software solutions to address a volatile economy, increased regulations, talent shortages and global competition. Our unique framework of Business Analytics offerings enables organizations to solve complex problems, manage for performance, drive sustainable growth and anticipate change.
Enter the SAS Business Analytics Zone now
See All Zones


IT Jobs

 

SAS Information Management Kit

SAS is the leader in business intelligence and analytical software and services. Only SAS offers leading data integration, storage, analytics and business intelligence applications within a comprehensive enterprise intelligence platform. SAS gives 97 of the top 100 companies in the 2007 Fortune 500 THE POWER TO KNOW®.

Webcast: The Information Management Roadmap
Imagine high-quality data, cleansed, analyzed and delivered throughout your organization. Join Computerworld, IT visionary Thornton May and a panel of experts to learn how SAS® can help you make it happen.

View this webcast 
Research Report: Information Management Initiatives at Midsize and Large Organizations
See the top-line results of this Computerworld sponsored survey to see how IT and business leaders are handling information management implementation.

Download this report 
White Paper: Information Management: Better Information for Winning Decisions.
This white paper explains how the SAS Information Evolution Model aids companies in assessing how they use this information to make strategic decisions and drive business.

Download this white paper